Live data from Hacker News

'; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

stripe.com

51–60 of 80 posts

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#56
post #47

Gah, I'm stuck on level 4. I've never really dealt with security in ruby / sinatra / sequel applications.

... Yeah, me too. If you check out the "about" page [1], there's IRC info at the bottom [2], so there may be hints there. 1: https://stripe-ctf.com/about 2: irc://irc.stripe.com:+6697/ctf Edit: the IRC helped. the issue isn't ruby, sinatra, etc.

I was stumped by disbelief. Well, now I know that Stripe isn't lazy.

Re: '; CREATE TABLE `Capture the Flag`;' -- Stripe's Web Security CTF is Live

#60

This is suprisingly fun. At first, you feel like a badass, reading the documentation for every function call, googling for exotic bugs. Then you feel like a total idiot when you notice how simple it actually is. Finally, you laugh at people in the IRC because you know exactly how stupid they feel.

The most frustrating thing was knowing exactly what the exploit was, but not quite getting how to take advantage of it.
Post reply on HN