How To Find Information Hidden in Websites

CyberStart Game Challenge Spoiler (HQ, Level 7, Challenge 3)

CyberStart
CyberStart Family
2 min readMar 15, 2018

--

We’re moving! Come and find us on www.cyberstart.com/blog where you will find even more tips, tricks and industry support. See you there!

Fancy yourself a cyber security expert in the making?

At CyberStart, we’ve created a range of real-life cyber security challenges online to test your skills. In this blog, we’ll be talking you through one challenge in particular and showing you how to solve it.

By the end of the blog, you’ll know how to find hidden information in websites and how to prevent websites being vulnerable to attack. Ready to get learning?

Here’s the problem… can you solve it?

As a cyber security expert, you’ve been asked to look into a gang that runs a number of legitimate and criminal operations. You’ve been given a tip that there could be hidden information in one of the gangs’ websites. It’s being stored in a file called “extra.txt”.

Would you have any idea how to find it?

Check out the video below to see the scenario and how to solve it!

⚠️ Warning: The video below is a spoiler of HQ, level 7, challenge 3 in CyberStart Game. If you are currently playing CyberStart Game and want to solve this challenge by yourself, we recommend you don’t watch this just yet!

What does this teach us?

Website flaws such as this file inclusion are a common mistake that leaves businesses open to attack! In this particular case, the website needs to make itself resistant to these kind of flaws to ensure others cannot ask for data, other than what the website expects to provide.

Learn how to reveal and prevent security flaws

Examining and understanding how web applications load and serve data can often reveal security flaws. The thought process behind discovering this file inclusion vulnerability is similar to many other security flaws, so it’s a great skill to get your head around.

If you’re playing CyberStart Game already, good luck! Make sure to get in touch if there are any other challenges you would like to see a spoiler of at support@joincyberstart.com

If you’re not already playing along, why not sign up to one of our free programmes to get involved and learn more about cyber security?

Interested in our programmes? Check out where you can build your cyber security knowledge for free!

UK 13–18-year-old student programme: Cyber Discovery https://cyberdisc.io/medium

USA 13–18 year-old girls student programme: Girls Go CyberStart https://ggcs.online/medium

USA 18–year-old and above college student programme: Cyber FastTrack https://cyberft.io/medium

--

--

CyberStart
CyberStart Family

CyberStart is a collection of tools that will introduce you to the cyber security industry and accelerate your entry into the profession! 💻