'; CREATE TABLE `Capture the Flag`; -- Stripe CTF Web Edition coming next week'
stripe.com
stripe.com
I like the idea of being on a team. So, Let's get this started; I'm looking for a team! I'm an experienced C developer (work on and manage a transactional processing platform day-to-day) who works with MySQL+Memcache heavily. SQL injections, memory, buffer overflows and algorithms will be my strong points while javascript/xss attacks may be my shortcomings. Email is in my profile.
Well, Google had a good introduction on web exploits, with a sandboxed environment for you to try it: http://google-gruyere.appspot.com/
A bit older, but good nonetheless: Hack this site[1]
Contests like this are a great idea to help promote safe coding practices.
Companies, take note: providing fun and education to the community can boost your reputation.
I would love to see one that used different DB back-ends at some point. I'm sure it would be interesting to see the other attacks we are not considering with the much more diversified stacks now in existence.
We hope that people new to web security can solve the first few levels with some work and inspection, and the later levels with hints from others or a significant amount of research into the topics.
At the end of the day, the point of the exercise is to expose realistic vulnerabilities for fun and education. We try to make them similar to how they'd be in the wild.
In the first Stripe CTF, I played for the first 3 levels, learned some things, then stopped. But I considered it a success for myself. I'm sure others did similar things.
Capturing the flag wasn't something most people could do in a short time, so having 250/12k even accomplish it I'd think was a rather high conversion rate.
The things under Web Security are the relevant bits. You can read up on a lot of them at https://www.owasp.org/index.php/Main_Page and I'd recommend just googling them as well. More importantly, grab Burp proxy, install old (vulnerable) versions of web apps, and start playing around. You'll find XSS, SQLi, and plenty of other fun things in no time.
Also, my contact info is in my profile if you have other questions.