<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><description></description><title>The Esquire of Oz</title><generator>Tumblr (3.0; @esquireofoz)</generator><link>https://esquireofoz.tumblr.com/</link><item><title>Tumblr's 4th Annual Security Capture the Flag</title><description>&lt;p&gt;&lt;a href="https://security.tumblr.com/post/174852292580/tumblrs-4th-annual-security-capture-the-flag" class="tumblr_blog"&gt;security&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;We’ve hosted an internal Security Capture the Flag (&lt;a href="https://www.alienvault.com/blogs/security-essentials/capture-the-flag-ctf-what-is-it-for-a-newbie"&gt;CTF&lt;/a&gt;) event for four years in a row now, with each year getting better than the last!&lt;br/&gt;&lt;/p&gt;
&lt;h2&gt;
&lt;a href="https://github.tumblr.net/Tumblr/engineering-blog-articles/blob/fb10ea316a5d8d3a2c53bcdd890d473b306dc9f9/articles/122%20-%20Security%20CTF%202018.md#the-event"&gt;&lt;/a&gt;The event&lt;/h2&gt;
&lt;p&gt;Previously, we were only open to Tumblr employees. This year we decided to extend an invite out to the other teams housed under our parent company, &lt;a href="https://www.oath.com/"&gt;Oath&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;All participants had a three hour window to hack, a buffet of tacos, beer, and wine to dive into, and a stack of prizes for the top four players (see &lt;b&gt;Prizes&lt;/b&gt; below for details)!&lt;/p&gt;
&lt;p&gt;Challenges were available Jeopardy-style, broken down by category. We had eight fun categories to select from:&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Auth Bypass (&lt;a href="https://www.owasp.org/index.php/Testing_for_Bypassing_Authentication_Schema_(OTG-AUTHN-004)"&gt;authn&lt;/a&gt; | &lt;a href="https://www.owasp.org/index.php/Testing_for_Bypassing_Authorization_Schema_(OTG-AUTHZ-002)"&gt;authz&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)"&gt;Cross Site Request Forgery (CSRF)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)"&gt;Cross Site Scripting (XSS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Cryptanalysis"&gt;Crypto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Computer_forensics"&gt;Forensics&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Reverse_engineering"&gt;Reverse Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.owasp.org/index.php/SQL_Injection"&gt;SQL Injection (SQLi)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://www.owasp.org/index.php/Testing_for_XML_Injection_(OTG-INPVAL-008)"&gt;XML Injection&lt;/a&gt; (+ &lt;a href="https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing"&gt;XXE&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;&lt;p&gt;We also sprinkled a few “inside joke” Easter eggs around the system that awarded bonus points to anyone that discovered them! For example, if they attempted to find a hole in the CTF system itself and navigated to &lt;code&gt;/wp-admin&lt;/code&gt;, we’d give them a flag on a prank WordPress page; or perhaps testing to find XSS with a &lt;code&gt;&amp;lt;marquee&amp;gt;&lt;/code&gt; tag — only the greatest of all XSS tags!&lt;/p&gt;
&lt;p&gt;While the Security Team walked around and helped out, we also setup a mini &lt;a href="http://shmoocon.org/lockpick-village/"&gt;lockpick village&lt;/a&gt; just because.&lt;/p&gt; &lt;p&gt;&lt;a href="https://security.tumblr.com/post/174852292580/tumblrs-4th-annual-security-capture-the-flag" class="tmblr-truncated-link read_more"&gt;Keep reading&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;</description><link>https://esquireofoz.tumblr.com/post/174885686157</link><guid>https://esquireofoz.tumblr.com/post/174885686157</guid><pubDate>Thu, 14 Jun 2018 11:36:35 -0400</pubDate></item><item><title>pcwt:




GIRO’18 Stage 3: Double Eilat TelaViviani!




