Henceforth, All Job Applicants Must Hack Into Our Backend (Dev Challenge)
seatgeek.com
seatgeek.com
Then I guess you'd have to give him the job by default :-)
So I would by no means liken this to the Greplin Challenge, but we're trying to accomplish something different. We're hoping to eliminate the crappy applicants so we can spend more time on the good ones.
Whenever I've been apart of interviewing candidates, ≈70% of the time was wasted on applicants who fluffed their resumé, got an interview, and were obviously not what they claimed to be. This would probably significantly reduce that overhead and at the same time attract people who enjoy coding vs. do it just to pay the bills.
How were y'all's percentages in that regard? How many applicants flat-out couldn't write code to save their life?
1) Viewed source. Didn't see any obvious comments.
2) Looked at .css files. Nothing obvious there, though there are styles for form/etc classes and elements that aren't used in the page.
3) Tried creating some forms with input and label elements in the markup in Firebug to see if CSS labeling on buttons showed anything. Just showed "Submit Query".
4) Looked at session headers in Firebug/Safari and saw something along the lines of
< HTTP/1.1 403 Forbidden
< Server: nginx
< Date: Tue, 26 Oct 2010 09:10:58 GMT
< Content-Type: text/html; charset=utf-8
< Connection: keep-alive
< Status: 403 Forbidden
< X-Runtime: 0.001014
< Content-Length: 1552
< Set-Cookie: sg.session=%7B%22csrf.token%22%3A%228KSf5VQhEB6DRoS0Z9PWW6ugXnH4e132LzBH8E76dE4%3D%22%7D; path=/
5) Noticed 'csrf.token' and googled to figure out it was a cross site request forgery prevention token, which seems sort of related.Tried to mess around with this in Python and sort of got somewhere with this
>>>urllib.unquote("%7B%22csrf.token%22%3A%22R5wuQON8nVfha%2F7WRCXTvVMo7rZzu41dFPOVZ2V0MMw%3D%22%7D")
'{"csrf.token":"R5wuQON8nVfha/7WRCXTvVMo7rZzu41dFPOVZ2V0MMw="}'
Then tried re-encoding: >>> urllib.quote(eval(urllib.unquote("%7B%22csrf.token%22%3A%22R5wuQON8nVfha%2F7WRCXTvVMo7rZzu41dFPOVZ2V0MMw%3D%22%7D")).values()[0])
'R5wuQON8nVfha/7WRCXTvVMo7rZzu41dFPOVZ2V0MMw%3D'
and then doing an HTTP POST with curl curl -v -d "csrf.token=R5wuQON8nVfha/7WRCXTvVMo7rZzu41dFPOVZ2V0MMw%3D" apply.seatgeek.com
But no dice. Is this totally the wrong direction? Is this puzzle really that obvious to any real web developer worthy of the name, and if so where did you earn your spurs/what books/sites did you read?I tried POSTing and PUTing with data values like "csrf=valuefromcookie" and (this may seem stupid) "browser=seatgeek".
I hand crafted a request using cURL.
I also discovered their VHOST settings aren't quite right either because when you POST to https://apply.seatgeek.com it takes you straight to the homepage (instead of redirecting you to the http://apply.seatgeek.com page).
Either way, kudos to those that got it in 15 minutes - I wasted far too much time chasing my tail on this one.
What's more annoying is I did do it correctly the first time - I just misspelled it! :-/
But I guess it would keep the lazy applicant from applying.
EDIT: on second thought, maybe it is the right level. They aren't likely looking for $100k+ hacker geniuses, just guys who can think outside the box and know how to do basic digging and prevent your typical hack.
I retract my statement. Clever application process.
I actually applied with SeatGeek awhile back, and I guess my resume was tossed in the fluff pile. I sort of wish they'd had this at the time, since I'm sure I could figure it out based on the other replies in this thread. But fuck it, I've gotten a job since then with what seems like a pretty cool company, so I can't complain. :)
I think it's the right level of difficulty: Difficult enough that you're able to weed out a lot of really low quality applicants, but not so difficult that you run the risk of excluding high quality applicants.
I wonder how many applications you get from people that don't actually want the job.
I submitted this as my resume: http://www.russellheimlich.com/blog/wp-content/uploads/2007/...
Edit: Removed potential spoilers.
I was well hooked on the writings of Aleph1, Mudge and Rain Forest Puppy at the time, and this game was an excellent tool for teaching developers about vulnerabilities and thus how to defend against them. I know that the game spawned a plethora of copy-cats later on of varying qualitites - does anybody happen to know the one I'm referring to?
I was completely addicted to that game in college. The also apparently have a version on steam now.
I went back and got it figured out - I think the barrier to entry for this is just right.