Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

New Challenges


New Challenges


As ever working HBH staff we have produced 3 new challenges for our members.

A new other, a new basic, and a BRAND NEW CATEGORY!

Click on Read More for details.

Three new challenges have been released:

Basic 26 (only_samurai) Other 14 (The Flash) Penetration Testing 1 (only_samurai and system_meltdown)


Penetration Testing you ask? What\'s that? After deciding the realistic challenges are a bit from realistic, system and I created this challenge. There is no ultimate \'goal\' per say. Rather, you are to find ALL the holes in the site. Some are linked, some are not. We\'ve packed a few difficult new ones in there for you too. Hopefully you\'ll enjoy it. It\'s worth a total of 350 points.

Login with nooblet:irtoleet

Get on it!

Comments
ghost's avatar
ghost 17 years ago

Enjoy mates! leave comments on the new chall format and such. :D

ghost's avatar
ghost 17 years ago

blah?

ghost's avatar
ghost 17 years ago

not blah it was a test for another site but i pasted it by mistake here as you can see is a test for that expression trick

ghost's avatar
ghost 17 years ago

trust me, if it worked, i'd have more HoF for it

ghost's avatar
ghost 17 years ago

the chall is good i found just 2 but i'm keep searching, but i wander where they can be ^^

ghost's avatar
ghost 17 years ago

I would be nicer if we didn't have to find hidden pages

ghost's avatar
ghost 17 years ago

hidden pages eh :S

ghost's avatar
ghost 17 years ago

Yeah "Some are linked, some are not"

SySTeM's avatar
SySTeM 17 years ago

EXPLOITS, NOT PAGES! >_<

spyware's avatar
spyware 17 years ago

Mozzer.. if those pages are hidden you could you find them ;x

ghost's avatar
ghost 17 years ago

awesome

ghost's avatar
ghost 17 years ago

they are built in exploits… there are ways to find them through the chall…

ghost's avatar
ghost 17 years ago

yeah? Why are you able to log in as nooblet without even needing a password?

Why is it that all you need to do is add another variable to an include and you can get credit for an 'exploit'?

ghost's avatar
ghost 17 years ago

Also, what happens if i were to exploit something that wasn't the intention of another exploit i found.

Say i found XSS, why can't i use it to try a session fixation?

Uber0n's avatar
Uber0n 17 years ago

This will be fun :D

Mr_Cheese's avatar
Mr_Cheese 17 years ago

nights_shadow - want to code a better challenge?

ghost's avatar
ghost 17 years ago

This is awesome. As usual, you guys rock B)

ghost's avatar
ghost 17 years ago

/me hugs only_samurai and other hbh dev!!!:D

ghost's avatar
ghost 17 years ago

fGt :p

ghost's avatar
ghost 17 years ago

It's just weird that i have to question errors about a challenge making fun of someone else's coding skills.

I can't tell whether it's part of the challenge because of this.