🛡️ Security Lab Track A · Web Application Security · Stage 1

Track A · Stage 1

Web Application Security

Recon: robots.txt, comments & hardcoded secrets easynot started

A static site leaks its secrets through recon artifacts: robots.txt, developer comments, a forgotten backup path, and a hardcoded API key in a JS file. Assemble the flag.