Skip to main content

Training Update v0.91

blank
blank

Tuesday time and it’s time for more THM!

Today we start off with the NoSQL Injection room as part of the Web Application Pentesting pathway.

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

We find that John’s password is eight characters in length and starts with a number

blank

John’s password consists of only numbers and is 10584312

blank
blank
blank

pedro:coolpass123

blank

Flag – flag{N0Sql_n01iF3!}

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

Now we move on to the XXE Injection room on THM!

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

Flag – THM{1N_b4Nd_1$_34sYY}

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

blank

Flag – THM{0O8_xx3!!}

blank
blank
blank
blank

https://tryhackme.com/leagues

blank
blank
blank

Until next time & don’t sleepwalk through life!

Atsisveikink