Skip to content

Commit f62dcbe

Browse files
committed
Adding instructions for 2nd exercise - information disclosure
1 parent dc6e9dc commit f62dcbe

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

Exercises/Exercise-02.md

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
# Information disclosure
2+
3+
1. Complete Exercise-01.md
4+
2. Using the "api/todotiems/name/<name>" GET endpoint, fetch a previously created todoitem by name. Note that you do not need to enter a full name to get back an item, so if multiple items match the "name" term, they will all be returned.
5+
6+
*What happens if you search for items with just a quote? (')*
7+
*What does this result tell us about the system?*

0 commit comments

Comments
 (0)