Przed chwilą wrzuciłem na youtube video z mojej prelekcji z SEConference 2013, z dnia drugiego (o CTF, etc). Prelekcję z dnia pierwszego (o ZIP, etc) wrzucę w przeciągu paru dni. Pozostając przy tej tematyce, parę dni temu na mój kanał wrzuciłem też dwa podcasty o tym jak rozwiązać dwa zadanka z poprzedniego CTF - SIGINT 2013 - konkretniej crash oraz punchcard; linki poniżej.
SEConference 2013: CTFs, and Compos, and WarGames! Oh, my!
Video: http://www.youtube.com/watch?v=dEdHS1n_UCE
Slajdy: http://goo.gl/GNg6E
O prelekcji pisałem również w tym poście.
Podcasty Gynvael's CTF
Gynvael's CTF: SIGINT CTF 2013 punchcard (300) - kategoria: programming / crackme.
Gynvael's CTF: SIGINT CTF 2013 crash (400) - kategoria: pwning (binary exploitation).
Dodam, że więcej write-upów z CTFów można znaleźć na blogu naszego teamu CTFowego - Dragon Sector.
Jak pisałem wyżej, za kilka dni powinienem wrzucić video z dnia pierwszego (muszę je jeszcze tylko poskładać).
I tyle.

Sections
- lang:
|
- RSS:
|
- About me
- Tools
- → YT YouTube (EN)
- → D Discord
- → M Mastodon
- → T Twitter
- → GH GitHub
Links / Blogs
- → dragonsector.pl
- → vexillium.org
- Security/Hacking:
- Reverse Eng./Low-Level:
- Programming/Code:
Posts
- My howto script,
- Talk: PCI Express to Hell,
- Live: On Leaving Google and What's Next,
- Thoughts on overlarge fields in formats and protocols,
- On self-healing code and the obvious issue,
- LLM + Clean Room: Will LLMs be the death of code copyrights?,
- Solving a VM-based CTF challenge without solving it properly,
- Asking MEMORY.DMP and Volatility to make up,
- KnightCTF 2023 write-ups (RE category),
- Dev Log: Moving contacts from Android to MaxCom MM721,
- → see all posts on main page
// copyright © Gynvael Coldwind
// design & art by Xa
// logo font (birdman regular) by utopiafonts / Dale Harris
/* the author and owner of this blog hereby allows anyone to test the security of this blog (on HTTP level only, the server is not mine, so let's leave it alone ;>), and try to break in (including successful breaks) without any consequences of any kind (DoS attacks are an exception here) ... I'll add that I planted in some places funny photos of some kittens, there are 7 of them right now, so have fun looking for them ;> let me know if You find them all, I'll add some congratz message or sth ;> */
Vulns found in blog:
* XSS (pers, user-inter) by ged_
* XSS (non-pers) by Anno & Tracerout
* XSS (pers) by Anno & Tracerout
* Blind SQLI by Sławomir Błażek
* XSS (pers) by Sławomir Błażek
// design & art by Xa
// logo font (birdman regular) by utopiafonts / Dale Harris
/* the author and owner of this blog hereby allows anyone to test the security of this blog (on HTTP level only, the server is not mine, so let's leave it alone ;>), and try to break in (including successful breaks) without any consequences of any kind (DoS attacks are an exception here) ... I'll add that I planted in some places funny photos of some kittens, there are 7 of them right now, so have fun looking for them ;> let me know if You find them all, I'll add some congratz message or sth ;> */
Vulns found in blog:
* XSS (pers, user-inter) by ged_
* XSS (non-pers) by Anno & Tracerout
* XSS (pers) by Anno & Tracerout
* Blind SQLI by Sławomir Błażek
* XSS (pers) by Sławomir Błażek
Comments:
"...parę dni temu mój kanał wrzuciłem..."
brakuje chyba - na -
"...parę dni temu na mój kanał wrzuciłem..."
Ups. Fixed, thanks :)
Add a comment: