Coming soon: Stripe CTF3, distributed systems edition
stripe.com
stripe.com
The whole thing was very fun, I highly recommend anyone interested in security to give it a go. The XSS challenges were also cool: they ran a headless webkit browser to emulate a user so your XSS code actually did something.
I know it's got a couple bugs still, but the first levels should be pretty solid.
The last level involved compromising one of the earlier servers iirc because the pw dbs only responded in-network. The "Password Database" was chunked amongst a few servers, requiring an increase in the port number on the response due to a waterfall type password check (ie: if chunk1 is correct, go hit chunk2 server and check). You also had to re-check your chunks because other people's requests were making the port increase as well. I had a huge rush when my script finally stopped and my "password" showed up on screen.
Definitely looking forward to one based in distributed systems as I've been researching that sort of stuff over the last year and such.
I started brute forcing before the jitter was very bad but only got one chunk in with my Python script.
I rewrote my solution in Go (which does http pipelining) and I could solve a whole password in about 4 minutes even during the peak time during the day when everyone was trying.
My Go solution could reliably get 10-20 valid port numbers in a row during peak times, and only jittered for 3 port numbers or so.
(I started my last block at about the same time as Eevee, but it ended up being 8044 so I had to settle for 21st place)
When I came to HN and saw a lot of people I admire talking about how hard it was, especially daeken [1], I remember thinking something along the lines of "well, I thought it was hard but not that hard", and decided to try to find a few security bugs in open source software... Best thing I ever did... In just a few weeks I found some nice bugs on both Drupal and Wordpress, got the first CVE credited to myself, and then I started to have fun (and some profit) with the various bug bounty programs around the web, most notably those run by Google (I'm currently 0x05 overall) [2] and Facebook (7th) [3].
After a year doing security work on the side I was able to quit my day job last august and now I make my living basically as a security consultant and also as a "bounty hunter". I also got multiple job offers from US companies (I currently live in Brazil).
And all of this happened only because the stripe CTF gave me the confidence to actually follow my dreams. Oh, and I still don't know if I have what it takes to be really successful in the field, but frankly security bugs are everywhere so I go ahead and keep on finding them. I'm learning a lot every single day and the mean time between bugs is getting lower and lower, which is great. So thank you Stripe. Thank you very much.
Shameless plug: BTW, I'm in the committee for the W2SP conference, so if anyone has some interesting discovery to share, please submit a paper.
[1] https://news.ycombinator.com/item?id=4424299 [2] https://www.google.com/about/appsecurity/hall-of-fame [3] https://www.facebook.com/whitehat/thanks [4] http://www.w2spconf.com/2014/
Well that and all of your hard work and talent.
Thanks a lot for the work you put into these things!
"Our Paxos implementation is closer to Raft algorithm than to what you'd read in Paxos paper which is… horrible."
http://www.infoq.com/presentations/spanner-distributed-googl...
There's certainly been a lot more interest lately in building distributed systems, and in certain models mostly related to databases. I think a lot of this has been pushed by a few companies with an interest in either pushing these fields forward or being known as experts. A good example might be Basho, who've generated a lot of buzz around the Ricon conferences and the Think Distributed podcast.
To be clear, I think this is a good thing. I personally think distributed systems are a really interesting topic, and a big swell in interest generates discussion and lots of interesting reading material. :) Granted it also generates a lot of faddishness and crap, but that's the price of any kind of wide interest in a topic.
And really, while there's some crap out there, a lot of it's actually really good. I've been enjoying aphyr's recent blogging about Jepsen, a lot of the recorded talks from Ricon West were really interesting, and there's been some good discussion on Twitter and lobste.rs related to these topics.
So sure, the valley might be treating this like a fad. They also do that with *.js and obscure editor plugins. :) But in this case I think that's not a bad thing.
Is that because your words are a little bit challenging?
I'm with you. Distributed Computing is not new, especially it's not only about a couple of algorithms. But looks like folks here are only familiar with the algorithms, such as the algorithms used by Google.
Actually Distributed Computing means a lot more than that. I'm going to write some blog about that, but not quite ready yet.