News
Loooking for ParticipantsWritten on 22.05.22 by Sebastian Roth Dear former WebSecurity students, Our Bachelor student Philipp is currently writing his thesis about Trusted Types. As part of this thesis, he is conducting a study on the usability of Trusted Types. The study consists of two parts: First, an interview about XSS and Trusted Types. And… Read more Dear former WebSecurity students, Our Bachelor student Philipp is currently writing his thesis about Trusted Types. As part of this thesis, he is conducting a study on the usability of Trusted Types. The study consists of two parts: First, an interview about XSS and Trusted Types. And afterwards, a coding task where Trusted Types sanitizer functions need to be created. The whole process will last approximately 60 minutes, and you will be compensated with a 25€ Amazon voucher. So if you are interested or have further questions, do not hesitate to write him an email (s8phbaus@stud.uni-saarland.de). |
Backup exam results / backup exam inspectionWritten on 27.09.21 by Ben Stock I have finished grading and added the results into the CMS. We will do the exam inspection on Thursday, 10-11:30. Please let me know if you plan to attend so I can decide whether to just do it in my office or reserve a room. |
Reminder: backup exam participation / possible Covid symptomsWritten on 25.09.21 by Ben Stock If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19… Read more If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19 patient, who was tested positive, in the last 14 days? Do you have any of the following symptoms?
If a student is not sure about the answer to one of these questions, then he/she has to consult a doctor to decide whether or not his/her health status is critical. If the decision is that he/she can participate, then he/she has to bring a medical certificate along to the exam. |
Backup examWritten on 22.09.21 by Ben Stock For Monday's backup exam, we will not be in GHH, but instead in HS 002 in the CS building. As last time, please have a vaccination proof, recovery proof, or negative test result available for me to check. You can see your seat number in the CMS.
Also, the standard disclaimer applies: Also… Read more For Monday's backup exam, we will not be in GHH, but instead in HS 002 in the CS building. As last time, please have a vaccination proof, recovery proof, or negative test result available for me to check. You can see your seat number in the CMS.
Also, the standard disclaimer applies: Also note the following (will remind again about this on the day before the exam): If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19 patient, who was tested positive, in the last 14 days? Do you have any of the following symptoms?
If a student is not sure about the answer to one of these questions, then he/she has to consult a doctor to decide whether or not his/her health status is critical. If the decision is that he/she can participate, then he/she has to bring a medical certificate along to the exam. |
Reminder: backup exam registrationWritten on 13.09.21 by Ben Stock This is your one-week reminder. Please ensure that you are registered through the LSF by September 20 if you want to take the backup exam. |
Exam results & exam inspectionWritten on 29.07.21 by Ben Stock We have put the exam results into the CMS. Please check your personal status page. We will do the inspection on Monday, from 10-12 in CISPA's room 0.07. |
Reminder: exam participation / possible Covid symptomsWritten on 27.07.21 by Ben Stock If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19… Read more If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19 patient, who was tested positive, in the last 14 days? Do you have any of the following symptoms?
If a student is not sure about the answer to one of these questions, then he/she has to consult a doctor to decide whether or not his/her health status is critical. If the decision is that he/she can participate, then he/she has to bring a medical certificate along to the exam. |
Exam detailsWritten on 23.07.21 by Ben Stock Quick reminder about the details for the exam:
Quick reminder about the details for the exam:
Also note the following (will remind again about this on the day before the exam): If your answer is "yes" to one or more of the following questions, then you are not allowed to attend the exam. If you provide a doctor’s certificate to the examination office later on, the examination attempt will be canceled and will not count. Did you have definite contact with a Covid-19 patient, who was tested positive, in the last 14 days? Do you have any of the following symptoms?
If a student is not sure about the answer to one of these questions, then he/she has to consult a doctor to decide whether or not his/her health status is critical. If the decision is that he/she can participate, then he/she has to bring a medical certificate along to the exam. |
Reminder: Exam registrationWritten on 21.07.21 by Ben Stock Hi folks, note that *today* is the last chance you have to register for the main exam. After today, you cannot register and can therefore not take part in the exam. |
Exam preparation and planningWritten on 13.07.21 by Ben Stock To allow everyone to have some more time to prepare specifically for the types of questions you might expect, we will use this week's slot to not only explain the jeopardy solutions, but also to provide a general idea of what you can expect from the exam. In the final meeting on July 23, I will cover… Read more To allow everyone to have some more time to prepare specifically for the types of questions you might expect, we will use this week's slot to not only explain the jeopardy solutions, but also to provide a general idea of what you can expect from the exam. In the final meeting on July 23, I will cover topics that you can nominate which should be clarified. Please add your topics as answers to the post in the Askbot at https://cms.cispa.saarland/askbot/websec21/question/32/topics-for-wrap-up-session-on-july-23/ If you plan to take the exam on July 28, note the following important points:
Note also the regulation from the university regarding masks during the exam: While entering/leaving the room (this includes also waiting situations), moving in the room, and while talking to supervisors, medical mouth-nose protection (surgical masks) or FFP 2 / KN 95 / N95 masks are mandatory. It is recommended that everyone (including supervisors) wears protective masks during the entire exam, also while sitting at the seat. |
Outlook for next two weeks / Final reminder for evaluation ;-)Written on 09.07.21 by Ben Stock I have just uploaded the slides and video of the final regular lecture today. We will meet next week (16.7.2021) at the regular time to discuss the second batch of jeopardy challenges. I will run through the steps of each challenge and we will also release a "walkthrough" guide. The week after… Read more I have just uploaded the slides and video of the final regular lecture today. We will meet next week (16.7.2021) at the regular time to discuss the second batch of jeopardy challenges. I will run through the steps of each challenge and we will also release a "walkthrough" guide. The week after (23.7.2021), we will have our exam preparation, in which I will give you hints on what to expect in the exam and what types of answers we will look for. Generally speaking, the exam will be very practical. That is, if you managed to do all the jeopardy and screecher challenges (or understood how they work from the provided solutions), you should not have a hard time with the majority of the exam. Examples of some of the more theoretical questions can be found in the Reading Guide, so I encourage everyone to have a look at the control tasks (solutions are the end of the reading guide). Finally, as a reminder, if you have not yet evaluated the lecture, please do so before July 15, at which point the system will be shut off. The link to the evaluation is: https://qualis.uni-saarland.de/eva/?l=130408&p=2tpvbh Have a nice weekend! |
Taking gamification to the next level: our CTF team saarsecWritten on 29.06.21 by Ben Stock Hi all, if you liked the challenges we did for FoWS, you'll probably also like playing actual CTFs ;-) Our local team saarsec is regularly participating in these and there are two great Attack/Defense CTFs (somewhat similar to Screecher, but round-based with frequently changing flags) coming up (on… Read more Hi all, if you liked the challenges we did for FoWS, you'll probably also like playing actual CTFs ;-) Our local team saarsec is regularly participating in these and there are two great Attack/Defense CTFs (somewhat similar to Screecher, but round-based with frequently changing flags) coming up (on July 10 and July 18) These CTFs, which typically for for 8-10 hours, will allow you to apply your exploitation, patching, and automation skills. Some more info about the CTF team can be found at https://saarsec.rocks/. We have regular meetings on Thursday at 5pm, held virtually at the moment. If you are interested in joining for the meeting, send me an email and I can provide you with access to the meeting URL. If you want to then join more regularly, you'll get an invite to saarsec's Mattermost channel, which we use for all the coordination. |
EvaluationWritten on 24.06.21 by Ben Stock I have received the link for the evaluation today. Please rate the lecture at https://qualis.uni-saarland.de/eva/?l=130408&p=2tpvbh Also, if you have additional feedback you want to leave about the lecture, feel free to use the feedback in the CMS. We also appreciate specific feedback on the… Read more I have received the link for the evaluation today. Please rate the lecture at https://qualis.uni-saarland.de/eva/?l=130408&p=2tpvbh Also, if you have additional feedback you want to leave about the lecture, feel free to use the feedback in the CMS. We also appreciate specific feedback on the Jeopardy challenges through the gameserver interface. |
No Q/A session on FridayWritten on 24.06.21 by Ben Stock Given that there are just two quizzes and no other content for lecture 9's quiz, we'll skip this week's meeting. If you have specific questions about something that was unclear in the lecture, ping me on Mattermost or send me an email so I can clarify. We will release the new challenges at 10 am. |
