💻 TORHAT

Information disclosure in debug page

Steps to solve

1. Right click home page (/) -> Engagement Tools -> Discover content -> Click on Session is not running.
2. Go to Target -> Site map
3. Select url -> cgi-bin -> phpinfo.php
4. Right click that request to phpinfo.php file and copy url
5. Open new tab and paste it.
6. Ctrl+F and type SECRET_KEY.
7. Copy the value of SECRET_KEY variable and paste it as solution.

That's it Folks! Easy, isn't it?

Help us do more: Buy Me A Coffee