  By: admin on Aug. 28, 2014, 2:32 p.m.

This challenge is based on the Heartbleed Bug in OpenSSL discovered in April 2014. Attack a server provided by the group for Privacy and Compliance with the Research Institute Cyber Defence (CODE) at Bundeswehr University Munich, which is specifically prepared to be vulnerable to the Heartbleed bug.

  By: Veselovský on Sept. 1, 2014, 7:02 p.m.

I am not sure whether this is a problem or I just do it wrong…
but what if somebody is continuously performing a login with incorrect/random/trial password (and perhaps he/she does it more frequently then the "script in the background")?
I can see lots of different "passwords" that somebody was trying to login with, I tried several of them and none of them was correct.
I can spent hours on it this way…

  By: Veselovský on Sept. 1, 2014, 9:05 p.m.

Probably, the problem I mentioned above was not a problem, as I have just solved part 1.

But I still miss the logic of the challenge and its three parts. At the moment I consider it a bit messy, because I first had to login into part 2 of the challenge to see whether I am on the right track and only then was able to solve the first part.

  By: Veselovský on Sept. 1, 2014, 9:21 p.m.

…also I do not understand why we have to provide as a codeword a password of Alice that is nowhere accepted on the "" site. Since it is nowhere accepted, how should I have known that it is a correct codeword to provide? I have not known, I just did trial and error.

  By: wackerao on Sept. 3, 2014, 3:45 p.m.

Please see my response to part 2, as it applies here too.

  By: stegi on April 15, 2015, 6:02 p.m.


I found this site by accident yesterday and already had some fun solving the first challenges.
I wanted to try this challenge but I don't have any prior experience doing 'stuff like that' on a computer. So when I went on the projects page I didn't have a single clue what to do :(

So I wanted to ask, if anyone could give me a hint or link how I can learn to get startet with that.

Thanks in andvance :)

  By: madness on June 18, 2021, 5:37 a.m.

"No heartbeat response received, server likely not vulnerable"

  By: Fountain on Oct. 15, 2021, 12:47 a.m.

Perhaps I'm late to the party. As best I can tell, the target server is no longer vulnerable to Heartbleed. Has the server been patched or am I missing something?

