Challenges do NOT require any bruteforcing/directory fuzzing/massive amounts of traffic unless clearly specified in the challenge information below.
Note: This challenge just requires you to have a keen eye. Look carefully!
Firstly, this developer hid his admin panel at a random subdomain he didn't think anyone could find. Because of this thinking (didn't think anyone would find it), the dev was kind of sloppy with how he secured his admin panel. Can you find a way in, and is there anything else vulnerable? (Hint: XSS?)