> For the complete documentation index, see [llms.txt](https://lyethar.gitbook.io/methodology/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://lyethar.gitbook.io/methodology/readme/exploitation/web-applications/discovering-hidden-parameters.md).

# Discovering Hidden Parameters

{% embed url="<https://github.com/s0md3v/Arjun>" %}

Arjun is a tool designed to discover hidden parameters in websites.&#x20;

![](/files/nwAcok0vCA3dYetUIHAJ)

Notice how the tool was able to find the parameter flag.

Lets take another example for the sake of explanation.

![](/files/8nRS8VeAXeabT8xu08NB)

Notice the page parameter.&#x20;

![](/files/EJZwHSIFuhcYFbFDX1Ix)

Notice how arjun was able to figure out the parameter page on its own.&#x20;
