Road

Room Link: https://tryhackme.com/room/road

Initial Scan

Kali

nmap -A $VICTIM

Scan all ports

Kali

TCP/80 - HTTP

Kali

I go to the /v2/ directory and it forwards me a login, I then create a user.

Under profile it tells us the admin email. admin@sky.thm

There is a page that allows us to update our password, I try with my account with burp running to intercept.

I change my email to admin and it seems to work

I can login as admin

Under profile there is a page that accepts uploads for profile pictures but there doesn't seem to be any filtering

Kali

Just changed the IP part.

From the source we can see a place where the images are uploaded to

Kali

directory listing is disabled but we know the name of the file, it doesn't change the name

Get autocomplete

TCP/27017 - MongoDB

Victim

Victim

Victim(mongo)

Victim

Victim(webdeveloper)

Victim(webdeveloper)

preload.c

Victim(webdeveloper)

Last updated