Stripe CTF Post Mortem: A Would-Be Hacker's Tale
stephenwhitmore.com
Stripe CTF Post Mortem: A Would-Be Hacker's Tale
1–10 of 11 posts
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#2Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#3He didn't talk about the last level for some reason.
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#4Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#5He didn't talk about the last level for some reason.
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#6
That doesn't look like the work of a very talented hacker. Whatever happened to readfile() ?The attack could also have been a lot more interesting if .php files were disallowed but short snippets like this could be hidden inside GIF images.
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#7That doesn't look like the work of a very talented hacker. Whatever happened to readfile() ? The attack could also have been a lot more interesting if .php files were disallowed but short snippets like this could be hidden inside GIF images.
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#8That doesn't look like the work of a very talented hacker. Whatever happened to readfile() ? The attack could also have been a lot more interesting if .php files were disallowed but short snippets like this could be hidden inside GIF images.
In one of the rounds the attack was exactly that, payload inside a gif
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#9That doesn't look like the work of a very talented hacker. Whatever happened to readfile() ? The attack could also have been a lot more interesting if .php files were disallowed but short snippets like this could be hidden inside GIF images.
Why not? Do all talented hackers use 'readfile()'?
Re: Stripe CTF Post Mortem: A Would-Be Hacker's Tale
#10He didn't talk about the last level for some reason.