Rayaa
banner
0xrayaa.bsky.social
Rayaa
@0xrayaa.bsky.social
Playing with Rust 🦀 and Solidity 🪨 !
Smart Contract Auditor.
Bug Bounty Hunter.
Pinned
Today is new!
While doing Rust Audit Learned something new today!

Its regarding "zip". not ZIP file compression :P
Reposted by Rayaa
If you like bounties, I highly recommend this presentation from Martin Doyhenard on novel web cache deception techniques. It comes with Web Security Academy labs too!
www.youtube.com/watch?v=70yy...
DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache exploitation - Martin Doyhenard
YouTube video by DEFCONConference
www.youtube.com
November 26, 2024 at 2:33 PM
I do agree with you!
Human r most vulnerable :)
November 28, 2024 at 6:44 PM
An simple que in auditors mind will be :
What if both have different lengths ?

But In Rust, the zip method only iterates until one of the iterators is exhausted.

here comes the problem! :
Here, the third element in payouts (30) is ignored because multipliers has fewer elements.
November 28, 2024 at 10:56 AM
'Zips up' two iterators into a single iterator of pairs.

zip() returns a new iterator that will iterate over two other iterators, returning a tuple where the first element comes from the first iterator, and the second element comes from the second iterator.
November 28, 2024 at 10:56 AM
Today is new!
While doing Rust Audit Learned something new today!

Its regarding "zip". not ZIP file compression :P
November 28, 2024 at 10:56 AM
Lets talk about web3 security!
November 28, 2024 at 10:48 AM