Introduction
This writeup covers the Neighbour room on TryHackMe, a beginner-level web challenge focused on insecure direct object references (IDOR). The lab is short, practical, and highlights how simple authorization flaws can lead to unintended data exposure.
- Room link: https://tryhackme.com/room/neighbour
Initial Reconnaissance
Even though this is an IDOR-focused room, I started with a quick Nmap scan to check exposed services.
~$ nmap -sV 10.49.151.21
The scan completed cleanly and confirmed that the host was reachable. Only two TCP ports were open.
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5
80/tcp open http Apache httpd 2.4.53
SSH was open, but the web service on port 80 was clearly the main attack surface.
Web Exploitation
I navigated to the web application running on port 80 and was presented with a simple login interface.
At first glance, the page looked intentionally minimal. One detail stood out immediately: a message below the login form referencing a guest account, along with a hint to inspect the page source (Ctrl+U) .
Opening the source code revealed a commented line that hadn’t been removed during development:
<!-- use guest:guest credentials until registration is fixed. "admin" user account is off limits!!!!! -->
That single comment explained the next step without needing any guesswork. I logged in using the provided guest credentials.
Once authenticated, I was redirected to a profile page associated with the guest user.
Capturing the Flag
While reviewing the page, I noticed the structure of the URL in the address bar:
http://10.49.151.21/profile.php?user=guest
The application was directly referencing the username as a request parameter. I modified the value of the user parameter in the URL and loaded the page again.
The response changed immediately, and the protected content became visible. The flag was displayed directly on the page.
flag{66be95c478473d91a5358f2440c7af1f}
For more TryHackMe labs and walkthroughs, check out my Medium profile: https://deathesther.medium.com/