Introduction
In this room, I performed basic web enumeration against a web application. A quick look at robots.txt revealed a hidden directory and a useful clue that ultimately led to the administrator panel and the flag.
Initial Access
I started the room by opening the provided web application URL.
Since the target web address was already provided, I navigated to the website and began my enumeration.
The page loaded successfully, but nothing immediately stood out. I also reviewed the page source and did not find anything useful there.
Web Enumeration
With no obvious clues on the homepage, I moved on to directory enumeration.
During the enumeration process, I discovered a robots.txt file and decided to inspect it.
Visiting:
https://<ip>:5000/robots.txt
The file revealed two interesting findings.
The first was a disallowed path:
/cupids_secret_vault/*
The wildcard suggested that additional directories or files might exist under that location.
The second finding was the string:
cupid_arrow_2026!!!
At this stage, it looked like it could potentially be a password or some other useful credential.
I then visited the discovered directory:
https://<ip>:5000/cupids_secret_vault/
The page itself did not reveal much information, so I continued enumerating directories within the discovered path.
This led me to an administrator login page.
Based on the value found in robots.txt, I decided to test the following credentials:
- Username:
admin - Password:
cupid_arrow_2026!!!
The login was successful, and I was immediately presented with the room flag.
Flags
THM{l0v3_is_in_th3_r0b0ts_txt}
Conclusion
This was a short but interesting challenge that reinforced the value of checking files like robots.txt during web reconnaissance.
Thanks for reading. If you enjoyed this walkthrough, feel free to check out my other TryHackMe writeups and cybersecurity content: