Road
Room Link: https://tryhackme.com/room/road
Initial Scan
Kali
nmap -A $VICTIM
Scan all ports
Kali

TCP/80 - HTTP
Kali

I go to the /v2/ directory and it forwards me a login, I then create a user.

Under profile it tells us the admin email. admin@sky.thm

There is a page that allows us to update our password, I try with my account with burp running to intercept.


I change my email to admin and it seems to work

I can login as admin

Under profile there is a page that accepts uploads for profile pictures but there doesn't seem to be any filtering
Kali
Just changed the IP part.


From the source we can see a place where the images are uploaded to

Kali
directory listing is disabled but we know the name of the file, it doesn't change the name



Get autocomplete
TCP/27017 - MongoDB
Victim

Victim
Victim(mongo)

Victim
Victim(webdeveloper)

Victim(webdeveloper)
preload.c
Victim(webdeveloper)

Last updated