This post is going to be about how I got started in hacking (thanks to Microsoft) and with time, how I was able to help them back by reporting some security vulnerabilities in their web applications.


The story started in my second year. I was a complete newbie — looking up tutorials on YouTube and calling myself a hacker. Hell, I couldn’t even dual boot a PC properly. Back in school, I wasn’t very good with computers. Maybe it was because of the curriculum or the intensive JEE coaching, but I never really had any motivation to explore programming. Things changed when I joined IIT and got my own laptop. My curiosity, eagerness to explore and my very talented friends sure took me a long way. Back to the story, it all started when I saw a notice board in the college campus. Three words caught my attention: **_hacking contest, Microsoft _**and goodies. Needless to say, these were sufficient to get the second year me excited. It was a group event, so I teamed up with two of my close friends. The rules were thus: a 24-hour preliminary round followed by the top 50 teams battling it out in the finale at the Microsoft Hyderabad campus. The glitch here was that only three teams per college could qualify.

I don’t recall how, but we ended up being ranked 42. But what broke my heart was that there were already 3 teams from IIT Guwahati above us. My hopes were dashed — all this while I had considered myself to be a hacker, but my team couldn’t even make it to the finals. We did solve some web-based challenges but the Reverse-engineering challenges had us stumped.

I took this to heart.

Somewhere deep down, it hurt my ego. That was the moment I realized that whatever I was doing was nowhere near enough. Also because of the Build The Shield event I got introduced to CTFs — Capture the Flag contests. We still remember the adrenaline rush we got by participating in the event and couldn’t wait to get another dose of it.

After the contest ended, we participated in random CTF contests and also started reading related write-ups . This taught us a ton of new stuff and slowly, we started getting better at solving the challenges. All the while we only had one thing in mind — to do better in next year’s Build The Shield.

#bug-bounty #information-security #hacking #microsoft #security

From Microsoft “Build the Shield” to Microsoft “Hall of Fame”
1.70 GEEK