April 28, 2023, 10:57 a.m. | Ryan Yager

System Weakness - Medium systemweakness.com

Today we are going to take a look at Glitch on Try Hack Me, which can be found here:

TryHackMe | GLITCH

The machine is rated as easy, and with a little enumeration it was not too bad. Lets start off with a RustScan:

We see that port 80 is open, lets do some of our inital reconnisance:

We see that their is an /api/access function:

Now we got a token, and it looks like base64:

Now that we have …

access api bad base64 cookie curl enumeration function glitch hack hacking machine port rustscan start token tryhackme value

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)