Skip to content

Mido9980/THM-Offensive-Security

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 

Repository files navigation

TryHackMe - Intro To Offensive Security Lab

Description

This lab consists of an easy break down into the world of an ethical hacker that looks for faults in websites that leads to vulnerable information or access to important systems. The following lab is TryHackMe's introduction into the world of hacking by simulating a loophole in a banking website, where money can be transferred to another account.

Languages and Utilities Used

  • GoBuster v2.0.1
  • Terminal
  • Web Browser

Environments Used

  • Ubuntu

Lab Walk-through:

Launch Browser and Visit Targeted Site:

Intro To Offensive Security

Finding Hidden Website Pages :
Intro To Offensive Security

Open Terminal and use command to find potentially hidden and vulnerable pages.

gobuster -u http://fakebank.com -w wordlist.txt dir

In the command above, -u is used to state the website we're scanning, -w takes a list of words to iterate through to find hidden pages.

You will see that GoBuster scans the website with each word in the list, finding pages that exist on the site. GoBuster will have told you the pages it found in the list of page/directory names (indicated by Status: 200).

Gobuster is a tool used to brute-force: URIs (directories and files) in web sites, DNS subdomains (with wildcard support), Virtual Host names on target web servers, Open Amazon S3 buckets, Open Google Cloud buckets and TFTP servers.

Intro To Offensive Security

A wordlist may contain thousands of words to search through in the .txt file.

Finding Secret Pages:

Intro To Offensive Security

At this point you will be shown what unprotected pages are vulnerable.

Using TryHackMe's example, with the use of GoBuster and terminal we found a secret bank transfer page that allows us to transfer money between accounts at the bank (/bank-transfer).

Type the hidden page into the FakeBank website in the browser.

http://fakebank.com/bank-transfer

From here we were able to enter account details and transfer funds from one bank account to another.

Mission Complete:

Intro To Offensive Security

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published