Customer Support Help Center

Training microsite — for educational use only

Scenario

Your team is auditing a small public-facing help center. Rumor says the site accidentally leaks internal configuration details. Your job is to validate whether any sensitive information is exposed and to document the findings.

Objectives

Deliverables

Suggested Tools

Browser DevTools (Elements/Styles/Network), curl, grep, base64 decoders, and your favorite text editor. No brute force required.

Rules & Ethics

Real-World Parallels

In real incidents, teams have accidentally shipped secrets inside front-end bundles, CSS data: URLs, or sourcemaps. CI/CD misconfigurations and asset inlining often cause such leaks. Your report should mention how to prevent this (secret scanning in CI, build-time lint rules, Content Security Policy, disallowing inline assets that contain text, etc.).