Welcome to HBH! If you had an account on hellboundhacker.org you will need to reset your password using the Lost Password system before you will be able to login.

Challenge points


ghost's Avatar
0 0

I'm not really sure what happened but some challenges I haven't done yet are showing up as completed. Has this happened to anyone else??


starofale's Avatar
Member
0 0

dillyboy1985 wrote: Has this happened to anyone else?? Not me.


stealth-'s Avatar
Ninja Extreme
0 0

Strange, I've never heard of this. You might want to consider changing your password, perhaps your sharing your account with someone? Or maybe you just drink a lot of alcohol and forget shit? That's always possible as well.


ghost's Avatar
0 0

Just noticed this happen to me also.

All of the application challenges, 11 of the 12 encryption challenges and a few others now show as completed.

It seemed to happen while I was logged on doing the patching challenges.


ghost's Avatar
0 0

i just noticed the same. I think in the past I might have done or at least tried one or two application challenges. But I doubt I even ever tried the encryption challenges. Most of them are now marked as passed.


starofale's Avatar
Member
0 0

As stealth- said, you might want to change your passwords.


ghost's Avatar
0 0

First thing I did when I noticed was change my password, log out and log back in.

I always use a unique, generated password for everything though. Certainly not easily guessable.

Some sort of session takeover?

I'd like to get the challenges I haven't done myself reset.

Any idea who the best person to contact is?

The reason I ask is because I pm'd mr_cheese regarding another matter to do with a challenge error where I got a message telling me to contact him and have yet to receive a response.


Mordak's Avatar
Evil Sorcerer
4,025 18

The error was in tracking 2, which he knows about and is fixing, Just redo the challenges there's no real need to reset them.


ghost's Avatar
0 0

Firstly, I'd prefer not to have to manually keep track of challenges I have completed.

More importantly, if there is a session takeover vulnerability it should be addressed.


ghost's Avatar
0 0

my password is only like one week old. also, wouldn't it be strange that it would be exactly the same challenges and amount of challenges? But I will change it again to be sure.


ghost's Avatar
0 0

<ynori7> yeah, the challenge completions are CSRFable, and somebody put it in their sig so a bunch of people got credit for stuff they didn't do

I was asking on IRC tonight about that b/c I noticed I had the same stuff happened on mine. Though before I asked, I went ahead and changed my pass.


ghost's Avatar
0 0

well that's an interesting turn of events…