Do Not Crawl
Client: the photography club at a secondary school, who run Shutterbox to show off their event photos. Engagement: Black-box assessment of Shutterbox before the club announces it publicly.
Scope
In scope: the Shutterbox application served at this origin and every HTTP endpoint it exposes.
No account has been issued to you, because Shutterbox has no sign-in. Every request you make is the request an anonymous visitor makes.
Out of scope: the hosting platform, other engagements, and denial of service.
Rules of engagement
The club committee has asked for this assessment and controls the system. Reach the objective and stop — they want to know what a stranger can find, not to have their site taken apart. Leave stored data intact, and stay inside the scope above.
The club has not released the site's source code. Work from what the running system tells you.
Constraints
Do not guess your way in. Enumerating addresses, wordlist scanning, and brute-forcing anything are all out of scope, and a finding reached that way will not be accepted. Every address you need is one the site hands you.
Objective
The committee believes two things protect Shutterbox. The folders they would rather nobody browsed are excluded in robots.txt, so search engines pass them by. And their committee console answers on an address so long and arbitrary that guessing it is hopeless — which is why they have never bothered to put a password on it.
The second belief is sound. The first one is doing no work at all, and the club has not noticed that the difference matters.
Disprove them: reach the committee console and recover the site key it displays. That key is what the club will accept as proof of impact. Submit it below to close the engagement.
Deliverable
The club wants a record of how you got there, not only the result. Log each request that moved the assessment forward in the Notes panel, and export the session when you are done.