Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Review Web Page Content for Information Leakage
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | 230% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 352% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 376% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 162% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 852% | 0% |
WSTG-INFO-05
Review Web Page Content for Information Leakage
Web pages often contain more information than what is visually displayed to users. HTML comments, JavaScript files, metadata, and debug artifacts can inadvertently expose sensitive information such as credentials, internal paths, infrastructure details, and business logic. This test involves systematically reviewing web page source code, scripts, and associated files to identify information leakage that could aid attackers in compromising the application.
<!-- -->).map files)bash# Download page and extract comments curl -s https://target.com | grep -o '<!--.*-->' # Extract multi-line comments curl -s https://target.com | grep -Pzo '<!--[\s\S]*?-->' # View page source in browser # Right-click > View Page Source # Ctrl+U / Cmd+U
html<!-- Database: mysql://admin:password123@localhost/db --> <!-- TODO: Remove before production --> <!-- Debug mode enabled --> <!-- Admin panel at /secret-admin-2024 --> <!-- User: testuser / Pass: test123 --> <!-- Internal IP: 10.0.0.50 --> <!-- Last modified by john.doe@company.com --> <!-- Version 2.3.1 - Build 4521 -->
bash# Extract all META tags curl -s https://target.com | grep -i '<meta' # Look for specific information curl -s https://target.com | grep -iE 'author|generator|description|keywords|robots|csrf'
html<meta name="author" content="John Doe" /> <meta name="generator" content="WordPress 6.0" /> <meta name="csrf-token" content="abc123xyz" /> <meta name="api-base" content="https://api.internal.target.com" /> <meta property="og:url" content="https://staging.target.com/page" />
bash# Extract all script sources curl -s https://target.com | grep -oP 'src="[^"]*\.js[^"]*"' # Download JavaScript files curl -s https://target.com | grep -oP '(?<=src=")[^"]*\.js[^"]*' | while read js; do echo "=== $js ===" curl -s "https://target.com$js" | head -50 done
bash# Download all JS and search for patterns curl -s https://target.com/app.js | grep -iE 'api_key|apikey|secret|password|token|auth|key' # AWS credentials grep -iE 'AKIA[0-9A-Z]{16}|aws_secret|aws_access' *.js # API endpoints grep -oP 'https?://[^\s"<>]+' *.js | sort -u # Internal paths grep -iE '/admin|/api/|/internal|/private' *.js
javascript// API Keys const API_KEY = "AIzaSyD-xxxxxxxxxxx" const STRIPE_KEY = "sk_live_xxxxxxxx" const GOOGLE_MAPS_KEY = "AIzaxxxxxxxx" // Credentials const DB_PASSWORD = "password123" const ADMIN_TOKEN = "eyJhbGciOiJIUzI1NiIs..." // Internal URLs const API_BASE = "https://internal-api.company.com" const ADMIN_URL = "/super-secret-admin" // AWS Credentials const AWS_ACCESS_KEY = "AKIAIOSFODNN7EXAMPLE" const AWS_SECRET_KEY = "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
bash# Check for source maps for js in app.js main.js bundle.js chunk.js vendor.js; do status=$(curl -s -o /dev/null -w "%{http_code}" "https://target.com/$js.map") echo "$js.map: $status" done # Download and analyze source map curl -s https://target.com/main.js.map | jq '.sources' # Extract original source code curl -s https://target.com/main.js.map | jq -r '.sourcesContent[]'
Source maps can reveal:
/home/developer/project/src/)bash# Extract hidden inputs curl -s https://target.com | grep -i 'type="hidden"' curl -s https://target.com | grep -i "type='hidden'" # Look for sensitive hidden fields curl -s https://target.com | grep -iE 'hidden.*value|hidden.*name'
html<input type="hidden" name="debug" value="true" /> <input type="hidden" name="admin" value="0" /> <input type="hidden" name="price" value="100" /> <input type="hidden" name="role" value="user" /> <input type="hidden" name="discount" value="0" />
bash# Extract data attributes curl -s https://target.com | grep -oP 'data-[a-zA-Z-]+="[^"]*"' # Look for sensitive data attributes curl -s https://target.com | grep -iE 'data-api|data-token|data-key|data-user|data-id'
bash# Find JSON in script tags curl -s https://target.com | grep -oP '<script[^>]*type="application/json"[^>]*>[\s\S]*?</script>' # Find window/global variables curl -s https://target.com | grep -oP 'window\.[a-zA-Z_]+\s*=\s*\{[^}]+\}'
