Member-only story
Lo-Fi: TryHackMe Writeup.
Tackling the Lo-Fi TryHackMe room turned out to be a fascinating adventure! With a mix of curiosity and determination, I jumped right into it, and what followed was an enjoyable learning experience plus a little bit of brute forcing the directory! Follow the steps below to reach to the flag!!!!
Step 1: The Foundation — Scouting the Terrain:
As always the very first step to any challenge is the very well known reconnaissance phase using Nmap. As seen in the below image we get two open ports: 22 for ssh and 80 for http.
data:image/s3,"s3://crabby-images/0fffe/0fffee51b6314e4c1ab20eaabbf1511066e9da45" alt=""
Step 2: Peeling Back the Layers:
Opening the web application in my browser, I began analyzing its structure. The source code hinted at a potential Local File Inclusion (LFI) vulnerability, and I decided to test it out.
How to Perform an LFI Attack
1. Inputs: Look for parameters in the URL or form fields that load files, such as
?page=
or?file=
.
2…