March 24, 2023, 2:02 p.m. | Ryan Yager

System Weakness - Medium systemweakness.com

Today we are going to look at a machine on Try Hack Me that is vulnerable to Cross Site Scripting (XSS) to be able to read a file on the local server.

TryHackMe | MD2PDF

We will start off as normal with a rustscan / nmap scan:

Port 5000 is strange, I ran an NMAP scan on it to see what it was and it turned out to be the same thing as port 80:

Looking at both 5000 and …

cross site scripting file hack hacking local machine nmap oscp penetration testing port run rustscan scan scripting server start tryhackme tryhackme-walkthrough vulnerable xs xss

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States