Content Discovery
Last updated
Last updated
The answers for these questions were in the reading:
I see the following at IP_Address/robots.txt
:
This is what the disallowed endpoint showed:
The THM written part mentioned the command to run: curl https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico | md5sum
I run the command on my local machine:
The favicon was from cgiirc. Another way to find this was to open the favicon:
If you can read the image, it spells out cgiirc.
We can look through the sitemap to see if there is anything interesting. I found the following:
This led me to this site:
Running the command mentioned in the Task, I got the following:
I accessed the link mentioned in the Task, and got here:
I then went under documentation, and saw the following:
Using those credentials (on that endpoint) I was then able to get the flag:
You can answer the question by looking at the information provided on the page:
The answer was site:
The answer to this question was based on the reading in the Task: wappalyzer
Similar to the last question, the answer to this question was in the reading as well: https://archive.org/web/
The answer was in the reading:
The answer was once again in the reading:
I ended up using ffuf
, since it seemed to be the fastest for me in terms of response:
I then ran a Control-F on , and I found this: