Ulli Weichert/ April 7, 2022/ IT-Security, Write-Ups/ 0Kommentare
Roboto Sans
The flag is somewhere on this web application not necessarily on the website. Find it.
Check this out.
- Visit the website
- Digging in the sourcecode - nothing there
- Looking the low-hanging fruits
- robots.txt -- this is interesting
- In the robots.txt there are some base64 encoded strings
- decoding it point us to 'js/myfile.txt'