May 1, 2024, 4:29 p.m. | anuragtaparia

System Weakness - Medium systemweakness.com

Hey, I am back with another write-up. Try this room and many more at TryHackMe!!!

NMAP Scan

nmap scannmap [IP] -sV -T5

We get three open ports 22, 80, 8000

Port 80 and 8000

Both the port gives 403 Forbidden error.

port 8000port 80

Now let’s do directory fuzzing on port 8000 via gobuster.

gobuster on port 8000gobuster dir -u [URL] -w /path/to/wordlist

Let’s check /robots.txt

/robots.txt

found FLAG 1 and I saw that all .sql,.zip, and .bak extension …

ctf ctf-writeup tryhackme tryhackme-walkthrough tryhackme-writeup

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom