Web applications send and receive data across the network during user login. Security engineers inspect web traffic using browser DevTools to ensure sensitive credentials are never exposed in plain text.
You have been given valid login credentials. Your job is to investigate what happens when you log in.
- Open Developer Tools by pressing F12 (or Right-click → Inspect) and switch to the Network tab.
- Enter the provided username and password into the login portal below.
- Click the Login button.
- Watch the Network tab for the login HTTP request to appear.
- Click on the login request to inspect the Request URL, HTTP Method, and Payload/Query Parameters.
- Identify the security mistake being made during transmission.
Use the credentials below to log in:
Inspect your browser's F12 Network tab during login and reflect on the following observations:
-
1What HTTP method is used by the login request?
-
2Where can you see the username?
-
3Where can you see the password?
-
4Is exposing a password in the URL a good practice?
-
5What should normally be used to protect login traffic?
-
6Why should developers use HTTPS?
Awesome investigation! Here is your official proof of completion to send to your instructor in Google Meet chat: