Select your language

Solutions and end of the Web Security challenges from RootedCON'2010 CTF

All good things are over... After just over a month of competition and a magnificent reception, I conclude the security contest. The statistics have been impressive: more than 1000 participants (700+ registered at the start of the contest) and 18 "web ninjas" who managed to pass each and every one of the tests (a relatively high number considering that there were really complicated tests).

The winner of the prize (iPod touch 4G) has been the first classified: PPP (Plaid Parliament of Pwning), an American team of known technical solvency, which has had to beat with other teams very seasoned in the hacking of web applications such as "FluxFingers" [third classified] (who has not read the magnificent articles of Reiners: [1], [2] and [3]) and even with solo people like our crack and friend Kachakil (in addition to teammate in "int3pids") [second placed].

There has been a great technical level and the contest was not easy (powerful and well-known teams such as the French Nibbles did not manage to overcome all the tests) so I take my hat off to those who have managed to finish them all successfully: ius, pepelux, okaboy, s3ntin3l, phib, ...). Of course, we must also recognize the effort and merit of the rest of the participants. You can check the top 25 of the classifieds or even access the complete "hall of fame".

The contest, which could be followed at all times thanks to my twitter (@roman_soft), had one more peculiarity: the "hall of shame" (or wall of shame :-)). This functionality of the new panel was not intended to be more than an experiment and at the same time a kind of joke: when a participant tried to hack the panel, it automatically introduced it into the "hall of shame", without further ado. The participant was not disqualified (despite being expressly prohibited from attacking the panel, according to the contest rules). I just wanted to demonstrate how the vast majority of participants would try to hack the panel and in fact it was (although luckily for me, without success :-P). As a result, a large part of the winners are part not only of the "hall of fame" but also of the "hall of shame" :-) On a technical level, I only placed a few check-points, strategically located, as a honeypot. It was more than enough ;-)).

Surely many of you are curious to know how one or more tests were passed... isn't it? I leave you the four solutions that I have received, compressed into a single file. Its authors are: ppp, pepelux, danitorre and miguel (very good work, guys!). For more information, don't forget to read the "readme" inside. And if you want to continue practicing (or try some of the techniques described in the solutions), hurry up and take advantage now that it is still possible: I will leave the challenge online for a while (maybe another month although it is not safe) although of course, it will no longer be possible to score. As always, I will try to warn via twitter of any news.

- Publicidad -

Finally, we would like to thank Bernardo Quintero and Hispasec Sistemas, sponsor of the contest, for their selfless support. And of course, to all of you who have participated in the contest and who are the ones who have really made this event great in every way. Thank you all!

Source: Roman Soft

Authors:

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter