Road
Last updated
Last updated
Room Link: https://tryhackme.com/room/road
Kali
Kali
Kali
I go to the /v2/ directory and it forwards me a login, I then create a user.
Under profile it tells us the admin email. admin@sky.thm
There is a page that allows us to update our password, I try with my account with burp running to intercept.
I change my email to admin and it seems to work
I can login as admin
Under profile there is a page that accepts uploads for profile pictures but there doesn't seem to be any filtering
Kali
Just changed the IP part.
From the source we can see a place where the images are uploaded to
Kali
directory listing is disabled but we know the name of the file, it doesn't change the name
Get autocomplete
Victim
Victim
Victim(mongo)
Victim
Victim(webdeveloper)
Victim(webdeveloper)
preload.c
Victim(webdeveloper)