Securing Stripe's Capture the Flag
blog.gregbrockman.com
blog.gregbrockman.com
Were any unexpected security vulnerabilities found (or patched mid-game by you) in the overall infrastructure?
Not sure if this was intentionally left open-ended but for example in Level 6 I exploited a Ruby session/cookie bug to gain access to the target user, before realizing that the easier way was just a simpler JavaScript XSS vulnerability.
It looks like homakov had a little fun with it (the guy who griefed github a bit half a year ago with their whitelisted attributes vulnerability and got the rails core team to put whitelisting on by default).
Thought for a minute after seeing the headline maybe the CTF was closed... I'd have thrown many (more) monitors out the window if I didn't get to finish lvl8 after spending so long on it...or at least ditch a few more monitors trying to finish it.
This was really fun to play, and I learned a thing or two (specifically the manner in which you solve #7 was totally new to me).
Thanks for putting the CTF together!
http://grsecurity.net/ http://en.wikibooks.org/wiki/Grsecurity http://en.wikipedia.org/wiki/Grsecurity http://en.wikipedia.org/wiki/PaX
Grsec's RBAC isn't strictly necessary, but it's quite nice too.
What was the amount of traffic at peak times between level 2 and 8?
root@leveleight2:~# ifconfig eth0 |tail -n 2 RX bytes:8200746652 (8.2 GB) TX bytes:27399989757 (27.3 GB)
Well, of course it is...
Seriously, what else is out there like this?
/facepalm