code-423n4 / 2024-08-phi-findings

2 stars 2 forks source link

QA Report #332

Open howlbot-integration[bot] opened 1 month ago

howlbot-integration[bot] commented 1 month ago

See the markdown file with the details of this report here.

ZaK3939 commented 1 month ago

Is there a similar report in H/M? This finding is important to us [L-02] RewardsDeposit and Deposit events can be spam emitted with 0 value deposits through external function

fatherGoose1 commented 1 month ago

@ZaK3939 I will keep an eye out for any similar H/M

ZaK3939 commented 1 month ago

@fatherGoose1 please check these ones https://github.com/code-423n4/2024-08-phi-validation/issues/273 https://github.com/code-423n4/2024-08-phi-validation/issues/60

c4-judge commented 1 month ago

fatherGoose1 marked the issue as grade-a

fatherGoose1 commented 1 month ago

L-02 is a good finding, but does not constitute a Medium severity issue. These events can easily be filtered out and would require financial investment from the malicious spammer.

c4-judge commented 1 month ago

fatherGoose1 marked the issue as selected for report

fatherGoose1 commented 1 month ago

I agree with all findings listed in this report.

liveactionllama commented 1 month ago

ℹ️ Removing selected for report, as the QA rankings will not be determined and finalized until after post-judging QA is finalized.

mcgrathcoutinho commented 1 month ago

Hi @fatherGoose1, I believe two HM dups from this report were missed out:

  1. L-17 is a duplicate of #14. Additional impact is also mentioned in the third point of the PhiNFT1155 section under Powers of each role
  2. L-07 is a duplicate of #268
c4-judge commented 1 month ago

fatherGoose1 marked the issue as selected for report

thebrittfactor commented 1 month ago

For awarding purposes, C4 staff have marked as 1st place.