DEATHESTHER
← All write-ups

TRYHACKME WRITE-UP

Web Application Security - TryHackMe writeup

Learn about web applications and explore some of their common security issues.

EasyWeb1 min read

Open the room on TryHackMe ↗ View on GitHub

Task 1. Introduction

What do you need to access a web application?

Browser

Task 2. Web Application Security Risks

You discovered that the login page allows an unlimited number of login attempts without trying to slow down the user or lock the account. What is the category of this security risk? Identification and Authentication Failure.You noticed that the username and password are sent in cleartext without encryption. What is the category of this security risk?

Cryptographic Failures

Task 3

Practical Example of Web Application Security Check the other users to discover which user account was used to make the malicious changes and revert them. After reverting the changes, what is the flag that you have received?

THM{IDOR_EXPLORED}