Elia...</title><description>&lt;img src="https://78.media.tumblr.com/2f4b320f1a7c25dd80f3c1f03c01de6d/tumblr_p8cupt0tOF1ruscp7o7_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/e18b2f1d4ce0e162926163d96334564b/tumblr_p8cupt0tOF1ruscp7o1_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/28e366c4fbb62d4f1082b0fc09b6f251/tumblr_p8cupt0tOF1ruscp7o3_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/968db48d6f77ec41075d4d381b153781/tumblr_p8cupt0tOF1ruscp7o6_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/6929b8eab7783f2d9d364292e9435b28/tumblr_p8cupt0tOF1ruscp7o10_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/6d2896133182b8292ffcab801c069af8/tumblr_p8cupt0tOF1ruscp7o9_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/28825e5a41311da06f47b19829d71e95/tumblr_p8cupt0tOF1ruscp7o4_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/700ec2db183aa8af038004f8f9556fb8/tumblr_p8cupt0tOF1ruscp7o8_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/8d191106eb10e2ccf329c3871af97893/tumblr_p8cupt0tOF1ruscp7o5_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/33c4994da5a42b7a0ed07a3fabeb3080/tumblr_p8cupt0tOF1ruscp7o2_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;p&gt;&lt;a href="http://pcwt.tumblr.com/post/173667682175/giro18-stage-3-double-eilat-telaviviani" class="tumblr_blog"&gt;pcwt&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;h2&gt;&lt;b&gt;

GIRO’18 Stage 3: Double Eilat TelaViviani!

&lt;/b&gt;&lt;/h2&gt;
&lt;p&gt;

&lt;i&gt;&lt;a href="http://www.cyclingnews.com/riders/elia-viviani/"&gt;Elia Viviani&lt;/a&gt; (&lt;a href="http://www.cyclingnews.com/teams/2018/quick-step-floors/"&gt;Quick-Step Floors&lt;/a&gt;) took his second consecutive sprint win at the &lt;a href="http://www.cyclingnews.com/races/giro-ditalia-2018/"&gt;Giro d'Italia&lt;/a&gt;during stage 3 in Eilat, using his bike skills to push back as Sam Bennett (Bora-Hansgrohe) tried to close the door along the barriers.

&lt;br/&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;

Rohan Dennis (BMC) kept the race leader’s pink jersey after finishing in the peloton and surviving the nervous finale in the Negev desert. Victor Campenaerts (Lotto Fix All) lost time in the finale and so Tom Dumoulin (Team Sunweb) is second at one second. José Gonçalves (Katusha-Alpecin) moved up to third at 13 seconds.

&lt;/i&gt;&lt;br/&gt;&lt;/p&gt;
&lt;/blockquote&gt;</description><link>https://esquireofoz.tumblr.com/post/173707266122</link><guid>https://esquireofoz.tumblr.com/post/173707266122</guid><pubDate>Tue, 08 May 2018 12:59:17 -0400</pubDate></item><item><title>The Giro comes to the Northern Negev.</title><description>&lt;img src="https://78.media.tumblr.com/3ecafa39cf18723f26a5ecade5098bcc/tumblr_p8eimvjYz61ropreyo1_500.gif"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;The Giro comes to the Northern Negev.&lt;/p&gt;</description><link>https://esquireofoz.tumblr.com/post/173707214837</link><guid>https://esquireofoz.tumblr.com/post/173707214837</guid><pubDate>Tue, 08 May 2018 12:57:03 -0400</pubDate><category>giro d'italia</category><category>israel</category><category>2018</category></item><item><title>rollersinstinct:


The route for this year’s Tour de...</title><description>&lt;img src="https://78.media.tumblr.com/8654b32b3875219f3da9d7acffb6a5ef/tumblr_of8mrhn2KU1qdw1kro1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://rollersinstinct.tumblr.com/post/151972887795"&gt;rollersinstinct&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;The route for this year’s &lt;a href="https://twitter.com/LeTour/status/788320039254523904"&gt;Tour de France&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;No cobbles in the TdF next year.  This looks like a tour which will favor the climbers who know how to time trial.&lt;/p&gt;</description><link>https://esquireofoz.tumblr.com/post/151989195062</link><guid>https://esquireofoz.tumblr.com/post/151989195062</guid><pubDate>Tue, 18 Oct 2016 15:27:30 -0400</pubDate></item><item><title>socialpeloton:


