anyone have any good resources for understanding the basics of all of this?
For level 1 to 3, Google those: system() exploit, never trust user input, buffer overflow
Hack your way through Stripe's Capture the Flag
121–130 of 219 posts
Re: Hack your way through Stripe's Capture the Flag
#122Re: Hack your way through Stripe's Capture the Flag
#123Anyone having trouble connecting to this?
This is why we can't have nice things.
Re: Hack your way through Stripe's Capture the Flag
#124Re: Hack your way through Stripe's Capture the Flag
#125Earlier quoted context omitted.
Stuck at level3 for a minute
Same, the only thing I can think of is doing something with the pointers in the fns variable in main, but I can't quite figure out what to do.
Several posters have hinted at buffer overflow, but I'm not yet seeing a buffer that I can overflow.
[edit: Nevermind, I got it. Whew.]
Re: Hack your way through Stripe's Capture the Flag
#126If people are going to be using brute-force tactics, they're probably each going to need separate virtual machines.
Re: Hack your way through Stripe's Capture the Flag
#127Re: Hack your way through Stripe's Capture the Flag
#128Re: Hack your way through Stripe's Capture the Flag
#129Earlier quoted context omitted.
I think the machine was actually hosed due to fork bomb. (I kept bumping the rlimits as more people logged in and ran up against nprocs, but the last time I clearly just bumped nprocs way too high. Live and learn....) You certainly should be able to solve all of the levels without tons of brute force though.
Oops, thought that no one had commented when I deleted. Sorry.
Re: Hack your way through Stripe's Capture the Flag
#130Earlier quoted context omitted.
Must be fun watching all of the attempts... Do you have any way to monitor progress?
We don't have an exposed way. We'll probably do a summary blog post in the future with stats though!
"User 10.0.0.1 read the level 1 file" "User 10.0.0.1 read the level 3 file"
Then I am a stats junkie