
Challenge 3/35: Plaintext Passwords in Logs Due to Debug Statement and Hidden SIEM Dashboard
ctfinformation_disclosuredebug_statementplaintext_passwordsSIEMhardcoded_credentials
🎯 Challenge 3/35 · Reconnaissance & Disclosure. Plaintext passwords in logs. Medium · Information Disclosure · 30–30 min. Exploiting a forgotten debug statement that logs plaintext passwords and a hidden SIEM dashboard with hardcoded credentials to retrieve a flag. Spin up the lab: npx create-oss-store my-ctf-lab. See it on the roadmap: https://koadt.github.io/oss-oopssec-store/roadmap#challenge-03. Walkthrough — spoilers, read it once you are stuck: https://koadt.github.io/oss-oopssec-store/posts/plaintext-password-in-logs. Star OopsSec Store on GitHub: https://github.com/kOaDT/oss-oopssec-store.