<h2 id="overview">Overview</h2> <p>I had a great time playing quals this year with Shellphish. I usually try to write full-length stories for my writeups (see my blog archives for a few), but this one will be a bit less complete for time reasons.</p> <h2 id="challenge-description">Challenge description</h2> <blockquote> <p>Are you hearing what I’m hearing?</p> <p>HOST:…
This year was Samurai’s third time playing Hack A Sat’s (HAS) quals round. The first time we played, we qualified for finals. Year 2, we didn’t qualify. So this year we were hoping to qualify again. I personally wasn’t super involved in the first year, and only a bit involved last year (I don’t think the weekends lined up super great for me), but I was interested to take a shot at it this year and…
This weekend, Samurai played the DEF CON CTF Qualifier event. We had a great time playing; much thanks to the organizers for putting on a great event! Many thanks to my teammates, it was awesome playing with you all! One of the challenges this weekend was called <code>baby-a-fallen-lap-ray</code>. It was categorized as a <code>pwn</code> challenge, and it made a comment about being ‘the return of…
I had the opportunity to compete in the CSAW CTF Finals 2018 for a second year in a row, with the <a href="https://umbccd.umbc.edu/">UMBC Cyber Dawgs</a>. It was a lot of fun, despite our somewhat lackluster finish in 10th place. I learned a lot. For instance, in this challenge, I learned how to exploit a Use-After-Free vulnerability (in WebAssembly no doubt!).
I recently had the opportunity to compete in the <a href="https://csaw.engineering.nyu.edu/ctf">CSAW CTF Finals</a> with the <a href="http://umbccd.umbc.edu/">UMBC Cyber Dawgs</a>. It was an amazing competition; the organizers were awesome and did a great job. We placed 7th in North America, by the way :) If you’ve never heard of CSAW before, it’s a huge student-run security…
<p>So if you’re here, you’re probably one of three types of people. Most likely is that I sent you here because you were wondering why the heck I mentioned this on social media. It’s also possible that you actually care about why I generated a GPG key. I happen to like my explanation, and I hope you do too :) Additionally, in the unlikely case that you just want my key, you can…
<p>So I wrote a blog post about my process of creating my March Madness bracket last year, so I figure this year I’ll revisit it and explain what I changed. (Note: I know this post is actually after March Madness started… but I’ve been busy. I did actually create the bracket before the games began.)</p> <p>I used <a href="https://www.codersbracket.com/">Coder’s Bracket</a>…
I’m just okay at picking basketball brackets. I usually finish somewhere in the upper third of the pack, IIRC. However, it’s interesting to enter a bracket and watch the results come in (I almost never watch the games), so I usually make a bracket. This year, I decided to use <a href="https://www.codersbracket.com/">Coder’s Bracket</a> to create my bracket.
As I thought about setting up my website and email, I wanted to have a way to give out disposable email addresses. That way, I can give Widget Co an email address unique to them, and I can know if they sell my email because I will get emails from Sprockets Inc. at my address for Widget Co. In that case, I can trash all email sent to that address, eliminating that spam.