Neighbour — THM Walkthrough
infosecwriteups.com·5d
🔓Password Cracking
Preview
Report Post

Initial Reconnaissance

Even though this is an IDOR-focused room, I started with a quick Nmap scan to check exposed services.

~$ nmap -sV 10.49.151.21

The scan completed cleanly and confirmed that the host was reachable. Only two TCP ports were open.

PORT   STATE SERVICE VERSION22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.580/tcp open  http    Apache httpd 2.4.53

SSH was open, but the web service on port 80 was clearly the main attack surface.

Web Exploitation

I navigated to the web application running on port 80 and was presented with a simple login interface.

At first glance, the page looked intentionally minimal. One detail stood out immediately: a message below the login form referencing a guest account, along with a hint to inspect the …

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help