Walkthroughs

Penetration testing reports from TryHackMe and CTF rooms. 2 posts published.

TryHackMeEasy6 findings

Jack-of-All-Trades

A penetration test was conducted against the target host 10.65.146.188. The assessment identified multiple critical vulnerabilities including credential exposure via HTML source code, hidden data in image files (steganography), an unauthenticated remote code execution endpoint, SSH credential disclosure via a…

Read walkthrough
TryHackMeMedium6 findings

Recruit

A penetration test was conducted against the Recruit web application hosted at recruit.thm (10.65.180.189). The engagement identified a chain of critical vulnerabilities that allowed an unauthenticated attacker to read arbitrary local files from the server, recover hardcoded credentials, exploit a SQL injection…

Read walkthrough