mirror of
https://github.com/tmoron/darkly.git
synced 2025-09-27 12:48:35 +02:00
+ | hidden done
This commit is contained in:
14
hidden/README.md
Normal file
14
hidden/README.md
Normal file
@ -0,0 +1,14 @@
|
||||
# Finding the Hidden Flag
|
||||
|
||||
## How We Found It
|
||||
First we went throught basic analysis of the website and thought of `.robots.txt`.
|
||||
|
||||
`Dissallow: /.hidden`
|
||||
|
||||
We wrote a script that crawled through the website’s `.hidden` directory. It checked every subdirectory and looked for each README file, examining the byte of its content. When that byte deviated from the expected pattern, we knew we’d found the flag!
|
||||
|
||||
## Utility of It
|
||||
For this project, there wasn’t any real-world utility, it was just a roleplay exercise for school to learn about web crawling and threading.
|
||||
|
||||
## How Can We Patch It
|
||||
The easiest fix is to restrict public access to sensitive files. Don’t place secret files in directories that are directly accessible from the web.
|
Reference in New Issue
Block a user