Scenario
Your team is auditing a small public-facing help center. Rumor says the site accidentally leaks internal configuration details. Your job is to validate whether any sensitive information is exposed and to document the findings.
Objectives
- Discover and retrieve the hidden chatbot log embedded in this page.
- Decode and analyze the log to identify what types of sensitive data are present (e.g., API keys, internal URLs, PII).
- Explain how such leakage can occur in real projects and propose concrete mitigations.
Deliverables
- A short report (≈ 1–2 pages) containing:
- Acquisition method: where you found the log and the exact steps/tools used.
- Decoded content: the plain-text log (sanitized for the report if necessary).
- Risk analysis: what would be the impact if this were real.
- Recommendations: at least 5 actionable fixes/preventive controls.
Suggested Tools
Browser DevTools (Elements/Styles/Network), curl, grep, base64 decoders,
and your favorite text editor. No brute force required.
Rules & Ethics
- This microsite is fictional and for training only.
- Do not scan beyond this page or attempt any attacks.
- Limit yourself to open-source intelligence (view-source/DevTools).
Real-World Parallels
In real incidents, teams have accidentally shipped secrets inside front-end bundles, CSS
data: URLs, or sourcemaps. CI/CD misconfigurations and asset inlining often cause
such leaks. Your report should mention how to prevent this (secret scanning in CI, build-time
lint rules, Content Security Policy, disallowing inline assets that contain text, etc.).