TryHackMe - TakeOver (Easy) - Live Walkthrough

preview_player
Показать описание

0:00 - Introduction
0:20 - Starting TakeOver.
4:00 - Discovering a virtual host on the web server.
7:09 - Attempting some enumeration of the discovered hostname, getting connection issues.
8:22 - Discovering another virtual host, killing a few processes.
11:53 - Trying to bypass the internal VPN access restriction.
18:53 - Looking in the SSL certificate, finding nothing.
24:19 - Nmap scanning the top 20 UDP ports to see if there is a VPN.
28:54 - Stumbling on the blog subdomain, realizing that ffuf wasn't working properly.
33:41 - "Debugging" ffuf using Burp, realizing the issue was SNI!
39:36 - Trying virtual host enumeration with gobuster, encountering the same issues.
41:38 - Enumerating the blog site.
44:59 - Explaining the difference between subdomains and virtual hosts.
47:58 - Resuming enumeration, not finding anything.
51:02 - Finding the "support" subdomain, extracting another domain from the SSL cert.
53:27 - Finding the flag in a redirect message from the new domain!
54:42 - Outro

Рекомендации по теме