Understanding Information disclosure
What it is
Information disclosure is the application handing out something it should have kept — a stack trace naming internal paths, a comment holding a key, a debug endpoint, a backup file left in the web root, a verbose error that confirms what an attacker guessed.
How you approach it
- Read everything the app gives you that it did not mean to be read — page source, response headers, error messages, files that should not be reachable.
- Predictable paths leak: a backup with a
.baksuffix, a.gitfolder, arobots.txtthat names what it hides, an old API version still answering. - The flag is sitting in plain sight somewhere the interface never links to. Ask for it directly.
How it gets fixed
A resource that was never linked was still served, and it held a secret. Requesting the predictable path directly returned it — no exploit, only something left exposed. The fix is to remove what should not ship and to return errors that reveal nothing about internals.
Practise it
Every lab in the Information disclosure category drills exactly this. Start at Apprentice and work up.