HC's Capture the Flag website
CTF Contests
25C3-CTF

25C3-CTF final results

List of advisories

TeamAdvisoryStatusRating
WiiPhoniesBY: c1de0x service: vdspi severity: medium (details)rejected[0] too late
WiiPhoniesBY: John_K service: CGIBAS severity: high (details)rejected[0] too late
OpenTUBY: anonymous coward service: goffer severity: low (details)rejected[0] too late
Ailuropoda MelanoleucasBY: Samsa service: vdspi severity: medium (details)rejected[0] there is a much more practical and effective fix
h4ck!nb3rgBY: churchy service: all? severity: low (details)accepted[2] yapp. It's serious
WiiPhoniesBY: John_K service: Team SquareRoots severity: high (details)rejected[0] no comment
squarerootsBY: manager service: ultrashare severity: medium (details)rejected[0] Not in the original version. Maybe another team modified this at your box.
Janet Reno Redemption Fund$BY: adc service: ultrashare severity: medium (details)rejected[0] Not enough information. Maybe dup.
61xor42BY: hc service: teamimage severity: low (details)accepted[1] True, geta ya one point
WiiPhoniesBY: c1de0x service: CGIBAS severity: high (details)rejected[0] one score is nuff ... there were already too many scores given out for these bugs
nosec/!eofBY: thorben service: ICANHASGOFERDEE severity: high (details)rejected[0] was already reported
Ailuropoda MelanoleucasBY: Samsa service: tcpserver severity: medium (details)rejected[0] stralloc_append does bounds checking
WiiPhoniesBY: John_K service: ULTRASHARE severity: high (details)accepted[2] Yapp.
WiiPhoniesBY: c1de0x service: CGIBAS severity: high (details)accepted[1] nice :-))
hohhBY: EQ service: Goferdee severity: high (details)rejected[0] was already reported
KEVABY: slashd service: cashflag severity: low (details)rejected[0] That fix doesn't work, because it doesn't distinguish between real and faked flags
Janet Reno Redemption Fund$BY: anonymous coward service: advisory system severity: low (details)rejected[0] oh, and you think THIS advisory is not silly?
Stealth AssassinBY: thaidn service: Goferdee severity: high (details)accepted[1] correct, but empty impact section
Stealth AssassinBY: lamer service: gopherdee severity: high (details)accepted[1] nice fix
KEVABY: slashd service: Cashflags severity: low (details)rejected[0] Please clarify the 'impact'-section of your report
Ailuropoda MelanoleucasBY: Samsa service: ultrashare severity: low (details)rejected[0] Yeah, but in my opinion this is fixed already by your previous fix (see #90)
Janet Reno Redemption Fund$BY: adc service: General severity: low (details)rejected[0] I think we told you to change it;)
squarerootsBY: manager service: CGIBAS severity: low (details)accepted[1] well done
hohhBY: EQ service: Goferdee severity: high (details)rejected[0] Hmm, you mean you should fix the vulnerability? How? ;)
h4ck!nb3rgBY: BfrOv3rfl0w service: cgibase severity: low (details)rejected[0] big news
SpaceBoyZBY: struppi service: VDspi severity: low (details)rejected[0] too late
Janet Reno Redemption Fund$BY: adc service: CONTEST severity: HIGH (details)rejected[0] Living may result in dying
h4ck!nb3rgBY: churchy service: ultrashare severity: low (details)accepted[1] Just a small test script, but you;re right. This is a bug.
mr. grinchBY: anonymous coward service: ultrashare severity: medium (details)rejected[0]
Janet Reno Redemption Fund$BY: adc service: CGIBAS severity: low (details)accepted[1] ok
HeroeZBY: anonymous coward service: Goferdee severity: medium (details)rejected[0] Fix missing
HeroeZBY: anonymous coward service: Goferdee severity: low (details)rejected[0] Impact, fix missing;-(
Ailuropoda MelanoleucasBY: Samsa service: ultrashare severity: medium (details)accepted[2] Yes. You're right. Sessions should be used more carefully.
WiiPhoniesBY: John_K service: CGIBAS severity: high (details)accepted[1] not exactly new (see adv sumthin from sq), but extend of bug is now realized
Janet Reno Redemption Fund$BY: anonymous coward service: Goferdee severity: high (details)rejected[0] Sorry, you were too late
Stealth AssassinBY: thaidn service: UltraShare severity: medium (details)rejected[0] Its a dup! They proposed the same solution and addressed the same problem. The main problem relies in @db.deleteFile. The fix fixes the same thing.
Janet Reno Redemption Fund$BY: adc service: Cashflags severity: low (details)rejected[0] Not a problem of cachflags, can you propose an alternate protocol?
h4ck!nb3rgBY: churchy service: ultrashare severity: low (details)accepted[2] Thats nice.
