DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Hidden Deep Into my Heart - TryHackMe writeup

Find what's hidden deep inside this website.

EasyWeb2 min read

Open the room on TryHackMe ↗ View on GitHub

Introduction

In this room, I performed basic web enumeration against a web application. A quick look at robots.txt revealed a hidden directory and a useful clue that ultimately led to the administrator panel and the flag.

Initial Access

I started the room by opening the provided web application URL.

image

Since the target web address was already provided, I navigated to the website and began my enumeration.

image

The page loaded successfully, but nothing immediately stood out. I also reviewed the page source and did not find anything useful there.

Web Enumeration

With no obvious clues on the homepage, I moved on to directory enumeration.

image

During the enumeration process, I discovered a robots.txt file and decided to inspect it.

Visiting:

https://<ip>:5000/robots.txt

image

The file revealed two interesting findings.

The first was a disallowed path:

/cupids_secret_vault/*

The wildcard suggested that additional directories or files might exist under that location.

The second finding was the string:

cupid_arrow_2026!!!

At this stage, it looked like it could potentially be a password or some other useful credential.

I then visited the discovered directory:

https://<ip>:5000/cupids_secret_vault/

image

The page itself did not reveal much information, so I continued enumerating directories within the discovered path.

image

This led me to an administrator login page.

image

Based on the value found in robots.txt, I decided to test the following credentials:

The login was successful, and I was immediately presented with the room flag.

image

Flags

THM{l0v3_is_in_th3_r0b0ts_txt}
image

Conclusion

This was a short but interesting challenge that reinforced the value of checking files like robots.txt during web reconnaissance.

Thanks for reading. If you enjoyed this walkthrough, feel free to check out my other TryHackMe writeups and cybersecurity content: