We use burp to analyse the traffic and we try to solve a challenge where we attack a web API of the application and try to extract private data from there.