Stealth AssassinBY: thaidn service: UltraShare severity: medium (details)rejected[0] I cannot delete a user without admin rights in my version.
Stealth AssassinBY: thaidn service: UltraShare severity: medium (details)rejected[0] Duplicate of #60
Stealth AssassinBY: thaidn service: ultrashare severity: medium (details)rejected[0] I doubt that. It s finally checked in deleteUser, isnt it? first line: if admin? ... If Im wrong, plz repost adv
SpaceBoyZBY: struppi service: VDspi severity: low (details)rejected[0] too late
OpenTUBY: anonymous coward service: goffer severity: medium (details)accepted[2] nice one :)
Stealth AssassinBY: bluemood service: cgibas severity: medium (details)rejected[0] has been posted first time some hours ago
Stealth AssassinBY: thaidn service: Ultrashare severity: high (details)accepted[2] Yes. I already forgot that I have introduced this bug.
squarerootsBY: manager service: ultrashare severity: low (details)accepted[1] ok.
squarerootsBY: manager service: VDspi severity: low (details)rejected[0] b0ring
squarerootsBY: manager service: CGIBAS severity: low (details)rejected[0] b0ring
squarerootsBY: manager service: goferdee severity: low (details)rejected[0] Admin problem
Janet Reno Redemption Fund$BY: adc service: cgibas severity: high (details)rejected[0] has been reported by squareroots a while ago
h4ck!nb3rgBY: churchy service: ultrashare severity: low (details)accepted[2] your right. XXS is a big issue in this service.
Stealth AssassinBY: lamer service: ultrashare severity: high (details)accepted[2] Your are right.
dameuse-pelteuseBY: het service: VDS severity: high (details)rejected[0] Fix your service plz :P
WiiPhoniesBY: John_K service: VDSI severity: high (details)accepted[1] already reported, but point for the detailed fix :)
DiskinBY: diskin service: CGIBAS severity: low (details)rejected[0] no more XSS for cgibas, please
squarerootsBY: manager service: CGIBAS severity: high (details)accepted[3] very nice
Ailuropoda MelanoleucasBY: Samsa service: vdspi severity: low (details)accepted[1] ok.
Stealth AssassinBY: bluemood service: cgibas severity: low (details)accepted[1] violates FCFS policy (single exception from rule), but still - I like it
h4ck!nb3rgBY: churchy service: ultrashare severity: low (details)accepted[4] Cool. I was not aware of this bug
61xor42BY: lwi service: cgibas severity: low (details)rejected[0] (1) no more XSS for cgibas, please (2) more elaborated fixes, plz
WiiPhoniesBY: c1de0x service: CGIBAS severity: medium (details)rejected[0] (1) no more XSS for cgibas, please (2) more elaborated fixes, plz
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: medium (details)accepted[1] would have given more points for fix in BASIC. well, you didn't wanted to have them ;-P
h4ck!nb3rgBY: churchy service: ultrashare severity: medium (details)accepted[3] This bug is new to me.
int80BY: scyclops service: vdspi severity: low (details)accepted[2] yup.
h4ck!nb3rgBY: churchy service: ultrashare severity: low (details)accepted[2] Yes. This counts :-)
WiiPhoniesBY: Ge0rG service: vdspi severity: high (details)accepted[2] correct.
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: medium (details)rejected[0] fix is not elaborated enough
nosec/!eofBY: watz service: ultrashare severity: low (details)rejected[0] The original config.rb was correct. Maybe you change something...
Janet Reno Redemption Fund$BY: adc service: VDspi severity: medium (details)accepted[2] correct.
OpenTUBY: anonymous coward service: goffer severity: high (details)rejected[0] Good, but this was already reported
gongbaojidingBY: js service: vdspi severity: high (details)rejected[0] too late
gongbaojidingBY: js service: 10.131.1.2 severity: high (details)rejected[0] Service "10.13.1.2" doesn't exist;)
Stealth AssassinBY: thaidn service: vdspi severity: medium (details)rejected[0] doesn't really fix the issue
Stealth AssassinBY: thaidn service: vdspi severity: medium (details)rejected[0] missing fix
WiiPhoniesBY: Ge0rG service: vdspi severity: low (details)accepted[1] yep.
WiiPhoniesBY: Ge0rG service: vdspi severity: high (details)accepted[2] yep.
gongbaojidingBY: js service: ultrashare severity: medium (details)accepted[1] Yes! It s a sql injection
WiiPhoniesBY: Ge0rG service: cgibas severity: low (details)accepted[3] wow - finally a nicely printed fix :-))
Stealth AssassinBY: lamer service: vdspi severity: medium (details)rejected[0] missing fix
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: medium/high (details)accepted[2] y00
