Uploaded July 2023 | Updated September 2026, 3 hours ago
In this video, Tib3rius completes four Information Disclosure labs from Portswigger Web Academy.
The labs completed are as follows:
Information disclosure in error messages: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-in-error-messages
Information disclosure on debug page: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-on-debug-page
Source code disclosure via backup files: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-via-backup-files
Authentication bypass via information disclosure: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-authentication-bypass
0:00 - Introduction
0:20 - Starting Lab: Information disclosure in error messages
1:02 - Manually "fuzzing" parameters with unexpected input, solving the lab.
2:59 - Starting Lab: Information disclosure on debug page
3:18 - Finding the debug page link in the source code, solving the lab.
4:25 - Starting Lab: Source code disclosure via backup files
5:42 - Finding the backup location in robots.txt.
6:41 - Starting Lab: Authentication bypass via information disclosure
8:13 - Using the TRACE HTTP method to expose headers added to our request.
9:21 - Identifying the custom header and using it to bypass authentication.
10:19 - Outro
Twitter: twitter.com/0xTib3rius
Twitch: twitch.tv/0xTib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
Threads: threads.net/@0xtib3rius
LinkedIn: linkedin.com/in/tib3rius
Facebook: facebook.com/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social
In this video, Tib3rius completes four Information Disclosure labs from Portswigger Web Academy.
The labs completed are as follows:
Information disclosure in error messages: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-in-error-messages
Information disclosure on debug page: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-on-debug-page
Source code disclosure via backup files: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-via-backup-files
Authentication bypass via information disclosure: portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-authentication-bypass
0:00 - Introduction
0:20 - Starting Lab: Information disclosure in error messages
1:02 - Manually "fuzzing" parameters with unexpected input, solving the lab.
2:59 - Starting Lab: Information disclosure on debug page
3:18 - Finding the debug page link in the source code, solving the lab.
4:25 - Starting Lab: Source code disclosure via backup files
5:42 - Finding the backup location in robots.txt.
6:41 - Starting Lab: Authentication bypass via information disclosure
8:13 - Using the TRACE HTTP method to expose headers added to our request.
9:21 - Identifying the custom header and using it to bypass authentication.
10:19 - Outro
Twitter: twitter.com/0xTib3rius
Twitch: twitch.tv/0xTib3rius
Courses: courses.tib3rius.com
Udemy: udemy.com/user/tib3rius
Discord: discord.com/invite/4qrvKMh
Threads: threads.net/@0xtib3rius
LinkedIn: linkedin.com/in/tib3rius
Facebook: facebook.com/0xTib3rius
InfoSec Exchange: https://infosec.exchange/@tib3rius
Bluesky: https://bsky.app/profile/tib3rius.bsky.social










