Japan's University Entrance Examination Center exposed an “albums” directory listing—but did Common Test listening audio leak?
Separating an interface that looks secret from an actual disclosure, and asking how secrecy, transparency and trust should be designed for a national examination
A raw directory at /albums/ on Japan's National Center for University Entrance Examinations website displayed folders containing PDFs, images and MP3 files, triggering warnings on social media to “delete it now” and fears that future Common Test listening material might be discoverable. The audio we could identify was from completed examinations or an officially published sample; no leak of an unadministered test has been established. That does not make the configuration harmless. An institution entrusted with national examination equality must protect secrets and make the boundary between public information and protected material intelligible and auditable.
On the evening of 25 August 2026, a URL began spreading rapidly on Japanese social media.
It belonged to the official website of the National Center for University Entrance Examinations: https://www.dnc.ac.jp/albums/.
It did not look like a normal public-information page. Under the heading “Index of /albums,” it displayed a long list of numerically named folders. Some child directories exposed lists of files with opaque names beginning with abm and extensions including PDF, JPG, PNG and MP3. Individual files could be opened.
Posts preserved in Yahoo! Japan's real-time search reflected two sharply different interpretations:
- “Are we supposed to be able to see this?”
- “Delete it now—someone might obtain a test immediately before it is held.”
- “The listening MP3s play.”
- “These appear to be materials already published through the ordinary website.”
- “Even if the files are public, leaving directory listing enabled is careless.”
The anxiety is understandable.
The Center administers a national examination taken by roughly half a million people. If even one person obtained a future question in advance, the harm would not be a technical footnote. It would alter the conditions under which years of effort, university admission, scholarships and family expectations are compared.
But the ability to imagine a grave consequence is not evidence that the consequence occurred.
The first task is neither to minimize the concern nor to prosecute the institution in public.
It is to distinguish what the evidence establishes from what it does not.
The short conclusion: the listing was exposed; a future-test leak is unconfirmed
As verified on 26 August 2026, the following propositions were true:
- The Center's
/albums/path displayed a directory index without authentication. - Numerous child directories listed raw filenames for PDFs, images and MP3 files.
- Some listed files could be accessed directly.
The evidence we examined did not establish any of the following:
- questions for the Common Test scheduled for January 2027 were present;
- audio for an unadministered listening examination had leaked;
- applicants' personal data, credentials or internal system configuration had been published; or
- photographs in the listing identified confidential question writers.
The distinction is not a rhetorical way to say that nothing matters. Different failures require different remedies.
| Proposition | What was verified | Assessment |
|---|---|---|
| A directory index was public | “Index of /albums” appeared without authentication | Confirmed |
| Listed files could be opened | Examples included PDFs, images and MP3s | Confirmed |
| Information intended to remain private left the institution | No future test or personal data was identified | Unconfirmed at present |
| The configuration and governance were sound | Listing was enabled and no public explanation defined its scope | Serious doubt remains |
Between “a file is reachable” and “a secret leaked” lies a decisive question: was that file meant to be public?
But there is also a distance between “we did not find a secret” and “the system was safe.”
Were the listening files from the next Common Test?
MP3 files produced the strongest alarm.
That reaction is predictable. A PDF on a public institutional server may look like a report or past paper. “Examination audio on the Center's server” immediately evokes an unreleased listening test.
The audio-related material that could be identified, however, was also offered through normal official pages.
The Center's answers page for the 2026 Common Test publicly links the English listening question paper, volume-check audio, test audio and transcript. That is an intentional publication of an already administered examination for candidates, teachers and the public to inspect.
Its page explaining extended-time listening samples explicitly says that the samples use audio from the 2024 main examination. A transcript associated with one of the widely noticed file groups was labelled as the 2026 supplementary and re-examination, which had already taken place on 24 and 25 January 2026.
An MP3 extension is therefore not evidence of premature disclosure.
Likewise, the existence of images does not establish that private staff photographs or a confidential list of question writers was exposed. Some social-media users traced photographs and venue maps back to normal official pages, including the Center's leadership and past-examination pages.
