1,086 karma · joined October 9, 2015
https://www.jaybosamiya.com/
[ my public key: https://keybase.io/jaybosamiya; my proof: https://keybase.io/jaybosamiya/sigs/-EdQtpSs9_8ZyWniQnhgxI6WXAkSB9snpQa3MyY3y_Q ]
[1]: https://github.com/nmap/nmap/commit/f2e162d2245679f420b40feb...
I learnt about this tool from Emery Berger's talk [2] on this (at strangeloop), which I highly recommend. Lots of really nice insight, even outside of this tool.
[1] https://github.com/plasma-umass/coz [2] https://www.youtube.com/watch?v=r-TLSBdHe1A
> If more than one contestant registers for a given category, the order of the contestants will be drawn at random. Based on the contestant order, the first contestant will be given an opportunity to attempt to compromise the selected target. If unsuccessful, the next randomly drawn contestant will be given an opportunity. This will continue until a contestant successfully compromises the target. The first contestant to successfully compromise a selected target will win the prize money for that target in that category. After a target has been compromised, the contest for that category is over and no other contestants will participate in the contest for that category (unless Sponsor has offered an additional winner option, which would be announced at the conference if applicable).
I still haven't been able to do complete code execution yet, but have reasons to believe it might be possible.
Simply using `x1` as input causes it to print "deadbeef11 is not defined". Additionally, parens are allowed, and there is the `=>` arrow syntax for defining functions. Thus, we have a way to define variables, a way to define lambda abstractions, as well as a way to perform applications. Therefore, we have the untyped lambda calculus. This is Turing complete, so I have reason to believe that it should be possible to execute arbitrary code. I just need to find some time to do so :)
Update: `(x1=>x1(x1))(x1=>x1(x1))` gives "Too much recursion" :D
Link(s): [0] https://www.uky.edu/~eushe2/Pajares/Kuhn.html
Related GitHub project (sandsifter): https://github.com/xoreaxeaxeax/sandsifter
Whitepaper: https://github.com/xoreaxeaxeax/sandsifter/blob/master/refer...
The RE101 and RE102 courses are created and run by Amanda Rousseau (Malware Unicorn), and she is amazing for giving back to the community constantly. I would definitely recommend following her on Twitter : https://twitter.com/malwareunicorn
The reason I bring all of this up, is since your typo "securedog" reminded me of (coincidentally) @malwareunicorn's 2 dogs : Malware Research Dog, and RE Pup. Absolutely adorable dogs :)
The reason I bring this up is because of the "always"
Link(s): [1] http://multivax.com/last_question.html
The plan of action: keep at it by attacking more wargames and CTF (capture the flag) contests. Also, I should probably try to consider bug bounties, to be able to orient the skills to real world problems as well.
Also, I would suggest looking into Tien-Tsin Wong's other works [2] as well. A lot of great ideas and papers there.
[1] https://appsrv.cse.cuhk.edu.hk/~ttwong/papers/asciiart/ascii... [2] https://appsrv.cse.cuhk.edu.hk/~ttwong/publication-favorite....
> document.addEventListener('keydown', function(event) { ... })
Basically, press any key on your keyboard on the website, and it'll work.
https://en.wikipedia.org/wiki/Foremost_%28software%29
A `sudo apt-get install foremost` works on Ubuntu to install it, IIRC
https://en.wikipedia.org/wiki/The_Hitchhiker's_Guide_to_the_...
The existence of the Babel Fish would make such questions much much simpler.
quicksort [] = []
quicksort (x:xs) = quicksort [y|y<-xs,y<x] ++ [x] ++ quicksort [y|y<-xs,y>=x]