html<script> window.__CONFIG__ = { apiKey: "secret123", environment: "staging", debugMode: true, } </script> <script type="application/json" id="app-data"> { "user": { "id": 1, "role": "admin", "token": "xyz" } } </script>
bash# Trigger errors and capture responses curl -s "https://target.com/api/test?id='" curl -s "https://target.com/nonexistent-page-12345" curl -s "https://target.com/" -H "Content-Type: invalid"
bash# Capture full response including body for redirects curl -sL -D - https://target.com/redirect-page # Using Burp/ZAP to intercept redirect responses # Disable "Follow redirects" and examine 3xx response bodies
bash# Get historical URLs waybackurls target.com | grep -iE '\.js$|\.json$|config|admin' # Check archived versions for leaked data curl -s "https://web.archive.org/web/2020/https://target.com/app.js"
| Tool | Description | Usage | | --------------- | --------------- | ---------------------------- | | curl/wget | HTTP client | curl -s https://target.com | | grep | Pattern search | grep -iE 'api_key\|secret' | | jq | JSON processor | jq '.sources' file.map | | waybackurls | Historical URLs | waybackurls target.com | | gau | Get All URLs | gau target.com |
| Tool | Description | Usage | | ---------------- | ------------------ | -------------------------------- | | truffleHog | Git secret scanner | trufflehog filesystem . | | gitleaks | Secret detection | gitleaks detect --source=. | | SecretFinder | JS secret finder | python3 SecretFinder.py -i url | | LinkFinder | Endpoint extractor | python3 linkfinder.py -i url | | JSParser | JavaScript parser | Extracts URLs from JS |
| Extension | Purpose | | --------------- | ----------------------- | | Wappalyzer | Technology detection | | Retire.js | Vulnerable JS libraries | | BuiltWith | Tech stack analysis | | Source Detector | Source map finder |
| Tool | Description | | ---------- | ----------------------------- | | Burp Suite | Intercept and analyze traffic | | OWASP ZAP | Automated scanning | | Fiddler | Traffic analysis | | Charles | HTTP debugging proxy |
| Service | Purpose | | ----------------------- | ------------------- | | KeyHacks | API key validation | | API Key Scanner | Cloud key detection | | Google Maps API Scanner | Maps key testing |
bash#!/bin/bash TARGET=$1 OUTPUT_DIR="content_scan_$(date +%Y%m%d)" mkdir -p $OUTPUT_DIR echo "[+] Scanning $TARGET for information leakage..." # 1. Download main page echo "[+] Downloading main page..." curl -s $TARGET -o "$OUTPUT_DIR/index.html" # 2. Extract and check comments echo "[+] Extracting HTML comments..." grep -o '<!--.*-->' "$OUTPUT_DIR/index.html" > "$OUTPUT_DIR/comments.txt" # 3. Extract META tags echo "[+] Extracting META tags..." grep -i '<meta' "$OUTPUT_DIR/index.html" > "$OUTPUT_DIR/meta_tags.txt" # 4. Extract JavaScript URLs echo "[+] Finding JavaScript files..." grep -oP '(?<=src=")[^"]*\.js[^"]*' "$OUTPUT_DIR/index.html" | sort -u > "$OUTPUT_DIR/js_files.txt" # 5. Download JavaScript files echo "[+] Downloading JavaScript files..." mkdir -p "$OUTPUT_DIR/js" while read js; do filename=$(basename "$js") if [[ $js == /* ]]; then curl -s "${TARGET}${js}" -o "$OUTPUT_DIR/js/$filename" else curl -s "$js" -o "$OUTPUT_DIR/js/$filename" fi done < "$OUTPUT_DIR/js_files.txt" # 6. Search for secrets in JavaScript echo "[+] Searching for secrets..." grep -rihE 'api_key|apikey|api-key|secret|password|token|auth|credential|AKIA|private_key' "$OUTPUT_DIR/js/" > "$OUTPUT_DIR/potential_secrets.txt" # 7. Check for source maps echo "[+] Checking for source maps..." while read js; do if [[ $js == /* ]]; then mapurl="${TARGET}${js}.map" else mapurl="${js}.map" fi status=$(curl -s -o /dev/null -w "%{http_code}" "$mapurl") if [ "$status" == "200" ]; then echo "Found: $mapurl" >> "$OUTPUT_DIR/source_maps.txt" fi done < "$OUTPUT_DIR/js_files.txt" # 8. Extract endpoints from JS echo "[+] Extracting endpoints..." grep -rohE '["'"'"']/[a-zA-Z0-9/_-]+["'"'"']' "$OUTPUT_DIR/js/" | sort -u > "$OUTPUT_DIR/endpoints.txt" # 9. Extract URLs echo "[+] Extracting URLs..." grep -rohE 'https?://[^\s"<>'"'"']+' "$OUTPUT_DIR/js/" | sort -u > "$OUTPUT_DIR/urls.txt" echo "[+] Scan complete. Results in $OUTPUT_DIR/"
bash# Install git clone https://github.com/m4ll0k/SecretFinder.git cd SecretFinder pip3 install -r requirements.txt # Scan single URL python3 SecretFinder.py -i https://target.com/app.js -o cli # Scan with regex python3 SecretFinder.py -i https://target.com/app.js -o cli -r 'api[_-]?key'
