🖼 Description
- Police dept website
- configure scope of the target
- spider the web app
- 10.100.13.5
📊 Goal
- find a hidden path
- bypass authentication by exploiting a "feature"
☑ Steps
- explore 10.100.13.5
- configure scope of engagement
- filter sitemap to show only in-scope items
- some resources are hidden. manually you can crawl the website. Find a way to automate crawling
- after getting the hidden path,
- explore
- extract useful info
- "magic tricks"
- keystone
🏁 Solution
- configure the in-scope item
- proxy options
- sitemap options
- sitemap filters
- navigate through target
- check robots.txt
- find a hidden path
- check source of login page