> For the complete documentation index, see [llms.txt](https://www.marialc.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.marialc.com/pentesterlab-labs/recon-badge/recon_02-.well-known-security.txt.md).

# recon\_02 (/.well-known/security.txt)

View the exercise here: [PentesterLab: Recon 02](https://pentesterlab.com/exercises/recon_02/course)

### **OBJECTIVE**

For this challenge, your goal is to retrieve the **security.txt** from the main website for **hackycorp.com**.

### **THE SECURITY.TXT FILE**

The **security.txt** file is used to tell security researchers how they can disclose vulnerabilities for a website. You can learn more about it here: [**securitytxt.org**](https://securitytxt.org/) and on Wikipedia: [**Security.txt**](https://en.wikipedia.org/wiki/Security.txt).

### **SOLUTION**

{% hint style="success" %}
The `/.well-known/security.txt` is a file used to provide security-related information about a website. Go to **`hackycorp.com/.well-known/security.txt`** to find the flag for this challenge.
{% endhint %}

<div align="left"><figure><img src="https://290105472-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F89FZKOizBQcf0e0Qdrp8%2Fuploads%2FhutwXmUTEd4Af9kFnuR2%2FUntitled.png?alt=media&amp;token=55980640-7307-4b1d-b563-258bb6b46b63" alt="" width="441"><figcaption></figcaption></figure></div>