Yet an external observer who matches several files cannot prove that every file was safe.
Only the Center possesses the complete deployment inventory, the mapping between files and public pages, publication histories and access logs. The most accurate conclusion is therefore limited:
Identifiable listening files were previously published examination audio or samples, and no unadministered test leak has been confirmed. Whether every file in every listed directory was intended for publication cannot be established without the operator's own audit and explanation.
What is directory listing?
People ordinarily reach documents on a website through headings, navigation, search results and download buttons.
Behind those pages, PDFs and images live in folders on a web server. If a person requests a folder URL and no index page handles the request, some server configurations generate a list of its contents. This is directory listing.
A directory index does not necessarily expose an entire server or an employee's computer. It displays resources under the web-accessible path that the server has been configured to serve.
Even so, disabling it is standard practice for a general public website.
OWASP Top 10: 2025 expressly recommends disabling web-server directory listing and keeping metadata and backup files outside web roots as part of preventing broken access control.
The reason is not that a listing automatically steals all data.
It makes unlinked material systematically discoverable.
Items mistakenly left under a public web root may include:
- superseded versions;
- drafts awaiting publication;
- backups;
- temporary spreadsheets or rosters;
- source images and editing files; or
- documents whose links were removed but whose files remained.
A URL that is difficult to guess is not genuine access control. Directory listing removes even that friction and supplies a catalogue that can be explored automatically.
The risk is less like finding the door to an entire building unlocked than finding the warehouse inventory at the entrance. If every box contains a public brochure, no secret has yet been disclosed. But the next box placed on the wrong shelf will immediately appear in the catalogue.
“It was all public information” is only half an answer
It is a public service—not a breach—for people to obtain past questions, statistics, regulations and research reports from the Center.
Indeed, the institution should publish much of this material. Public access to questions, answers, score adjustment, financial documents and research supports the legitimacy of a selection system that exercises enormous influence over educational opportunity.
Finding a past paper, a statistical report or an official portrait is not, by itself, an information leak.
But “public” describes at least three different conditions.
| Form of publicness | Example | Meaning available to the user |
|---|---|---|
| Intended publication | An official page gives the title, date, explanation and download link | The user understands what the item is and why it is public |
| Technical reachability | Anyone who knows the raw URL can open the file | Publication intent may be unclear |
| Unintended exposure | An index or deployment mistake reveals unpublished material | Confidentiality or privacy may be violated |
The problem here is that the storage layer supporting the first form was visible in the second form as a whole.
Even if most files corresponded to intended publications, that correspondence was not legible in the listing. Opaque filenames supplied no title, publication date, reason for release or status.
The result was that legitimate public documents looked like the contents of a secret repository accidentally opened.
This is not only a failure to protect confidentiality. It is a failure to communicate the meaning and governance of information.
Hume: “I had not seen it before” does not entail “it leaked”
David Hume warned against reading more necessity and causation into observed events than the evidence supports.
The inference experienced by social-media users is easy to reconstruct:
- A raw file index unlike the normal website suddenly appeared.
- It contained MP3s and large numbers of PDFs.
- The Center handles secret examination material.
- Therefore secret examination material may have leaked.
The first three propositions do not logically establish the fourth.
The listing is evidence that configuration governance may have been weak. It is not the same evidence as an unreleased question or future-test label.
The rational response is neither unconditional reassurance nor maximal accusation. It is to adjust confidence to the evidence:
- Seeing the index substantially increases confidence that directory listing was left enabled.
- Matching many files to official pages reduces confidence in a theory of wholesale secret leakage.
- The absence of a complete operator audit prevents a claim of zero risk.
- Without concrete future-test material, we should not report that “the Common Test leaked.”
Sophisticated scepticism is not disbelief in everything.
It is proportioning doubt to proof.
Foucault: the institution that examines candidates became the examined
Michel Foucault argued that modern institutions exercise power by observing, recording, examining and classifying individuals.
The Common Test is a literal and vast examination apparatus.
Candidates arrive at specified times, submit to identity checks, follow standardized instructions, produce recorded answers and are compared through scores. The institution makes candidates intensely visible. The internal processes of question writing, file governance and incident response, by contrast, are deliberately difficult to see.
The /albums/ index momentarily reversed that gaze.
Candidates and technologists stared at the impersonal storage structure behind the institution and asked: who examines the examiner?
That reversal has democratic value. A public body must be open to observation by the people whose opportunities it helps allocate. It would be wrong to dismiss a good-faith question as ignorant panic or to treat every person noticing the listing as a hostile attacker.
Visibility, however, is not the same as intelligibility.
A screen of numbers and extensions does not explain the institution. Contextless visibility can amplify suspicion instead of strengthening public oversight.
Democratic accountability does not require making everything naked. It requires explaining public procedures, justifying what must remain secret and for how long, and enabling verification that the boundary is actually enforced.
Onora O'Neill: more transparency does not automatically produce more trust
Philosopher Onora O'Neill has challenged the assumption that accountability is equivalent to indiscriminate transparency.
Publishing more information does not necessarily make an institution more trustworthy. Fragments without context, responsibility or intelligible organisation may generate more suspicion.
That paradox fits this incident.
Reachability of thousands of raw files is not meaningful institutional transparency. A reader cannot tell which version is current, which public page authorizes its release, whether it is obsolete, whether publication is pending or who approved it.
The O'Neillian question is not “how much did you display?” It is whether your conduct merits trust.
To merit trust here, the Center should be able to answer at least these questions:
- Was directory listing intentionally enabled?
- Was every listed file already published or deliberately prepared for publication?
- Were future questions, personal data and credentials structurally prevented from entering the same web root?
- For how long was listing available, and what access occurred?
- What was changed, and how will recurrence be detected?
“There was no problem” is not an adequate explanation.
The public needs to know what was examined and why the result justifies that conclusion.
Rawls: examination secrecy can protect equality rather than power
Transparency is a democratic principle, but not every secret is anti-democratic.
From John Rawls's perspective, institutions allocating educational opportunity and social positions should operate under fair conditions.
The reason to keep an unadministered Common Test secret for a limited period is not to protect the prestige of an agency.
It is to ensure that candidates sit the examination under equal informational conditions.
If a small group sees a question or audio file in advance, the advantage cannot simply be recalled later:
- not every viewer may be identifiable;
- memories and oral transmission cannot be deleted;
- knowledge of a leak makes all candidates doubt the examination;
- replacing questions can disrupt printing, transport, disability accommodations, schedules and venues nationwide.
In this context, secrecy is an instrument of fair opportunity.
That is why a configuration that merely appears capable of leaking questions can still be serious. Justice in an examination is not exhausted by accurate scoring. Participants need rational grounds to believe that they and others were governed by the same rules.
Security therefore has two layers:
- Substantive security: no candidate obtained an unadministered question.
- Institutional trustworthiness: audit, records and explanation make that judgment credible.
Without the second, even a true claim about the first may fail to restore confidence.
Kant: “I found it” is not the same as “I may exploit it”
When a public URL opens, an ethical question remains even before the legal analysis: may a person save everything and republish it?
Kant's test of universalisation asks whether the maxim of one's conduct could coherently be adopted by everyone.
Consider the maxim:
Anyone who finds a public institution's configuration error may copy and broadcast all accessible contents without restraint.
Universalised, that principle turns incident reporting into mass replication of the harm. Personal data and examination material would be copied irreversibly before the institution could assess or contain them.
Responsible conduct therefore includes:
- verifying only the minimum needed to establish the configuration problem;
- reporting apparently unpublished or personal material without publishing its contents;
- avoiding bulk download, guessing campaigns, modification and authentication bypass;
- describing the verifiable configuration rather than redistributing raw files; and
- asking the operator to remediate and explain.
Yet public restraint must not become institutional absolution.
The party entrusted with secrets, technical authority and budget bears a heavier duty than the citizen who happens to notice a URL.
Hans Jonas: low-probability, irreversible harm justifies prevention
Hans Jonas argued that technologies with large and far-reaching effects impose stronger responsibilities toward the future.
