Is anything truly secure...

3 Comments on “Brainbench.com Assessment Engine JavaScript Injection Vulnerability”

  1. Raghuraman
    Hey Nice Write up again. Thanks for bringing this to the attention of general public. I hope Brainbench at least now reacts fast. There are many online test vendors who rely only on client site validation only. Regards and many Thanks Raghuraman
  2. Brainbench TS
    Thanks for your findings. We have received your emails, and we have looked into the issue. While your finding is accurate, it should be noted that the Brainbench assessments are intended to be open book technical knowledge tests with the time being an indicator of that knowledge. While the client side timer is used to eliminate server and network latency, it is not the only time reported to administrators. In fact, the example you use below would be indicated as cheating in the admin’s report. Click here. PreVisor takes these issues seriously and is constantly looking for better ways to secure our content and systems. This issue will be addressed in future releases. PreVisor Technical Support
  3. jeremy
    Thanks for the response Brainbench TS! I am glad to hear you all are tracking this some how on the backend admin reports. I would question these reports a little though, as I have used this hack to take well over the time limit and still received the official certification on more than one occasion, but at least it is a good start to fixing the issue at hand.

Comments are closed.

Copyright © 2013 SudoSecure LLC. All rights reserved.

rvn_polyon_theme rvn_polyon_theme_tv_1_7 rvn_polyon_theme_fwv_2_2