<?xml version="1.0" encoding="UTF-8"?>
<!--
  sitemap.xml
  ───────────
  This sitemap is technically valid XML. It lists URLs. Some of those URLs
  are real. Some of them are not. The proportion of "not" is roughly 100%
  minus 1. Have fun figuring out the 1.

  If you came here from a recon script that just scrapes <loc> tags and
  feeds them back into a fuzzer — congrats, you're about to fuzz the
  honeypot list a second time. Recursion is beautiful.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">

  <!-- the one real page -->
  <url>
    <loc>https://example.com/</loc>
    <changefreq>weekly</changefreq>
    <priority>1.0</priority>
  </url>

  <!-- the rest are window dressing -->
  <url><loc>https://example.com/admin/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/administrator/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/wp-admin/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/phpmyadmin/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/internal/dashboard</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/staging/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/dev/</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/backup.zip</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/database.sql</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/.env</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/.git/HEAD</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/api/v1/internal/users</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/api/swagger.json</loc><priority>0.1</priority></url>
  <url><loc>https://example.com/flag.txt</loc><priority>0.0</priority></url>
  <url><loc>https://example.com/credentials.txt</loc><priority>0.0</priority></url>
  <url><loc>https://example.com/id_rsa</loc><priority>0.0</priority></url>
  <url><loc>https://example.com/you-found-me/</loc><priority>0.0</priority></url>

  <!--
    note to self: remember to replace example.com with the real domain after
    deploy. or don't! it's funnier if every recon script ends up fuzzing
    example.com's IANA-reserved domain. they have great uptime.
  -->
</urlset>
