【智能合约审计】————8、bankcoin

本文深入解析了BankCoin智能合约的源代码,介绍了其使用Solidity语言实现的数学运算库SafeMath,以及合同的主要功能,包括所有权转移、代币转账、批准和调用等操作。同时,文章还指出了合约中可能存在的整数溢出风险。

合约地址:

 

pragma solidity ^0.4.16;

library SafeMath {
  function mul(uint256 a, uint256 b) internal constant returns (uint256) {
    uint256 c = a * b;
    assert(a == 0 || c / a == b);
    return c;
  }

  function div(uint256 a, uint256 b) internal constant returns (uint256) {
    // assert(b > 0); // Solidity automatically throws when dividing by 0
    uint256 c = a / b;
    // assert(a == b * c + a % b); // There is no case in which this doesn't hold
    return c;
  }

  function sub(uint256 a, uint256 b) internal constant returns (uint256) {
    assert(b <= a);
    return a - b;
  }

  function add(uint256 a, uint256 b) internal constant returns (uint256) {
    uint256 c = a + b;
    assert(c >= a);
    return c;
  }
}

    contract owned {
        address public owner;

        function owned() {
            owner = msg.sender;
        }

        modifier onlyOwner {
            require(msg.sender == owner);
            _;
        }

        function transferOwnership(address newOwner) onlyOwner {
            owner = newOwner;
        }
    }

interface tokenRecipient { function receiveApproval(address _from, uint256 _value, address _token, bytes _extraData) public; }

contract bankcoin is owned {

    using SafeMath for uint256;
    
    // Public variables of the token
    string public name = "bankcoin";
    string public symbol = "BNK";
    uint8 public decimals = 0;
    uint256 public totalSupply = 5000000;

    // This creates an array with all balances
    mapping (address => uint256) public balanceOf;
    mapping (address => mapping (address => uint256)) public allowance;

    // This generates a public event on the blockchain that will notify clients
    event Transfer(address indexed from, address indexed to, uint256 value);

    // This notifies clients about the amount burnt
    event Burn(address indexed from, uint256 value);

    
    function bankcoin(){
     balanceOf[msg.sender] = totalSupply;
    }
   //存在整数溢出,可以导致"任意铸币"
    function mintToken(address target, uint256 mintedAmount) onlyOwner {
        balanceOf[target] += mintedAmount;
        totalSupply += mintedAmount;
        Transfer(0, owner, mintedAmount);
        Transfer(owner, target, mintedAmount);
    }
    
    /**
     * Internal transfer, only can be called by this contract
     */
    function _transfer(address _from, address _to, uint _value) internal {
        // Prevent transfer to 0x0 address. Use burn() instead
        require(_to != 0x0);
        // Check if the sender has enough
        require(balanceOf[_from] >= _value);
        // Check for overflows
        require(balanceOf[_to] + _value > balanceOf[_to]);
        // Save this for an assertion in the future
        uint previousBalances = balanceOf[_from] + balanceOf[_to];
        // Subtract from the sender
        balanceOf[_from] -= _value;
        // Add the same to the recipient
        balanceOf[_to] += _value;
        Transfer(_from, _to, _value);
        // Asserts are used to use static analysis to find bugs in your code. They should never fail
        assert(balanceOf[_from] + balanceOf[_to] == previousBalances);
    }

    /**
     * Transfer tokens
     *
     * Send `_value` tokens to `_to` from your account
     *
     * @param _to The address of the recipient
     * @param _value the amount to send
     */
    function transfer(address _to, uint256 _value) public {
        _transfer(msg.sender, _to, _value);
    }

    /**
     * Transfer tokens from other address
     *
     * Send `_value` tokens to `_to` in behalf of `_from`
     *
     * @param _from The address of the sender
     * @param _to The address of the recipient
     * @param _value the amount to send
     */
    function transferFrom(address _from, address _to, uint256 _value) public returns (bool success) {
        require(_value <= allowance[_from][msg.sender]);     // Check allowance
        allowance[_from][msg.sender] -= _value;
        _transfer(_from, _to, _value);
        return true;
    }

    /**
     * Set allowance for other address
     *
     * Allows `_spender` to spend no more than `_value` tokens in your behalf
     *
     * @param _spender The address authorized to spend
     * @param _value the max amount they can spend
     */
    function approve(address _spender, uint256 _value) public
        returns (bool success) {
        allowance[msg.sender][_spender] = _value;
        return true;
    }

