March 28, 2024, 5:04 p.m. | Serdar Çatal

System Weakness - Medium systemweakness.com

Difficulty: Medium

As always, let’s start with nmap:

“nmap scan result”

There are open ports on 22, 80 and 3306. Port 80 has a web server:

Okay, it is just a regular webpage. But when I put my cursor on the employment section on the navigation bar, I got this:

So, I got a hostname and a subdomain. Do not forget to add this to the “/etc/hosts” file on your device:

<IP_ADDRESS> empline.thm job.empline.thm

Let’s have a look at “job.empline.thm”: …

cybersecurity red team tryhackme tryhackme-walkthrough vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States