DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Neighbour - TryHackMe writeup

Check out our new cloud service, Authentication Anywhere. Can you find other user's secrets?

EasyWebIDOR3 min read

Open the room on TryHackMe ↗ View on GitHub

Introduction

This writeup covers the Neighbour room on TryHackMe, a beginner-level web challenge focused on insecure direct object references (IDOR). The lab is short, practical, and highlights how simple authorization flaws can lead to unintended data exposure.

Initial Reconnaissance

Even though this is an IDOR-focused room, I started with a quick Nmap scan to check exposed services.

~$ nmap -sV 10.49.151.21

The scan completed cleanly and confirmed that the host was reachable. Only two TCP ports were open.

PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.5
80/tcp open  http    Apache httpd 2.4.53

SSH was open, but the web service on port 80 was clearly the main attack surface.

Web Exploitation

I navigated to the web application running on port 80 and was presented with a simple login interface.

login

At first glance, the page looked intentionally minimal. One detail stood out immediately: a message below the login form referencing a guest account, along with a hint to inspect the page source (Ctrl+U) .

Opening the source code revealed a commented line that hadn’t been removed during development:

source code
<!-- use guest:guest credentials until registration is fixed. "admin" user account is off limits!!!!! -->

That single comment explained the next step without needing any guesswork. I logged in using the provided guest credentials.

logend

Once authenticated, I was redirected to a profile page associated with the guest user.

Capturing the Flag

While reviewing the page, I noticed the structure of the URL in the address bar:

http://10.49.151.21/profile.php?user=guest

The application was directly referencing the username as a request parameter. I modified the value of the user parameter in the URL and loaded the page again.

The response changed immediately, and the protected content became visible. The flag was displayed directly on the page.

flag
flag{66be95c478473d91a5358f2440c7af1f}
image

For more TryHackMe labs and walkthroughs, check out my Medium profile: https://deathesther.medium.com/