Legend Expert

Experts Exchange is an IT community for knowledge sharing with a focus on solving technology problems.  Persons looking for answers ask questions and "experts" try and answer them.  Experts are awarded points for answering questions in knowledge "zones" and gain ranks in those zones when acquiring sufficient points:

Master          50,000
Guru           150,000
Wizard         300,000
Sage           500,000
Genius       1,000,000
Savant      10,000,000
Elite       25,000,000
Technocrat  50,000,000
Legend     100,000,000

When earning a rank an expert is given the opportunity to create an html badge which displays the rank, points and zone and which may be used as an email signature.  The badge is made up of various images hosted on the experts exchange website and because the urls for those images are predictable it is trivial for anyone to create a badge for a zone and rank to which they are not entitled:
 
legendRankTopjah
legendRankMiddlelegendTitleMiddlelegendPointsMiddle
legendRankBottoml_174
Since nobody has yet attaied even half this amount of points, I'm the first person to be "awarded" the Legend rank.  Nice.

Now this isn't a major issue, but it could be used to mislead people as to a persons knowledge of a particular topic or in some cases a persons identity - it's possible for instance to create a badge for a ning.com social network for any user of that network and so impersonate them in communications.
It's not an easy task to prevent this sort of thing because these badges are just pieces of html which can be copied and placed anywhere and restricting the use of them to specific people isn't really feasible.

Never trust a badge then.

Leave a comment

Recent Entries

  • The TCP/IP Guide - Greasemonkey Userscript

    jah has written a greasemonkey userscript to fix the page layout for The TCP/IP Guide free online edition - it's very simple, but it took him ages!...

  • PicaVue

    jah has begun work on an open source javascript gallery to display his Picasa Web Albums - it's called PicaVue...

  • Nmap 5 - An Introduction

    The newest version of Nmap - Nmap 5.00 - is now available for download and is the best Nmap ever. This is a short introduction to Nmap and the Nmap family of tools: Zenmap; Ncat and Ndiff which are included with this latest release....

  • Enable apache mod_userdir on Debian

    How to enable mod_userdir for apache2 on Debian 5.0 (Lenny)....

  • Nmap 4.85BETA5 and Conficker detection

    Nmap 4.85BETA5 is now available and is able to remotely and anonymously detect hosts compromised with Conficker (downadup, kido) using an NSE script....

  • Install BackTrack 4 beta on VMware 5.5.x from the ISO image

    Here are the steps required to create a new VMware virtual machine on which to install BackTrack 4 beta from the ISO image...