> For the complete documentation index, see [llms.txt](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kaelenvs-cybersecurity-notes.gitbook.io/kaelens-tryhackme-experience/learning-paths/comptia-pentest+/application-based-vulnerabilites/owasp-top-10/severity-3-sensitive-data-exposure.md).

# \[Severity 3] Sensitive Data Exposure

Notes about Sensitive Data Exposure & the practical.

Sensitive Data Exposure - when a webapp accidentally exposes sensitive data. Usually consists of customer information and could also be more technical information such as usernames and passwords.&#x20;

The most common way to store a large amount of data is in a database. Databases usually follow SQL syntax or sometimes NoSQL.

Sometimes databases could be stored underneath the root directory of the website which can be downlaodable and queried from our own machine.&#x20;

sqlite3 is the most common flat-file database and can be interacted with most programming language.

To access a SQlite database, we can use the command, "`sqlite3 <database-name>`"

To see the tables in the database we can use the "`.tables`" command.&#x20;

**Practical**

To begin with this practical, I navigated to the webapp located at 10.10.37.57 and looked around the page source for comments.

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2F0fz7XrI8UAZzvvv2egfN%2F10.PNG?alt=media&amp;token=4a4baf72-6c58-492d-92fa-650927135523" alt=""><figcaption><p>The website's home page.</p></figcaption></figure>

Nothing stood out to me on the home page so I went to the next link I saw which was the /login page. On the /login page I could see some comments in the html code.&#x20;

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FcCbNhyIXbbjBHLcnpJhB%2F11.PNG?alt=media&amp;token=dadfc2d6-f520-449a-a347-09e2f70eeeb4" alt=""><figcaption><p>http://10.10.37.57/login</p></figcaption></figure>

From the comment we found in the code, we can see there is a database stored at /assets.&#x20;

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2FaD5rM1tL12SHQ4nzplRy%2F12.PNG?alt=media&amp;token=b19b3c6c-e87a-4941-b853-4080b2f14400" alt=""><figcaption><p>http://10.10.37.57/assets</p></figcaption></figure>

From here, we can answer the first two questions. The mentioned directory is /assets and the important looking file is webapp.db.&#x20;

I downloaded the webapp.db file and began running sqlite3.&#x20;

<figure><img src="https://618011075-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9sSHX9Ko3IU7Hcot2eC8%2Fuploads%2Frz3d3GASlqMxKepmO5Q8%2F13.PNG?alt=media&amp;token=2094228b-59ec-4ece-aa58-5a745846771c" alt=""><figcaption><p>sqlite webapp.db</p></figcaption></figure>
