{"id":21602939,"url":"https://github.com/falconandrea/example-dos-vulnerability","last_synced_at":"2026-04-27T11:31:04.542Z","repository":{"id":182360696,"uuid":"668370108","full_name":"falconandrea/example-dos-vulnerability","owner":"falconandrea","description":"Simple test to try and understand the DOS attack and its vulnerability","archived":false,"fork":false,"pushed_at":"2023-07-19T17:17:14.000Z","size":164,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-06-05T04:23:18.130Z","etag":null,"topics":["denial-of-service-attack","hardhat","solidity","vulnerability-analysis"],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/falconandrea.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2023-07-19T16:36:33.000Z","updated_at":"2023-07-19T16:54:55.000Z","dependencies_parsed_at":null,"dependency_job_id":"e06e9f49-7d3d-45a6-9255-35698bab619a","html_url":"https://github.com/falconandrea/example-dos-vulnerability","commit_stats":null,"previous_names":["falconandrea/example-dos-vulnerability"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/falconandrea/example-dos-vulnerability","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/falconandrea%2Fexample-dos-vulnerability","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/falconandrea%2Fexample-dos-vulnerability/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/falconandrea%2Fexample-dos-vulnerability/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/falconandrea%2Fexample-dos-vulnerability/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/falconandrea","download_url":"https://codeload.github.com/falconandrea/example-dos-vulnerability/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/falconandrea%2Fexample-dos-vulnerability/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32335295,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-26T23:26:28.701Z","status":"online","status_checked_at":"2026-04-27T02:00:06.769Z","response_time":128,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["denial-of-service-attack","hardhat","solidity","vulnerability-analysis"],"created_at":"2024-11-24T19:14:43.544Z","updated_at":"2026-04-27T11:31:04.528Z","avatar_url":"https://github.com/falconandrea.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ca href=\"https://trackgit.com\"\u003e\n\u003cimg src=\"https://us-central1-trackgit-analytics.cloudfunctions.net/token/ping/lk9ys8tiswp79yslowil\" alt=\"trackgit-views\" /\u003e\n\u003c/a\u003e\n\n# Denial of Service (DoS) Vulnerability in a Smart Contract\n\n## Introduction\n\nThis repository explores the Denial of Service (DoS) vulnerability in a smart contract on the Ethereum blockchain. A DoS attack aims to disrupt the normal functioning of a system or application, rendering it unavailable to legitimate users. In the context of a smart contract, a DoS attack can exploit design flaws or vulnerabilities to block contract execution, deny access to certain functionalities, or exhaust resources.\n\n## Vulnerability Description\n\nThe smart contract `Good.sol` implements an auction where participants can place bids for an item by sending an amount greater than the current highest bid. As a result, the new bidder becomes the new winner. The contract keeps track of the current winning bidder and the amount they bid. When a user becomes the new winner, the contract sends the money previously bid by the old winner to their address.\nHowever, a vulnerability arises if the previous winner is a smart contract that lacks a fallback or receive function to receive the funds. In this scenario, no other participant can become the new winner because the attempt to send funds to the old winner fails, preventing the update of the `currentWinner` value.\nAs a result, the `Good.sol` contract gets stuck, preventing further participation in the auction.\n\n## Mitigation\n\nTo mitigate the DoS vulnerability in the `Good.sol` contract, you can create a separate withdraw function for the previous winners.\n\n## Contracts\n\n### Good.sol\n\nThe Good.sol contract is the main contract implementing the auction functionality. It includes features such as the current winning bidder and bid tracking.\n\n### Attack.sol\n\nThe Attack.sol contract exploits the DoS vulnerability in Good.sol by making a higher bid and becoming the new winning bidder. However, Attack.sol cannot receive funds, leading to a blocked state in the Good.sol contract.\n\n## Disclaimer\n\nThis repository is for educational purposes only. The code provided should not be used in production environments without thorough security audits. Use at your own risk.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffalconandrea%2Fexample-dos-vulnerability","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ffalconandrea%2Fexample-dos-vulnerability","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ffalconandrea%2Fexample-dos-vulnerability/lists"}