<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Games for Web Hackers</title>
	<atom:link href="http://www.disenchant.ch/blog/games-for-web-hackers/35/feed" rel="self" type="application/rss+xml" />
	<link>http://www.disenchant.ch/blog/games-for-web-hackers/35</link>
	<description>Blog of Sven Vetsch / Disenchant</description>
	<lastBuildDate>Tue, 02 Mar 2010 12:16:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Disenchant</title>
		<link>http://www.disenchant.ch/blog/games-for-web-hackers/35/comment-page-1#comment-1228</link>
		<dc:creator>Disenchant</dc:creator>
		<pubDate>Tue, 09 Jan 2007 09:00:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/games-for-web-hackers/35#comment-1228</guid>
		<description>Hi kuza55,
first I have to say that just as I wrote, these are just ideas so everyone can create something new out of it and this aren&#039;t complete concept of web hacking games :)

I fully agree with you that the XSS Contest isn&#039;t that interesting for people which are already working or just having fun in the webapplication security field but for example I&#039;ll do something like this in a course for students because in this way, the get the point of finding XSS vulnerabilities, where they can find them and directly have some hands on training. This I think will be fun for them and it takes only about one hour and nearly no preparation.

About #3 you&#039;re absolutely right, of course this have to be a blackbox testing because else the people can just compare the original sourcecode with the modified one and find all vulnerabilities very easy. The coolest way here of course would be if someone wrote a complete new application and then you can also offer the source to the participants which makes it much more interesting but I don&#039;t think that there are so many webapp developers out there which would do that.

So #2 and #3 from my point of view can be interesting but you have to do it in a specific way with the right people and we don&#039;t have to discuss about idea #1, of course it&#039;s the most interesting and if someone is going to set up something like this, let me know ;)</description>
		<content:encoded><![CDATA[<p>Hi kuza55,<br />
first I have to say that just as I wrote, these are just ideas so everyone can create something new out of it and this aren&#8217;t complete concept of web hacking games <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I fully agree with you that the XSS Contest isn&#8217;t that interesting for people which are already working or just having fun in the webapplication security field but for example I&#8217;ll do something like this in a course for students because in this way, the get the point of finding XSS vulnerabilities, where they can find them and directly have some hands on training. This I think will be fun for them and it takes only about one hour and nearly no preparation.</p>
<p>About #3 you&#8217;re absolutely right, of course this have to be a blackbox testing because else the people can just compare the original sourcecode with the modified one and find all vulnerabilities very easy. The coolest way here of course would be if someone wrote a complete new application and then you can also offer the source to the participants which makes it much more interesting but I don&#8217;t think that there are so many webapp developers out there which would do that.</p>
<p>So #2 and #3 from my point of view can be interesting but you have to do it in a specific way with the right people and we don&#8217;t have to discuss about idea #1, of course it&#8217;s the most interesting and if someone is going to set up something like this, let me know <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kuza55</title>
		<link>http://www.disenchant.ch/blog/games-for-web-hackers/35/comment-page-1#comment-1215</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Mon, 08 Jan 2007 23:57:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/games-for-web-hackers/35#comment-1215</guid>
		<description>I think idea number 1 would be heaps of fun; you could include obscure and interesting bugs in them, so that even if people don&#039;t win they learn something, etc.

On #2; Its an interesting idea, but crawling over sites just to input &lt;code&gt;&quot;&gt;&lt;b&gt;test&lt;/b&gt;&lt;/code&gt; everywhere isn&#039;t exactly my idea of fun. Frankly that would bore me to tears honestly.

#3 is half way in between, in that sure you *can* put interesting vulns in there, but this is probably a black box approach, and so any interesting vulns there

So personally I&#039;d probably only participate in #1, because I can see it being much more interesting than the other two where the vulns are just going to be the standard run of the mill attacks we deal with every day - either that or they&#039;ll be almost impossible to find, and in #2, they might not even exist.</description>
		<content:encoded><![CDATA[<p>I think idea number 1 would be heaps of fun; you could include obscure and interesting bugs in them, so that even if people don&#8217;t win they learn something, etc.</p>
<p>On #2; Its an interesting idea, but crawling over sites just to input <code>&quot;&gt;&lt;b&gt;test&lt;/b&gt;</code> everywhere isn&#8217;t exactly my idea of fun. Frankly that would bore me to tears honestly.</p>
<p>#3 is half way in between, in that sure you *can* put interesting vulns in there, but this is probably a black box approach, and so any interesting vulns there</p>
<p>So personally I&#8217;d probably only participate in #1, because I can see it being much more interesting than the other two where the vulns are just going to be the standard run of the mill attacks we deal with every day &#8211; either that or they&#8217;ll be almost impossible to find, and in #2, they might not even exist.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Crypto</title>
		<link>http://www.disenchant.ch/blog/games-for-web-hackers/35/comment-page-1#comment-1203</link>
		<dc:creator>Crypto</dc:creator>
		<pubDate>Mon, 08 Jan 2007 14:00:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.disenchant.ch/blog/games-for-web-hackers/35#comment-1203</guid>
		<description>Great idea!! There is a scenario based web game up and running right now http://www.hackthissite.org/. The XSS contest would be relatively easy to get together too.</description>
		<content:encoded><![CDATA[<p>Great idea!! There is a scenario based web game up and running right now <a href="http://www.hackthissite.org/" rel="nofollow">http://www.hackthissite.org/</a>. The XSS contest would be relatively easy to get together too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
