Live data from Hacker News

'; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

stripe.com

21–30 of 80 posts

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#21
post #19

Definitely wish time wasn't a factor - on Level 3, but just don't have the time to commit to it :/ Maybe later tonight

Ditto. I would totally spend a few hours on this if I didn't have work to do :/ Maybe after you complete a level you could get the choice of "Pause the game" or "give me the next challenge" ?

Don't worry -- even if you don't get to play this week, we'll be releasing the levels afterwards so you can run them yourself at home.

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#24
Shameless, ala tptacek: Enjoying this challenge? We do similar things on a daily basis over at Tinfoil Security. We develop tools to attack websites in a lot of similar ways to this Stripe CTF. We're hiring in Palo Alto, and even if you've never done appsec work before, we'd love to chat.

https://www.tinfoilsecurity.com/jobs

(Or, you know, ask Stripe or Matasano for a job. They're both crazy awesome, have a ton of respect from me, and are also hiring.)

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#26
Shameless, following tptacek and borski's examples: Having fun finding broken code? Want to get paid without going to the effort of writing exploits? You might want to look at the Tarsnap (or scrypt, or kivaloo, or spiped) code and see if you can win some bug bounties: http://www.tarsnap.com/bugbounty.html

(Or, you know, ask Stripe or Matasano or Tinfoil Security for a job. They'll pay you far more than you'd ever get from Tarsnap's bug bounties.)

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#27
I really enjoyed this until I got stuck on level 3. I have a bunch of ideas about what the solution might be but I'm not good. Are there any websites with challenges similar to this that are more geared towards someone that isn't so great at this sort of thing? A "beginner" at security stuff?

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#28
post #20

Shameless: Enjoying this challenge? You'd enjoy working with us. We're hiring in Chicago, in Mountain View, and in Manhattan. This stuff is our day-to-day, plus reversing, custom protocols, tool development, and exotic applications. If you've never done appsec work professionally, but find these challenges fun and straightforward, we'd love to talk to you: We've hired more people off HN than from any other vector. ww…

Matasano also likes interns! I worked with them for the past two summers and can't say enough good about the experience. You will learn (or get to practice) the things tptacek mentioned above as well as web apps, mobile, ruby, a staggering amount of crypto, and whatever else you find interesting to work on or ask about. If you're into this stuff, check them out!

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#30

I really enjoyed this until I got stuck on level 3. I have a bunch of ideas about what the solution might be but I'm not good. Are there any websites with challenges similar to this that are more geared towards someone that isn't so great at this sort of thing? A "beginner" at security stuff?

You may want to check out the Reading Materials section on https://stripe-ctf.com/about.
Post reply on HN