The XSS Rat
CWAP · Module 10 — Hidden Credentials

Attack 3 — Backups, config, debug pages and actuators

Animated, step-by-step: fuzz for the artefacts a deploy left behind, read the config that stores secrets on purpose, and take a found credential from disclosure to a proven, validated flag.
Module 10Secret disclosureBackups / debug / actuatorHigh

◤ Attacker workstation

🐀
you
idle

◤ On the wire

◤ Server

key material
waiting
attacker
server
hunter@cwap — bash
0:00 / 0:00 step 1 / 1