    /**
     * Set allowance for other address and notify
     *
     * Allows `_spender` to spend no more than `_value` tokens in your behalf, and then ping the contract about it
     *
     * @param _spender The address authorized to spend
     * @param _value the max amount they can spend
     * @param _extraData some extra information to send to the approved contract
     */
    function approveAndCall(address _spender, uint256 _value, bytes _extraData)
        public
        returns (bool success) {
        tokenRecipient spender = tokenRecipient(_spender);
        if (approve(_spender, _value)) {
            spender.receiveApproval(msg.sender, _value, this, _extraData);
            return true;
        }
    }

    /**
     * Destroy tokens
     *
     * Remove `_value` tokens from the system irreversibly
     *
     * @param _value the amount of money to burn
     */
    function burn(uint256 _value) public returns (bool success) {
        require(balanceOf[msg.sender] >= _value);   // Check if the sender has enough
        balanceOf[msg.sender] -= _value;            // Subtract from the sender
        totalSupply -= _value;                      // Updates totalSupply
        Burn(msg.sender, _value);
        return true;
    }

    /**
     * Destroy tokens from other account
     *
     * Remove `_value` tokens from the system irreversibly on behalf of `_from`.
     *
     * @param _from the address of the sender
     * @param _value the amount of money to burn
     */
    function burnFrom(address _from, uint256 _value) public returns (bool success) {
        require(balanceOf[_from] >= _value);                // Check if the targeted balance is enough
        require(_value <= allowance[_from][msg.sender]);    // Check allowance
        balanceOf[_from] -= _value;                         // Subtract from the targeted balance
        allowance[_from][msg.sender] -= _value;             // Subtract from the sender's allowance
        totalSupply -= _value;                              // Update totalSupply
        Burn(_from, _value);
        return true;
    }
    //存在整数溢出,可以导致"下溢增持"
    function distributeToken(address[] addresses, uint256 _value) onlyOwner {
     for (uint i = 0; i < addresses.length; i++) {
         balanceOf[owner] -= _value;
         balanceOf[addresses[i]] += _value;
         Transfer(owner, addresses[i], _value);
     }
}
}

 

WordPress 平台本身并没有提供“余额检查”功能,这个功能通常与电子商务、会员系统或金融相关插件有关。如果需要在 WordPress 网站上实现余额检查功能,通常需要依赖第三方插件或自定义开发。以下是一些可能的实现方式: 1. **会员系统插件** 如果网站涉及用户账户余额(如积分、虚拟货币等),可以使用会员系统插件,例如: - **Ultimate Member**:支持创建用户资料和自定义字段,可以结合自定义开发实现余额查询功能。 - **UserPro**:提供用户资料管理功能,适合需要用户账户体系的网站。 2. **电子商务插件** 如果网站涉及实际交易和账户余额管理,可以使用以下插件: - **WooCommerce**:这是 WordPress 上最流行的电商插件之一,支持订单管理、用户余额(通过扩展如 WooCommerce Customer/Order/Coupon CSV Import Suite 或第三方扩展)等功能。 - **Easy Digital Downloads**:适合销售数字产品的网站,支持自定义字段和用户余额管理。 3. **自定义开发功能** 如果需要特定的余额检查功能,可以通过自定义开发实现,例如在主题的 `functions.php` 文件中添加以下代码来创建一个简单的余额字段: ```php function add_balance_field($user_id) { add_user_meta($user_id, 'account_balance', 0, true); } add_action('user_register', 'add_balance_field'); function display_user_balance($user_id) { $balance = get_user_meta($user_id, 'account_balance', true); echo '当前余额:' . $balance . ' 元'; } ``` 上述代码会在用户注册时添加一个默认余额字段,并提供一个函数用于显示用户的余额。 4. **数据库查询** 如果余额信息存储在数据库中,可以通过 SQL 查询来获取特定用户的余额信息。例如: ```sql SELECT meta_value FROM wp_usermeta WHERE user_id = 1 AND meta_key = 'account_balance'; ``` 通过这种方式,可以直接从数据库中提取余额信息并进行展示或处理。 ### 插件推荐 如果希望使用现成的插件来管理用户余额,可以考虑以下插件: - **User Wallet System**:该插件允许用户在网站上存储资金、进行交易,并提供余额查询功能。 - **WP User Frontend**:支持前台用户管理,可以结合自定义字段实现余额功能。 如果需要更具体的插件推荐或功能实现,请提供更多关于“余额”功能的使用场景,以便进一步分析和建议。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

FLy_鹏程万里

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值