Nombre de usuario: 
Contraseña: 
Vincular sesión a esta IP 

Challenge Idea : Fun Factor?

Clasificación global: 615
Puntuación total: 41358
Mensajes: 5
Agradecer: 3
Voto positivo: 3
Registrado: 11A 250d
Ávatar de Wixxerd

El usuario está desconectado
Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
I have an idea for a challenge(s) where I provide the visitor with a TextAea, and a paragraph detailing tables available in a database. They have to submit a query that produces resultsets based upon the criteria in the paragraph.

I don't think they'll wind up being high ranking (really hard) challenges, but was curious if anyone would find them fun? I could do variations..."You're attached to a MySQL database and need to return a result joining these tables, sorted blah blah, with only 5 results, etc."

Their submissions would run against the tables (after I cleaned up injection vectors) and then check their results. I could encapsulate their queries in tries so as to not produce fugly errors, and strip out all the drops, delete, sp calls, etc. when I clean it for injection.

What you guys think? Worth it?
Clasificación global: 31
Puntuación total: 313502
Mensajes: 54
Agradecer: 79
Voto positivo: 58
Registrado: 16A 70d










Última vez visto: 23h 38m
El usuario está desconectado
RE: Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
It definatelly worth it.. I find it very good idea!

Maybe some will not find it very fun to play with challenges like these but it will be very educational if the queries become more and more complex. And if i remember correctly i think there were a couple of challenges like these in some challenge site but i can't remember which one.

But as you already know it needs a very careful setup because there could be attack vectors that go beyond the challenge and could result in bringing down your site..That's why many result in simulating solution queries which i don't think would work in this case..
Puntuación total: 316955
Mensajes: 98
Agradecer: 105
Voto positivo: 105
Registrado: 14A 333d







Última vez visto: 60d 1h
El usuario está desconectado
RE: Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
Cita de criple_ripper
Octubre 21, 2012 - 15:06:40

But as you already know it needs a very careful setup because there could be attack vectors that go beyond the challenge and could result in bringing down your site..That's why many result in simulating solution queries which i don't think would work in this case..


As I think already nearly happened after talking to dloser Smile
The challenge was up briefly then taken down after it was deemed unsafe - Wixxerd: I suggest having challenges beta tested before putting them online, but be sure your testers are up to the job.
Without meaning to volunteer anyone, you need to be looking to the like of dloser, tehron, criple_ripper and people of this calibre in order to get a thorough test done.
If you find time, head onto the irc (server: irc.idlemonkeys.net channel: #wechall) and ask around there, most of us are happy to help and we're available there a lot more than we are available here Smile

As you know, I too am happy to help out where I can (depending on my work situation) so drop me a line, and good luck with getting this fixed Smile

sabre
https://www.revolutionelite.co.uk/
Última edición por sabretooth - Octubre 21, 2012 - 15:14:41
Clasificación global: 615
Puntuación total: 41358
Mensajes: 5
Agradecer: 3
Voto positivo: 3
Registrado: 11A 250d
Ávatar de Wixxerd

El usuario está desconectado
RE: Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
I've gotten a few really good suggestions already for securing it. (Don't worry was most definitely still in beta... Along with several other play versions...Smile ) Definitely moving it to a different DB instance that doesn't have anything else on it... I don't want the focus of these "specific" ones to be injection, but I find it hard to believe it wont get tried... a lot. Happy
Última edición por Wixxerd - Octubre 21, 2012 - 15:58:11
Clasificación global: 544
Puntuación total: 46268
Mensajes: 220
Agradecer: 205
Voto positivo: 214
Registrado: 13A 181d
Ávatar de space
El usuario está desconectado
RE: Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
Cita de sabretooth
Octubre 21, 2012 - 15:13:14

Without meaning to volunteer anyone, you need to be looking to the like of dloser, tehron, criple_ripper and people of this calibre in order to get a thorough test done.

You forgot kwisatz and jjk… Happy
Contact only via c3BhY2VAd2VjaGFsbC5uZXQ= or PM...
Windows can be secure... but only if you don't use it Happy
Puntuación total: 316955
Mensajes: 98
Agradecer: 105
Voto positivo: 105
Registrado: 14A 333d







Última vez visto: 60d 1h
El usuario está desconectado
RE: Challenge Idea : Fun Factor?
Google/Traductor0¡Gracias!0Buen mensaje!0Mal mensaje! link
Cita de space
Octubre 21, 2012 - 18:37:36

You forgot kwisatz and jjk… Happy



Cita de sabretooth
Octubre 21, 2012 - 15:13:14

and people of this calibre


;)
https://www.revolutionelite.co.uk/
tunelko, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, kalungmas se suscribieron a este tema y reciben emails en nuevas publicaciones.
1 personas están viendo el tema ahora mismo.
Este tema ha sido visto 2720 veces.