TryHackMe 5 Minute Hacks - Neighbour Writeup
Abstract
This is yet another very simple challenge, judging by the its instructions. It is basically a binary analysis challenge, but you can solve it using different methods such as our old friend Bruteforce.
The Challenge - Compiled
![]() | Level: Easy Time: 4 min Type: IDOR Requirements: - Basics of Insecure Direct Object Reference (IDOR) - Basic HTML code analysis Resources Used: - Kali Linux (VM) - Browser |
|---|
Walkthrough
The challenge provides the following instructions:
Check out our new cloud service, Authentication Anywhere -- log in from anywhere you would like! Users can enter their username and password, for a totally secure login process! You definitely wouldn't be able to find any secrets that other people have in their profile, right?
Check out similar content on TryHackMe:
- IDOR
Let’s start with our old friend “nmap”
nmap -sC -sV 10.128.146.172
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-03 19:14 -0400
Nmap scan report for 10.128.146.172
Host is up (0.031s latency).
Not shown: 998 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 81:91:6b:cc:7a:9d:ff:cf:1c:3f:61:9e:5a:20:9c:e8 (RSA)
| 256 2c:a5:18:19:6e:fc:c9:ef:9a:d3:43:51:72:39:1d:1e (ECDSA)
|_ 256 3e:06:3e:af:96:65:15:e8:f5:ce:25:6b:cd:43:88:b0 (ED25519)
80/tcp open http Apache httpd 2.4.53 ((Debian))
|_http-server-header: Apache/2.4.53 (Debian)
|_http-title: Login
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.57 seconds
Two services were identified, 22/TCP (SSH) and 80/TCP (HTTP). We can immediatelly see it works with an Apache/2.4.53 (Debian) and is also running some sort of PHP site.
After opening it in our browser, the site shows a simple authentication form.

Notice that the observation asks to use a guest account (found inside the HTML code) in case we don’t have one. Hitting CTRL+U, I found the guest account credentials in a comment at the end of the code:
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Login</title>
<link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.5.2/css/bootstrap.min.css">
<style>
body{ font: 14px sans-serif; }
.wrapper{ width: 360px; padding: 20px; margin: 0 auto; }
</style>
</head>
<body>
<div class="wrapper">
<h2>Login</h2>
<p>Please fill in your credentials to login.</p>
<form action="/index.php" method="post">
<div class="form-group">
<label>Username</label>
<input type="text" name="username" class="form-control " value="">
<span class="invalid-feedback"></span>
</div>
<div class="form-group">
<label>Password</label>
<input type="password" name="password" class="form-control ">
<span class="invalid-feedback"></span>
</div>
<div class="form-group">
<input type="submit" class="btn btn-primary" value="Login">
</div>
<p>Don't have an account? Use the guest account! (<code>Ctrl+U</code>)</p>
<!-- use guest:guest credentials until registration is fixed. "admin" user account is off limits!!!!! -->
</form>
</div>
</body>
</html>
Once signing with “guest:guest¨, we have the following:

Inspecting the code shows nothing out of the ordinary for the “guest” user.
Notice that on the browser URL there is a “user=guest” parameter. Do you remember the challenge description?
You definitely wouldn't be able to find any secrets that other people have in their profile, right?
So, after trying a few attempts with different users such as root, admin, etc, we found our flag:
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Welcome</title>
<!-- admin account could be vulnerable, need to update -->
<link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.5.2/css/bootstrap.min.css">
<style>
body{ font: 14px sans-serif; text-align: center; }
</style>
</head>
<body>
<h1 class="my-5">Hi, <b>admin</b>. Welcome to your site. The flag is: flag{REDACTED}</h1>
<p>
<a href="logout.php" class="btn btn-danger ml-3">Sign Out of Your Account</a>
</p>
</body>
</html>
I hope you enjoyed this simple yet fun challenge.
Related Posts
- [TryHackMe 5 Min Challenges](/blog/Writeups/challenges