Congrats to @petosagan @markcavendish...</title><description>&lt;img src="https://78.media.tumblr.com/8b9fbf2bf81a4c9e68e9c10a8d59f9fa/tumblr_of6s2zsT471sgpry4o1_500.jpg"/&gt;&lt;br/&gt;&lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://socialpeloton.tumblr.com/post/151926665071"&gt;socialpeloton&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Congrats to @petosagan @markcavendish @bomtoonen 🚴🚴🚴💨💨💨&lt;br/&gt;
..&lt;br/&gt;
#Repost @ucidoha2016&lt;br/&gt;
・・・&lt;br/&gt;
Men Elite Road Race #UCIDoha2016&lt;br/&gt;
1. 🇸🇰 Peter Sagan 🏆&lt;br/&gt;
2. 🇬🇧 Mark Cavendish &lt;br/&gt;
3. 🇧🇪 Tom Boonen&lt;br/&gt;
..&lt;br/&gt;
..&lt;br/&gt;
..&lt;br/&gt;
#socialpeloton #cycling #велоспорт #ciclismo #cyclisme #procycling #doha2016 #petersagan #sagan #markcavendish #cvndsh #tomboonen #uci #roadcycling #cyclist #worldchampion #qatar (at The Pearl-Qatar)&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The Sag man is doing his thing!&lt;/p&gt;</description><link>https://esquireofoz.tumblr.com/post/151933468082</link><guid>https://esquireofoz.tumblr.com/post/151933468082</guid><pubDate>Mon, 17 Oct 2016 10:42:19 -0400</pubDate><category>sagan cavendish boonen uci worldchampionships cycling</category></item><item><title>pcwt:


TDF TOP 10 - GC CONTENDERS
Some have already tasted...</title><description>&lt;img src="https://78.media.tumblr.com/6415b8f63686af62cf951750eb58e945/tumblr_o9hld7RBT11ruscp7o1_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/e09c78ee20272948f12d58fe83d86b6c/tumblr_o9hld7RBT11ruscp7o2_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/5d4a8a30ec293cb4086f64c503512215/tumblr_o9hld7RBT11ruscp7o3_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/d70fc996aec50f7e25d3418aab3302d3/tumblr_o9hld7RBT11ruscp7o6_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/28eaa04e47e352d5cf19c262f15e32f7/tumblr_o9hld7RBT11ruscp7o10_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/7e9bcefa8248725d6beefadaa79590f6/tumblr_o9hld7RBT11ruscp7o5_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/112e7ca4cb61bd5ee74ba43cb2fd3ecb/tumblr_o9hld7RBT11ruscp7o4_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/fc539ba94dbe2f2dda23ae49d828ff1b/tumblr_o9hld7RBT11ruscp7o7_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/e0c087a9485f7f207e71038b1fff2638/tumblr_o9hld7RBT11ruscp7o8_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;img src="https://78.media.tumblr.com/6ef4bf42e25c1d513ee4dddc23fc2c76/tumblr_o9hld7RBT11ruscp7o9_500.jpg"/&gt;&lt;br/&gt; &lt;br/&gt;&lt;p&gt;&lt;a class="tumblr_blog" href="http://pcwt.tumblr.com/post/146605803445"&gt;pcwt&lt;/a&gt;:&lt;/p&gt;

&lt;blockquote&gt;
&lt;h2&gt;&lt;b&gt;&lt;a href="https://plus.google.com/b/103635254282780611303/communities/114435503478132620253?gmbpt=true&amp;pageId=103635254282780611303&amp;hl=en-GB&amp;_ga=1.208862290.1715014490.1466255622"&gt;TDF TOP 10 - GC CONTENDERS&lt;/a&gt;&lt;/b&gt;&lt;/h2&gt;
&lt;b&gt;&lt;i&gt;Some have already tasted glory, some are the hope of a whole nation and some will discover the Tour for the 1st time… but all of them are dreaming about the yellow jersey! Who’s your favorite?&lt;/i&gt;&lt;/b&gt;&lt;br/&gt;&lt;br/&gt;&lt;b&gt;&lt;i&gt;‪ &lt;a href="https://plus.google.com/s/%23TdF"&gt;#TdF&lt;/a&gt; &lt;a href="https://plus.google.com/s/%23TourdeFrance"&gt;#TourdeFrance&lt;/a&gt; &lt;a href="https://plus.google.com/s/%23LeTour"&gt;#LeTour&lt;/a&gt; &lt;a href="https://plus.google.com/s/%23ViveleTour"&gt;#ViveleTour&lt;/a&gt; &lt;a href="https://plus.google.com/s/%23MaillotJaune"&gt;#MaillotJaune&lt;/a&gt; &lt;a href="https://plus.google.com/s/%23TDF2016"&gt;#TDF2016&lt;/a&gt;  ﻿

&lt;/i&gt;&lt;/b&gt;
&lt;/blockquote&gt;</description><link>https://esquireofoz.tumblr.com/post/146613856607</link><guid>https://esquireofoz.tumblr.com/post/146613856607</guid><pubDate>Tue, 28 Jun 2016 14:27:55 -0400</pubDate></item></channel></rss>
