She remembered an old trick from a cybersecurity webinar: look for exposed directory indexes and change logs.
inurl:view index.shtml 24 upd