<?xml version="1.0"?>
<!-- name="generator" content="blosxom/2.0" -->
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN" "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">
  <channel>
    <title>SensePost qow   </title>
    <link>http://www.sensepost.com/qow</link>
    <description>Question of the Week</description>
    <language>en</language>

  <item>
    <title>When Harry met Sally</title>
    <pubDate>Tue, 24 Jul 2007 14:57:00 </pubDate>
    <link>http://www.sensepost.com/qow/qow-2.html</link>
    <description>
&lt;p&gt;Harry and Sally met online and fell deeply in love. Harry wishes to send
Sally an engagement ring via snail-mail but...&lt;/p&gt;

&lt;p&gt;The local postal service pilfer anything that is not locked in a box with a
padlock.&lt;/p&gt;

&lt;p&gt;Harry and Sally both have lots of boxes (and lots of padlocks) but none
where each has a copy of the key..&lt;/p&gt;

&lt;p&gt;How can Harry get his Ring to Sally ?&lt;/p&gt;

&lt;p&gt;/mh&lt;/p&gt;

&lt;p&gt;PS.. i _dont_ claim credit for coming up with this puzzle (or the
solution)&lt;/p&gt;

&lt;p&gt;PPs: For Bonus points, whats this solution better known as?&lt;/p&gt;
</description>
  </item>
  <item>
    <title>XSS - Not just for girls!</title>
    <pubDate>Mon, 7 May 2007 16:36:00 </pubDate>
    <link>http://www.sensepost.com/qow/qow-1.html</link>
    <description>
&lt;p&gt;
Update:
&lt;/p&gt;

&lt;p&gt;Ok.. so 31 chars allowed a quick thinking &amp;lt;img src=&quot;http://x.y.z.a&quot;&amp;gt; which
got the browser out.. option is gone.. limit is 30 chars (we can keep going to
make this arb. smaller.. so the solution is not to find the smallest ip/domain
u can get ur hands on :&gt; &lt;/p&gt;

&lt;p&gt;/mh&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;You are faced with a web based application that you know is vulnerable to XSS. You have seen the code.. Now once you submit your details, it will be viewed by an admin/other-user&lt;/p&gt;

&lt;p&gt;[This QoW is a simple version.. if you can XSS yourself, you win]&lt;/p&gt;

&lt;p&gt;All you need to do to claim victory, is to submit your details so that the resultant page re-directs you to a listening netcat.&lt;/p&gt;

&lt;p&gt;No cookie-grab needed (maybe we want to steal the guys referer)...&lt;/p&gt;

&lt;p&gt;Vulnerable form is &lt;a href=&quot;http://qow.sensepost.com/qow1/qow1.html&quot;&gt;here&lt;/a&gt;, a copy of the CGI's source is &lt;a href=&quot;http://qow.sensepost.com/qow1/qow1&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;TIP: U can see from the code, that your stuff has to fit into 31 chars...&lt;/p&gt;

&lt;hr /&gt;

The answer is available &lt;a href=&quot;http://www.sensepost.com/blog/1267.html&quot;&gt;here&lt;/a&gt;.
</description>
  </item>
  <item>
    <title>What is Question of the Week (QoW)?</title>
    <pubDate>Sun, 6 May 2007 16:36:00 </pubDate>
    <link>http://www.sensepost.com/qow/whatisthis.html</link>
    <description>
&lt;h3&gt;What is it?&lt;/h3&gt;

During the course of our assessments we often bump into interesting / exciting problems. For years we have then converted these to mini labs in a virtual environment to ensure that all SensePosters got to play along too. (This way everyone gets to benefit, and we get a bunch of alternative strategies to tackle problems at any given time.)

&lt;h3&gt;It's called QoW. Is it released every week?&lt;/h3&gt;

Its name was set to question of the week way back in 2002 when the QoW setter had more time. These days it is more likely to happen every fortnight. (This is why its RSS'd.)

&lt;h3&gt;What's this video stuff?&lt;/h3&gt;

The video link holds some sanitized videos created for some interesting attacks. Where it makes sense, a video will demo the QoW answer after the new qustion is posted...

&lt;h3&gt;Is there a link to past questions?&lt;/h3&gt;

We are not putting a full list of past QoWs up (mainly so we can stagger them fairly routinely while diving into our past qows). We will keep all available ones linked online.

&lt;h3&gt;Where's the `the' in `QoW'?&lt;/h3&gt;

It got lost.
</description>
  </item>
  </channel>
</rss>