Random rebootWritten on 22.06.21 by Ben Stock Unfortunately, the machine hosting the exercises was rebooted me understanding why. I have restarted all services now and it seems the screecher instances and jeopardy challenges should be operational. Should that not be the case, please let me know. |
End of power outageWritten on 20.06.21 by Ben Stock Hi folks, unfortunately, there we some network issues last night still with the CISPA network, which is why I only was able to restart everything just now. We have extended the deadline for this week's sheet by 48h (i.e., 27.6.2021 10:00am) and the one for the next week also by 24h (i.e., 3.7.2021… Read more Hi folks, unfortunately, there we some network issues last night still with the CISPA network, which is why I only was able to restart everything just now. We have extended the deadline for this week's sheet by 48h (i.e., 27.6.2021 10:00am) and the one for the next week also by 24h (i.e., 3.7.2021 10:00am). Note that this change is not reflected in the sheets, but only in our Gameserver database. |
Power OutageWritten on 18.06.21 by Ben Stock Dear all, there will be a shutdown of CISPA's power supply from 10pm tonight until 6pm tomorrow for necessary maintenance. In that time, the servers hosting the videos as well as the challenges and screecher instances will be unavailable. CMS should still work though. If you want to watch the… Read more Dear all, there will be a shutdown of CISPA's power supply from 10pm tonight until 6pm tomorrow for necessary maintenance. In that time, the servers hosting the videos as well as the challenges and screecher instances will be unavailable. CMS should still work though. If you want to watch the video(s), please sure to finish your downloads before 10pm tonight. We will shut down the VMs at 9pm tonight and start them again at the latest 24h later. To account for the lost time, we will postpone the Screecher deadline by 1 day, i.e., June 26th, 10 am. For the jeopardy challenges, there is only the deadline at the end of the semester, so no need to push that. |
Invited Talk in our Web Sec Lecture SeriesWritten on 10.06.21 by Ben Stock Hi all, in our CISPA Web Sec lecture series, we have a speaker today who might be interesting for some of you. Feel free to join the Zoom call, info below. When: Thursday June 10, 10:00 AM Zoom link: https://cispa-de.zoom.us/j/96775779464?pwd=WFQ1aW9Xb2c1OHMybWlEUDIralN5QT09 Hi all, in our CISPA Web Sec lecture series, we have a speaker today who might be interesting for some of you. Feel free to join the Zoom call, info below. When: Thursday June 10, 10:00 AM Zoom link: https://cispa-de.zoom.us/j/96775779464?pwd=WFQ1aW9Xb2c1OHMybWlEUDIralN5QT09 Speaker: Stefano Calzavara Title: May I take your subdomain? Exploring same-site attacks on the modern Web
|
Reminder / Clarification: Screecher HTTP AuthenticationWritten on 17.05.21 by Ben Stock Just a quick reminder, in particular for those not on Mattermost: your screecher instances are running behind an HTTP Authentication, which is not filled by the crawlers (except for those that check functionality/exploitability on your instances). That means, if you try to host a file used for the… Read more Just a quick reminder, in particular for those not on Mattermost: your screecher instances are running behind an HTTP Authentication, which is not filled by the crawlers (except for those that check functionality/exploitability on your instances). That means, if you try to host a file used for the jeopardy challenges on your screecher instance, that will not work. That is what you have your attacker directories for :-) |
Due to popular demand solutions now contains PoCs + changesWritten on 10.05.21 by Marius Steffens Hey all, due to popular demand, we have released solutions for exercise sheet 1 and updated the solution for sheet 2 with PoCs + diffs for the fixes. Cheers,
|
New jeopardy exercises, no screecher exercises this weekWritten on 07.05.21 by Marius Steffens Hey everyone, today we will not release an exercise sheet. All jeopardies released until today(including today) are due on June 4, 10 am (the rest of the jeopardies will be discussed at the end of the… Read more Hey everyone, today we will not release an exercise sheet. All jeopardies released until today(including today) are due on June 4, 10 am (the rest of the jeopardies will be discussed at the end of the semester). Happy Hacking! |
MattermostWritten on 05.05.21 by Ben Stock Hi folks, I realized today that we did not post the link to the Mattermost outside of the live lecture ~2 weeks ago. The URL for it is https://mattermost.websec.saarland - please use the option to "Login with Gitlab".
|
Welcome to Foundations of Web SecurityWritten on 16.04.21 (last change on 16.04.21) by Ben Stock Welcome to this year's iteration of (what is now known as) Foundations of Web Security. To access the Zoom meetings and the lecture recordings, please see https://cms.cispa.saarland/websec21/7/Lecture_Access. We'll start the lecture at 10:15 today and you can already download the (preliminary) slides… Read more Welcome to this year's iteration of (what is now known as) Foundations of Web Security. To access the Zoom meetings and the lecture recordings, please see https://cms.cispa.saarland/websec21/7/Lecture_Access. We'll start the lecture at 10:15 today and you can already download the (preliminary) slides from the Materials section in CMS. I have also uploaded the video for lecture 2 as well as Q/A for both lectures 1 and 2, so you can take a look at the questions while attending the lecture / watching the videos. |