> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/pt-br/web/information-disclosure/information-disclosure-on-a-debug-page.md).

# Divulgação de Informações em uma Página de Depuração

### Divulgação de Informações na Página de Depuração

**Descrição do laboratório**

Este laboratório contém uma página de depuração que divulga informações sensíveis sobre a aplicação. / O objetivo é identificar e enviar a variável de ambiente **SECRET/ KEY**.

**Observação inicial**

Ao interceptar solicitações HTTP, vemos o envio de uma **GET** consulta contendo um parâmetro relacionado à chave do socket. / Isso indica a presença de mecanismos de depuração ou diagnóstico expostos.

**Análise com o Burp Suite**

* Ao explorar o **Mapa do site** do Burp Suite, uma página sensível é identificada.
* Um **phpinfo** página está acessível, o que representa um vazamento crítico de informações.

<figure><img src="/files/c5298efad5bb8311c40ca49c1bd340bfc125bfac" alt=""><figcaption></figcaption></figure>

**Recurso vulnerável**

Caminho identificado:

```bash
/cgi-bin/phpinfo.php
```

Esta página exibe a configuração completa do PHP, incluindo variáveis de ambiente.

**Dados sensíveis divulgados**

Na `phpinfo.php` página, a seguinte variável é exibida:

* **SECRET/\_KEY** :

<figure><img src="/files/10e1773430ab689a960111bfdccca8a81c2bc54c" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/pt-br/web/information-disclosure/information-disclosure-on-a-debug-page.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