bash# Install git clone https://github.com/GerbenJavado/LinkFinder.git cd LinkFinder pip3 install -r requirements.txt # Find endpoints python3 linkfinder.py -i https://target.com/app.js -o cli # Output to file python3 linkfinder.py -i https://target.com -d -o results.html
bash# AWS Access Key AKIA[0-9A-Z]{16} # AWS Secret Key [0-9a-zA-Z/+]{40} # Google API Key AIza[0-9A-Za-z\\-_]{35} # Stripe API Key sk_live_[0-9a-zA-Z]{24} # Private Key -----BEGIN (RSA|DSA|EC|OPENSSH) PRIVATE KEY----- # Generic Secret [s|S][e|E][c|C][r|R][e|E][t|T].*['|"][0-9a-zA-Z]{32,45}['|"] # Generic API Key [a|A][p|P][i|I][_]?[k|K][e|E][y|Y].*['|"][0-9a-zA-Z]{32,45}['|"] # JWT eyJ[A-Za-z0-9-_=]+\.eyJ[A-Za-z0-9-_=]+\.?[A-Za-z0-9-_.+/=]* # Basic Auth basic [a-zA-Z0-9=:_\+\/-]{5,100} # Bearer Token bearer [a-zA-Z0-9_\-\.=:_\+\/]{5,100}
bash# Use build tools to strip comments # Webpack: terser-webpack-plugin # Gulp: gulp-strip-comments # npm: strip-json-comments
javascript// webpack.config.js const TerserPlugin = require("terser-webpack-plugin") module.exports = { optimization: { minimize: true, minimizer: [ new TerserPlugin({ terserOptions: { format: { comments: false, }, }, extractComments: false, }), ], }, }
javascript// BAD const API_KEY = "AIzaSyD-xxxxxxxxxxx" // GOOD const API_KEY = process.env.API_KEY
bash# .env file (never commit) API_KEY=your_api_key DB_PASSWORD=your_password # Add to .gitignore .env .env.local .env.*.local
javascript// webpack.config.js module.exports = { devtool: process.env.NODE_ENV === "production" ? false : "source-map", }
json// Angular: angular.json { "configurations": { "production": { "sourceMap": false } } }
javascript// Google Cloud Console // - Add HTTP referrer restrictions // - Add IP restrictions // - Limit API scope // AWS IAM // - Use least privilege // - Set resource restrictions // - Enable key rotation
[ ] No hardcoded credentials
[ ] No internal IPs in code
[ ] No developer comments in production
[ ] Source maps disabled
[ ] Environment variables used
[ ] Debug code removed
[ ] Test data removedyaml# GitHub Actions example - name: Scan for secrets uses: trufflesecurity/trufflehog@main with: path: ./ base: main extra_args: --only-verified
Base Score: Variable (5.3 - 9.8 depending on exposed data)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Score: 5.3 (Medium)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Score: 9.8 (Critical)
| Finding | Severity | Impact | | ----------------------- | -------- | ------------------------- | | Developer comments | Info | Limited exposure | | Version information | Low | Aids targeted attacks | | Internal paths/URLs | Low | Reconnaissance data | | API endpoints | Medium | Attack surface mapping | | Internal IP addresses | Medium | Network information | | Non-sensitive API keys | Medium | Service abuse potential | | Admin credentials | Critical | Full compromise | | Cloud credentials (AWS) | Critical | Infrastructure compromise | | Database passwords | Critical | Data breach |
| CWE ID | Title | Description | | ----------- | ------------------------------------------------------------ | ------------------------------ | | CWE-200 | Exposure of Sensitive Information | General information disclosure | | CWE-312 | Cleartext Storage of Sensitive Information | Hardcoded credentials | | CWE-615 | Inclusion of Sensitive Information in Source Code Comments | Comments with secrets | | CWE-540 | Inclusion of Sensitive Information in Source Code | Secrets in code | | CWE-798 | Use of Hard-coded Credentials | Hardcoded passwords | | CWE-209 | Generation of Error Message Containing Sensitive Information | Verbose errors |
[ ] HTML source code reviewed for comments
[ ] META tags analyzed
[ ] All JavaScript files downloaded
[ ] JavaScript searched for secrets (API keys, passwords)
[ ] JavaScript searched for internal URLs/paths
[ ] Source maps checked and analyzed
[ ] Hidden form fields reviewed
[ ] Data attributes examined
[ ] Inline JSON/data reviewed
[ ] Error responses analyzed
[ ] Redirect response bodies checked
[ ] Historical versions checked (Wayback)
[ ] Automated secret scanner run
[ ] Endpoints extracted and documented
[ ] Sensitive findings categorized by severity
[ ] Risk assessment completed
[ ] Remediation recommendations preparedOther measured skills in the registry, with their headline benchmark lift.