4 ms·
The last stripe CTF literally changed my life. I've always been interested in security but didn't have the confidence and honestly thought I didn't have it take
by reginaldo 13y ago
The last stripe CTF literally changed my life. I've always been interested in security but didn't have the confidence and honestly thought I didn't have it takes to be successful in the field. I decided to try the CTF anyway just for fun and was able to finish everything much to my surprise. I had read about SHA-1 padding when it affected Flickr so I knew just what to do on the level that involved SHA-1 padding, which I thought was the hardest.
When I came to HN and saw a lot of people I admire talking about how hard it was, especially daeken [1], I remember thinking something along the lines of "well, I thought it was hard but not that hard", and decided to try to find a few security bugs in open source software... Best thing I ever did... In just a few weeks I found some nice bugs on both Drupal and Wordpress, got the first CVE credited to myself, and then I started to have fun (and some profit) with the various bug bounty programs around the web, most notably those run by Google (I'm currently 0x05 overall) [2] and Facebook (7th) [3].
After a year doing security work on the side I was able to quit my day job last august and now I make my living basically as a security consultant and also as a "bounty hunter". I also got multiple job offers from US companies (I currently live in Brazil).
And all of this happened only because the stripe CTF gave me the confidence to actually follow my dreams. Oh, and I still don't know if I have what it takes to be really successful in the field, but frankly security bugs are everywhere so I go ahead and keep on finding them. I'm learning a lot every single day and the mean time between bugs is getting lower and lower, which is great. So thank you Stripe. Thank you very much.
Shameless plug: BTW, I'm in the committee for the W2SP conference, so if anyone has some interesting discovery to share, please submit a paper.
[1] https://news.ycombinator.com/item?id=4424299 https://news.ycombinator.com/item?id=4424299
[2] https://www.google.com/about/appsecurity/hall-of-fame https://www.google.com/about/appsecurity/hall-of-fame
[3] https://www.facebook.com/whitehat/thanks https://www.facebook.com/whitehat/thanks
[4] http://www.w2spconf.com/2014/ http://www.w2spconf.com/2014/
- milesokeefe 13y ago>And all of this happened only because the stripe CTF Well that and all of your hard work and talent.
- dikei 13y agoThat's a very inspiring story. Kudos to you.