The whole thing was very fun, I highly recommend anyone interested in security to give it a go. The XSS challenges were also cool: they ran a headless webkit browser to emulate a user so your XSS code actually did something.
The whole thing was very fun, I highly recommend anyone interested in security to give it a go. The XSS challenges were also cool: they ran a headless webkit browser to emulate a user so your XSS code actually did something.
When I came to HN and saw a lot of people I admire talking about how hard it was, especially daeken [1], I remember thinking something along the lines of "well, I thought it was hard but not that hard", and decided to try to find a few security bugs in open source software... Best thing I ever did... In just a few weeks I found some nice bugs on both Drupal and Wordpress, got the first CVE credited to myself, and then I started to have fun (and some profit) with the various bug bounty programs around the web, most notably those run by Google (I'm currently 0x05 overall) [2] and Facebook (7th) [3].
After a year doing security work on the side I was able to quit my day job last august and now I make my living basically as a security consultant and also as a "bounty hunter". I also got multiple job offers from US companies (I currently live in Brazil).
And all of this happened only because the stripe CTF gave me the confidence to actually follow my dreams. Oh, and I still don't know if I have what it takes to be really successful in the field, but frankly security bugs are everywhere so I go ahead and keep on finding them. I'm learning a lot every single day and the mean time between bugs is getting lower and lower, which is great. So thank you Stripe. Thank you very much.
Shameless plug: BTW, I'm in the committee for the W2SP conference, so if anyone has some interesting discovery to share, please submit a paper.
[1] https://news.ycombinator.com/item?id=4424299 [2] https://www.google.com/about/appsecurity/hall-of-fame [3] https://www.facebook.com/whitehat/thanks [4] http://www.w2spconf.com/2014/
Well that and all of your hard work and talent.
The last level involved compromising one of the earlier servers iirc because the pw dbs only responded in-network. The "Password Database" was chunked amongst a few servers, requiring an increase in the port number on the response due to a waterfall type password check (ie: if chunk1 is correct, go hit chunk2 server and check). You also had to re-check your chunks because other people's requests were making the port increase as well. I had a huge rush when my script finally stopped and my "password" showed up on screen.
Definitely looking forward to one based in distributed systems as I've been researching that sort of stuff over the last year and such.
I know it's got a couple bugs still, but the first levels should be pretty solid.
I started brute forcing before the jitter was very bad but only got one chunk in with my Python script.
I rewrote my solution in Go (which does http pipelining) and I could solve a whole password in about 4 minutes even during the peak time during the day when everyone was trying.
My Go solution could reliably get 10-20 valid port numbers in a row during peak times, and only jittered for 3 port numbers or so.
(I started my last block at about the same time as Eevee, but it ended up being 8044 so I had to settle for 21st place)