April 28, 2023, 10:57 a.m. | Ryan Yager

System Weakness - Medium systemweakness.com

Today we are going to take a look at Glitch on Try Hack Me, which can be found here:

TryHackMe | GLITCH

The machine is rated as easy, and with a little enumeration it was not too bad. Lets start off with a RustScan:

We see that port 80 is open, lets do some of our inital reconnisance:

We see that their is an /api/access function:

Now we got a token, and it looks like base64:

Now that we have …

access api bad base64 cookie curl enumeration function glitch hack hacking machine port rustscan start token tryhackme value

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens