Farewell – TryHackMe challenge writeup

Description https://tryhackme.com/room/farewell Use red-teaming techniques to bypass the WAF and obtain admin access to the web application. The farewell server will be decommissioned in less than 24 hours. Everyone is asked to leave one last message, but the admin panel holds all submissions. Can you sneak into the admin area and read every farewell message … Read more

Paddelify – TryHackMe challenge

Description You’ve signed up for the Padel Championship, but your rival keeps climbing the leaderboard. The admin panel controls match approvals and registrations. Can you crack the admin and rewrite the draw before the whistle?Note: In case you want to start over or restart all services, visit http://10.82.162.200/status.php Directories enumeration First I used common feroxbuster … Read more