7 May 2004 Stevey   » (Master)

HOWTO

I've almost finished the first draft of the 'Source Code Auditing HOWTO', modelled upon the documentation already available in the Linux Documentation Project.

I'll be posting this in livejournal shellcode community in a day or two for comment.

Wargames

I've also put together a challenging wargame on a spare machine.

A user signs up for an account and recieves the password for the account 'level1' on my box.

Once they login a message is displayed, and they must exploit the '~/bin/level2' binary which is setuid(level2), this will enable them to read the password to level2, where the process repeats itself.

So far I have four levels put together of gradually increasing complexity.

I still have a couple of things to do, then we'll go live with some local people.

I'm not sure the box is restricted enough to open it to the world, although I'm looking forward to reading the syslog and captured information.

Latest blog entries     Older blog entries

New Advogato Features

New HTML Parser: The long-awaited libxml2 based HTML parser code is live. It needs further work but already handles most markup better than the original parser.

Keep up with the latest Advogato features by reading the Advogato status blog.

If you're a C programmer with some spare time, take a look at the mod_virgule project page and help us with one of the tasks on the ToDo list!