TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ghost in the Shellcode

68 点作者 notmine1337将近 3 年前

3 条评论

withzombies将近 3 年前
I wrote another Ghost in the Shellcode story up on twitter thread[0], but I&#x27;d like to share it here also.<p>In 2013, I wrote a GitS challenge called &quot;hackerbook&quot;. It was a &quot;misc&quot; challenge where I presented you with a series of photos of prominent hackers at the time and asked you their name. It worked on the same principle as reCaptcha, I only knew the names of about 30 of the hackers and put those into the database. For the remaining ones, I accepted any answer but logged it to the database. If you correctly named all the 30 that I knew, you got the flag.<p>I wrote it because I thought it&#x27;d be funny to get people to give up the real names of their friends. I also thought it might be a good way to harvest the names of hackers[1] who are opsec thought leaders. For the remaining photos, I went to every CTF team&#x27;s twitter, facebook, flickr, etc and sliced out random people.<p>The challenge worked pretty well at de-anonymizing a few folks. One player even sent me a photo of his friend&#x27;s passport, claiming my challenge was broken and not accepting the correct name.<p>I think we already knew most people would give away all their personal details for a chance to win a free ice cream but they&#x27;ll also give away their friends details for made up internet points.<p>[0] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;withzombies&#x2F;status&#x2F;1529145520027054081" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;withzombies&#x2F;status&#x2F;1529145520027054081</a><p>[1] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;thegrugq" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;thegrugq</a>
merlincorey将近 3 年前
&gt; There may have been others, but this is how I remember it.<p>Uh, yeah, DC949 ran Open Capture The Flag (OCTF) at Defcon from 2005 through at least 2010[0].<p>We later ran the original Barcode Shmarcode[1] contest during Snowpocalypse at Shmoocon so I know the Ghost in the Shellcode team was at least somewhat aware of DC949.<p>[0] <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9Gs2Ja6Gt4Q" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=9Gs2Ja6Gt4Q</a> - DEFCON 18: oCTF: 5 years in 50 minutes 1&#x2F;4 (2010)<p>[1] <a href="https:&#x2F;&#x2F;www.shmoocon.org&#x2F;barcode-shmarcode&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.shmoocon.org&#x2F;barcode-shmarcode&#x2F;</a> - Shmoocon: Barcode Shmarcode
评论 #31530548 未加载
评论 #31530242 未加载
withzombies将近 3 年前
If you&#x27;re new to CTF and want to try your hand at it, the qualifying round for DEFCON CTF starts tonight.<p>DEFCON is easily the most prestigious of the CTF competitions, so much so that it needs to pre-qualify the teams competing and that competition[0] starts tonight and runs all weekend.<p>[0] <a href="https:&#x2F;&#x2F;nautilus.institute&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nautilus.institute&#x2F;</a>