Slashdot Log In
Network Computing Editor Wins RSA Hacking Contest
Posted by
Zonk
on Sun Feb 18, 2007 08:28 PM
from the hack-on-hack-off dept.
from the hack-on-hack-off dept.
richkarpi writes "Network Computing's security editor won the recent RSA Interactive Testing Challenge. He has up a blow-by-blow description of the events at their site: 'The most important factor in the contest besides basic web exploitation skills (cross site scripting (XSS), SQL injection, cross site request forgeries (CSRF), etc.) was speed ... I squeaked out a win in the tie-breaking challenge the first day with only a few seconds to spare as my opponent was right behind in the hunt to combine three injectable fields into one long javascript function.'"
This discussion has been archived.
No new comments can be posted.
Network Computing Editor Wins RSA Hacking Contest
|
Log In/Create an Account
| Top
| 65 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Meh (Score:5, Funny)
(http://en.wikipedia.org/wiki/User:DavidHOzAu)
Re:Meh (Score:5, Funny)
(Last Journal: Sunday November 06 2005, @10:30PM)
You're right because real hackers are banned from the internet. You're not a real hacker til you get charged as one.
1m a 1337 h4x0r!!!!!1 (Score:4, Funny)
Re:1m a 1337 h4x0r!!!!!1 (Score:5, Funny)
(http://www.rulingwars.net/)
Re:Meh (Score:5, Insightful)
Besides, I never claimed that I was a "real hacker".
(yes, that's me. Holy crap, I've been slashdotted!)
Re:Meh (Score:4, Informative)
He did ask permission to use the Framework before doing so, which he "happened" to have on a USB stick. The point of the exercise was application testing, not rooting the Windows 2000 server that we forgot to install a firewall on. Whoops, our bad!
Having never seen him before, we didn't know he really was HD Moore until we used images.google.com to find out.
Congrats again Jordan, hope to see you next year since you won a free pass!
Re:Meh (Score:5, Funny)
Knock on door from Homeland Security in 3..2..1 (Score:2, Funny)
Wonder what the expense report looks like (Score:2)
(Last Journal: Friday May 18, @11:07AM)
Re:Wonder what the expense report looks like (Score:5, Funny)
And yes, I was drinking dew for the finals:
http://www.rsaconference.com/2007/US/press/photos
Time victory = valid? (Score:5, Funny)
Re:Time victory = valid? (Score:5, Funny)
(http://slashdot.org/my/logout)
That's Nothing (Score:2, Funny)
This one time, I was hacking this really locked-up-the-wazoo Gibson. I'd set up a couple of IDS/IPS evasion bots, perimeter scanning came up clean. Small SQL injection issue merged with XSS showed that the backend database may have been either 768-bit encrypted or a simple 3DES matter, but I was running low on time and didn't get to check. Once the tables were writable to sa, I was able to jump in and jump out with no problem. One of their systems caught an early sniff, but was shut down with a smurf. Everything was PERFECT until their night noc ran a reverse udp traceroute back to one of the hosts I had set up after that, straight DOWNHILL. I got called twice by my isp asking about unusual activity, some other shit about access attempts to a federally monitored system, and they had everything in logs including the Schneier-level, rot-26 I thought would hide me. Fortunately I managed to find a reverse-folding routepath on their IIS Apache and I got out just in time while erasing the incriminating forum posts.
Posted anonymously for obvious reasons.
web security != security (Score:2)
(http://geexology.org/ | Last Journal: Tuesday October 11 2005, @07:25PM)
More interesting (Score:2)
Yeah, sure.... (Score:5, Funny)
Mitnick warned me about hacker tricks like that... I for one am not going to RTFA!
The CSRF and XSS FAQ (Score:3, Informative)
(http://www.cgisecurity.com/)
The XSS FAQ [cgisecurity.com]
The Cross-site Request Forgery FAQ [cgisecurity.com]
Why I disable Javascript by default... (Score:2)
Contest Requirements? (Score:2, Funny)
Yeah, but how would he do against Chloe Sullivan? (Score:3, Funny)
(http://www.myke.com/)
Of course, their cover could be working for the Mormons...
myke
Re:Ugh (Score:2)
He wasn't insulting the intelligence of Mormons. He was just remarking on how odd it is that an employee of a *church* was so talented. And it is odd. You would expect that someone so skilled would be more likely to be working for a "tech" company.
Re:Ugh (Score:4, Informative)
Read it again and you'll notice I also included myself in the category of "people you wouldn't expect in the finals of a web hacking competition". So unless you think I was also calling myself stupid, I wasn't belittling anyone. Merely pointing out that neither of us were the first folks you'd expect to see in the semi-finals.