Confidential Document - DuckyMomo20012/owasp-juice-shop GitHub Wiki
Confidential Document
Difficulty: :star2:
Description: Access a confidential document.
Category: Sensitive Data Exposure
Tags: Good for Demos
Solution:
On the About Us page, when we hover over the text Check out our boring terms of use if you are interested in such lame stuff
, we see an http://127.0.0.1:3000/ftp/legal.md
link in the lower left corner of the web page.
We access the path
http://127.0.0.1:3000/ftp
and will see a list of files
We click on
acquisitions.md
and we get the challenge