Even if the probability that a future Common Test file will be placed under a public directory is low, the possible damage is vast and difficult to reverse.
“No secret was found this time, so the configuration may remain” is therefore weak reasoning.
The cost of disabling automatic indexes is small. The cost of a genuine premature disclosure is immense. Precaution supports closing the catalogue and auditing the entire deployment.
But the social-media command to “delete it now” should not be interpreted as an instruction to erase all files.
Past papers, applicant guides, research and venue maps are public services linked from normal pages. The right response is to disable automatic listing, preserve intended links and reconcile every deployed file with a publication inventory.
Precaution is not destructive panic. It is proportionate care: using a small intervention to reduce a large irreversible risk.
What should the Center do?
The response should be judged less by the size of an apology than by the specificity of verification.
Disable directory indexes
Automatic listing should be turned off for /albums/ and its descendants. Existing official pages can continue linking to individual public files; public documents need not disappear.
Reconcile the web root with a publication register
Every deployed file should have a corresponding official page, title, publication date, responsible unit and current or superseded status. Files without a documented publication route require individual review.
Separate confidential and public environments structurally
Future questions, personal information and working drafts must not rely on “there is no link, so nobody will find it.” They should be managed in separate authenticated and audited systems, not under a public web root.
Examine logs and caches
The Center should determine when listing became available and whether unusual exploration or bulk retrieval occurred. If any protected material existed, search indexing, caches and third-party copies would also need attention.
Publish findings in stages
An initial notice should describe the event, scope under investigation and any action expected of users. A final account should state whether protected information existed, the exposure period, log findings, remediation and recurrence prevention. Invoking “security reasons” to say nothing does not rebuild trust.
Provide a safe reporting channel
People who discover vulnerabilities or configuration errors need a clearly advertised channel before they resort to social media. The policy should welcome good-faith reports while defining the limits of authorized verification.
Detect recurrence continuously
Controls should flag unexpected files and extensions in the public environment, support recurring outside-in assessment and require pre-publication checks. Security is not the memory of one successful audit; it is the capacity to detect the next mistake quickly.
Security is the quality of a boundary, not the quantity of secrecy
The binary choice between “all the files were public, so nothing happened” and “a listing appeared, so the Common Test leaked” misses the essential problem.
There is presently no basis for asserting that an unadministered test leaked. The listening material we could identify was past examination audio or a sample published through official pages. That matters. Unsupported claims of a future-test leak can needlessly distress candidates and inflict unfair damage on the institution and its staff.
At the same time, public directory listing is not merely an untidy visual setting.
It makes the boundary between intended publication and accidental exposure ambiguous from the outside. Even if today's shelves held only public documents, the next mistaken deployment might not.
The Center must protect more than the secrecy of a question paper. It must protect confidence that:
- candidates competed under the same informational conditions;
- public documents are authentic and accompanied by context;
- anomalies are detected, recorded and explained; and
- citizens who raise responsible concerns receive a responsible answer.
Together, those conditions constitute institutional trust.
A secret is not secure merely because it is obscure.
It is secure when an institution has deliberately designed what is public, what is closed and who verifies the boundary.
The directory index did not prove that the Common Test leaked.
It exposed a harder question: what grounds do citizens have for believing that it did not?
NOW IN QUESTION
- Is every resource reachable at a public URL ethically and institutionally “meant to be public”?
- If no future question is found, is enabled directory listing a minor problem?
- How transparent should a public institution be, and which temporary secrets are necessary for equality?
- Where should a citizen draw the line between warning others and amplifying harm?
- Is saying that no harm occurred equivalent to having a system that can demonstrate it?
Sources
- National Center for University Entrance Examinations: “Index of /albums”
- The Center: answers and listening materials for the 2026 main examination
- The Center: extended-time listening audio samples
- The Center: Information Security Basic Policy
- The Center: Information Systems Security Rules
- OWASP Top 10: 2025, A01 Broken Access Control
- OWASP Web Security Testing Guide: unreferenced files and directory listing