<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: 25C3: CTF dominated by iphone-dev team, HackMii</title>
	<atom:link href="http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:57:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Pragmatk</title>
		<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/comment-page-1/#comment-59765</link>
		<dc:creator><![CDATA[Pragmatk]]></dc:creator>
		<pubDate>Sun, 18 Jan 2009 19:17:42 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7352#comment-59765</guid>
		<description><![CDATA[There were no buffer overflows.
Challenges / services:
- insecure setups / &quot;trojaned&quot; configs
- An Ada service with a rather obvious backdoor (and some less obvious) + a search flaw which led to revelation (and therefore retrieval) of flags.
- A real funny perl implementation of BASIC as a CGI-handler. It had some unsanitized open()-calls which enabled arbitrary file reads, command execution through pipes, etc.
- Some Ruby web service which I must admit I didn&#039;t understand much of.

[I might have missed one or two there, but you get the concept. There wasn&#039;t any &quot;real&quot; overflow-stuff]

Your age comment is ridiculous, blizzarddemon. Those guys won because they were quick to grasp the system setup and develop methods for systematically collecting the &quot;flags&quot; (hashes) from the other contestants and because of their ability to navigate through the treacherous config files (those were causing our team, the Janet Reno Redemption Fund, real problems - I think three hours passed before we *found* the last two services), not because of their age. I&#039;m 15, and I think the oldest person in our team was 40-something, so we had the whole range covered - so why didn&#039;t we win?! ;o)]]></description>
		<content:encoded><![CDATA[<p>There were no buffer overflows.<br />
Challenges / services:<br />
- insecure setups / &#8220;trojaned&#8221; configs<br />
- An Ada service with a rather obvious backdoor (and some less obvious) + a search flaw which led to revelation (and therefore retrieval) of flags.<br />
- A real funny perl implementation of BASIC as a CGI-handler. It had some unsanitized open()-calls which enabled arbitrary file reads, command execution through pipes, etc.<br />
- Some Ruby web service which I must admit I didn&#8217;t understand much of.</p>
<p>[I might have missed one or two there, but you get the concept. There wasn't any "real" overflow-stuff]</p>
<p>Your age comment is ridiculous, blizzarddemon. Those guys won because they were quick to grasp the system setup and develop methods for systematically collecting the &#8220;flags&#8221; (hashes) from the other contestants and because of their ability to navigate through the treacherous config files (those were causing our team, the Janet Reno Redemption Fund, real problems &#8211; I think three hours passed before we *found* the last two services), not because of their age. I&#8217;m 15, and I think the oldest person in our team was 40-something, so we had the whole range covered &#8211; so why didn&#8217;t we win?! ;o)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blizzarddemon</title>
		<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/comment-page-1/#comment-57601</link>
		<dc:creator><![CDATA[blizzarddemon]]></dc:creator>
		<pubDate>Fri, 02 Jan 2009 02:20:27 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7352#comment-57601</guid>
		<description><![CDATA[Impressive, seeing the focus of there groups, I&#039;d bet these guys might also be younger then the rest of the other folks attending. I&#039;ve seen both groups work and I&#039;ve yet to be disappointed.]]></description>
		<content:encoded><![CDATA[<p>Impressive, seeing the focus of there groups, I&#8217;d bet these guys might also be younger then the rest of the other folks attending. I&#8217;ve seen both groups work and I&#8217;ve yet to be disappointed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zamadatix</title>
		<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/comment-page-1/#comment-57254</link>
		<dc:creator><![CDATA[Zamadatix]]></dc:creator>
		<pubDate>Tue, 30 Dec 2008 15:37:33 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7352#comment-57254</guid>
		<description><![CDATA[amazing bootmii demo video:  

http://www.youtube.com/watch?v=9oaq9i4fmeg]]></description>
		<content:encoded><![CDATA[<p>amazing bootmii demo video:  </p>
<p><span style="text-align:center; display: block;"><a href="http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/"><img src="http://img.youtube.com/vi/9oaq9i4fmeg/2.jpg" alt="" /></a></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TJHooker</title>
		<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/comment-page-1/#comment-57253</link>
		<dc:creator><![CDATA[TJHooker]]></dc:creator>
		<pubDate>Tue, 30 Dec 2008 15:31:15 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=7352#comment-57253</guid>
		<description><![CDATA[They probably learned routing algorithms and buffer overflows way before they started reverse engineering firmware; they&#039;d have to actually.]]></description>
		<content:encoded><![CDATA[<p>They probably learned routing algorithms and buffer overflows way before they started reverse engineering firmware; they&#8217;d have to actually.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

