<feed xmlns='http://www.w3.org/2005/Atom'>
<title>ctf-website/src, branch master</title>
<subtitle>The website for a Capture The Flag competition.</subtitle>
<id>https://git.amat.us/ctf-website/atom/src?h=master</id>
<link rel='self' href='https://git.amat.us/ctf-website/atom/src?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/'/>
<updated>2012-04-06T20:39:30Z</updated>
<entry>
<title>Updated flags list.</title>
<updated>2012-04-06T20:39:30Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-06T20:39:30Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=6632d4b8993b4676357a6ac6797788bae7d5d981'/>
<id>urn:sha1:6632d4b8993b4676357a6ac6797788bae7d5d981</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Be a bit more polite with failed logins.</title>
<updated>2012-04-06T20:39:03Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-06T20:39:03Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=4f3ae689ab81ac6daad115db7a0fdf32a0a6c984'/>
<id>urn:sha1:4f3ae689ab81ac6daad115db7a0fdf32a0a6c984</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added two new flags to home page with some reformatting.</title>
<updated>2012-04-06T05:58:48Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-06T05:58:48Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=a832dce3558c0c104ad0722110589f7b0ec4ff9c'/>
<id>urn:sha1:a832dce3558c0c104ad0722110589f7b0ec4ff9c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added list of challenges.</title>
<updated>2012-04-06T03:28:42Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-06T03:28:42Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=7e0e286e9b1441240c89a032f8687c6a4eeefa84'/>
<id>urn:sha1:7e0e286e9b1441240c89a032f8687c6a4eeefa84</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Throttle account creation.</title>
<updated>2012-04-06T03:11:59Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-06T03:11:59Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=5e66967a341052649226051731c5fb84b9592555'/>
<id>urn:sha1:5e66967a341052649226051731c5fb84b9592555</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Created flag and scoreboard database.</title>
<updated>2012-04-05T05:22:13Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-05T05:22:13Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=805348adff5ad6ee0efa42e24dbd84aed4249225'/>
<id>urn:sha1:805348adff5ad6ee0efa42e24dbd84aed4249225</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Avoid html injection.</title>
<updated>2012-04-05T03:19:02Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-05T03:19:02Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=8c193293c6f42e8dd1522c8d5cd26febc8a20f02'/>
<id>urn:sha1:8c193293c6f42e8dd1522c8d5cd26febc8a20f02</id>
<content type='text'>
This is probably unnecessary because valid unix usernames
don't have any bad characters in them.
</content>
</entry>
<entry>
<title>Added flag form and login sessions.</title>
<updated>2012-04-05T02:59:12Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-05T02:59:12Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=abbb4cf8b090bb95087f52dcc42927d13f792e36'/>
<id>urn:sha1:abbb4cf8b090bb95087f52dcc42927d13f792e36</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Improved new account security.</title>
<updated>2012-04-05T02:30:58Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-05T02:29:02Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=58d95efffff28e28d4f8db885b7abe7613728740'/>
<id>urn:sha1:58d95efffff28e28d4f8db885b7abe7613728740</id>
<content type='text'>
Since chpasswd takes multiple username:password lines
it was possible to change the password of any account:
curl -data "username=attacker&amp;password=%0aroot:omghax" -k https://ctf/new
</content>
</entry>
<entry>
<title>Moved login form.</title>
<updated>2012-04-05T02:28:39Z</updated>
<author>
<name>David Barksdale</name>
<email>amatus.amongus@gmail.com</email>
</author>
<published>2012-04-05T02:28:39Z</published>
<link rel='alternate' type='text/html' href='https://git.amat.us/ctf-website/commit/?id=d2c5278e5995c05949a2bcf431b9b0793b4f0522'/>
<id>urn:sha1:d2c5278e5995c05949a2bcf431b9b0793b4f0522</id>
<content type='text'>
</content>
</entry>
</feed>
