You are on page 1of 2

Burpsuite Basics

When we access the IP address from the browser, we get this landing page.

It doesn't seem like much, but we can inspect the source code to find some sensitive information.

We know that the robots.txt file is there. Let's check it out.

We have a list of possible directories. While checking, we found that the connections directory has a webpage on
it. The debug parameter also caught our eye.

1/2
Sure enough, in connections we can see a message Debug is false. Let's add the url parameter debug. We didn't
find anything when set to false, so we tried setting it to true.

We found sensitive information.

2/2

You might also like