h4ck!nb3rgBY: churchy service: ultrashare severity: medium (details)rejected[0] It's not a SQL Injection. Fix isn't working
nosec/!eofBY: watz service: cgibas severity: medium (details)rejected[0] boring
nosec/!eofBY: Silicium service: cgibas severity: medium (details)rejected[0] too unspecific fix
OpenTUBY: anonymous coward service: unknown/several severity: high (details)rejected[0] Sry. Neither it's a service nor a system related bug. (only those are counting)
KEVABY: slashd service: cgbas severity: medium (details)rejected[0] too late - see advisory 25
WiiPhoniesBY: Ge0rG service: vdspi severity: low (details)rejected[0] proposed fix introduces a new bug - service could return unintended results
Stealth AssassinBY: thaidn service: vdspi severity: high (details)accepted[2] yes.
WiiPhoniesBY: Ge0rG service: LeetWWW severity: low (details)accepted[1] Sorry about that; but you are right: 8080 is indeed the correct port
KEVABY: slashd service: cgibass severity: high (details)rejected[0] no precise problem and impact description
Stealth AssassinBY: lamer service: gopherdee severity: high (details)rejected[0] Fix missing => Reject.
Stealth AssassinBY: lamer service: vdspi severity: low (details)rejected[0] missing fix. you don't have to provide source code, the right concept is sufficient.
dameuse-pelteuseBY: het service: vdspi severity: high (details)accepted[2] It's pretty hard to get all the automatic checks disabled, BTW.
Stealth AssassinBY: lamer service: vdspi severity: low (details)rejected[0] missing fix, sorry. it's not that hard...
WiiPhoniesBY: Ge0rG service: vdspi severity: high (details)accepted[2] yup.
WiiPhoniesBY: Ge0rG service: vdspi severity: high (details)accepted[2] yup.
Stealth AssassinBY: lamer service: cgibas severity: high (details)accepted[2] this fix is not really complete and will result in synatx error, but is sufficient for points
Ailuropoda MelanoleucasBY: ailurotest service: ICANHASGOFERDEE severity: medium (details)accepted[2] ok.
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: medium (details)accepted[1] japp
h4ck!nb3rgBY: fid service: system severity: medium (details)accepted[1] ok.
squarerootsBY: manager service: CGIBAS severity: high (details)rejected[0] advisory 20 was faster, sorry
nosec/!eofBY: thorben service: /etc/passwd severity: low (details)accepted[1] ok.
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: high (details)accepted[3] very nice
Stealth AssassinBY: lamer service: cgibas severity: medium (details)accepted[2] though problem description is wrong, fix will work
nosec/!eofBY: cjay service: vdspi severity: medium (details)accepted[1] ok.
OpenTUBY: anonymous coward service: CGIBASS severity: high (details)rejected[0] is not a problem of the service, but rather of the OS - we consider this not applicable for scores
Ailuropoda MelanoleucasBY: Samsa service: cgibas severity: high (details)rejected[0] please specify fix in code or be more verbose
nosec/!eofBY: thorben service: goffer severity: low (details)rejected[0] too late.. other team was faster
nosec/!eofBY: thorben service: vdspi severity: low (details)rejected[0] too late.. other team was faster
KEVABY: slashd service: cgibas severity: high (details)rejected[0] fix should be code, or at least reasonable explicit
61xor42BY: lwi service: lighttpd/web2.0 severity: low (details)rejected[0] no fix given
Ailuropoda MelanoleucasBY: ailurotest service: ICANHASGOFERDEE severity: high (details)rejected[0] We need more details
KEVABY: slashd service: cgibas severity: medium (details)rejected[0] no fix given
KEVABY: slashd service: cgibas severity: medium (details)rejected[0] no fix given
h4ck!nb3rgBY: fid service: VDspi severity: high (details)rejected[0] absence of user/pass authentication is by design
KEVABY: slashd service: cgibas severity: medium (details)rejected[0] no fix given
h4ck!nb3rgBY: churchy service: ultrashare severity: high (details)accepted[1] Yes. you are right.
KEVABY: slashd service: cgibass severity: high (details)rejected[0] missing fix
Ailuropoda MelanoleucasBY: ailurotest service: testing123 severity: low (details)rejected[0] Please stop reporting Test Adv.
Ailuropoda MelanoleucasBY: ailurotest service: severity: low (details)accepted[1] Thx for testing
localhostBY: hc service: noch ein advi severity: sory, high (details)accepted[1] asdf
localhostBY: hc service: zweites severity: foo (details)accepted[5] cool
localhostBY: hc service: foo severity: rl (details)rejected[0] asdf

Team ranks -- Service states -- Advisories -- Pending advisories


Impressum