Network Computing is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

For Hackers, By a Hacker: Page 2 of 2

I squeaked out a win in the tie-breaking challenge the first day with only a few seconds to spare as my opponent was right behind in the hunt to combine three injectable fields into one long javascript function. (Each field was limited in length, and the overall javascript alert needed to win required all three to be joined, with some clever escaping to re-assemble correctly after the injection)

In the finals (thanks Jeremiah for the pics and the kind words!) my competition was a skilled security officer from a large medical device company head-quartered in Switzerland. While I was lucky enough to win in only two rounds, it could have easily gone to three. I was quite glad it didn't as it turned out the final challenge would have been quite a dozy -- a multi-part problem involving reverse engineering a pseudo encryption javascript function to crack a password.

Walking away with the win (and a cool GPS and entrance to RSA next year) was a lot of fun. I get to hold my head high, post a blog entry for hackers by a hacker, and I suppose if writing doesn't work out, I might just have a future hacking--excuse me--securing web applications.