◄ BACKPOST2026-10-04

TryHackMe 5 Minute Hacks - Neighbour Writeup

tryhackmethmchallengectfneighbourwriteuphackingidor

Abstract

This is yet another very simple challenge, judging by the its instructions. It is basically a binary analysis challenge, but you can solve it using different methods such as our old friend Bruteforce.

The Challenge - Compiled

thn-neighbourLevel: Easy
Time: 4 min
Type: IDOR
Requirements:
- Basics of Insecure Direct Object Reference (IDOR)
- Basic HTML code analysis
Resources Used:
- Kali Linux (VM)
- Browser

Walkthrough

The challenge provides the following instructions:

Check out our new cloud service, Authentication Anywhere -- log in from anywhere you would like! Users can enter their username and password, for a totally secure login process! You definitely wouldn't be able to find any secrets that other people have in their profile, right?

Check out similar content on TryHackMe:
- IDOR

Let’s start with our old friend “nmap”

nmap -sC -sV 10.128.146.172
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-03 19:14 -0400
Nmap scan report for 10.128.146.172
Host is up (0.031s latency).
Not shown: 998 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 81:91:6b:cc:7a:9d:ff:cf:1c:3f:61:9e:5a:20:9c:e8 (RSA)
|   256 2c:a5:18:19:6e:fc:c9:ef:9a:d3:43:51:72:39:1d:1e (ECDSA)
|_  256 3e:06:3e:af:96:65:15:e8:f5:ce:25:6b:cd:43:88:b0 (ED25519)
80/tcp open  http    Apache httpd 2.4.53 ((Debian))
|_http-server-header: Apache/2.4.53 (Debian)
|_http-title: Login
| http-cookie-flags: 
|   /: 
|     PHPSESSID: 
|_      httponly flag not set
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 8.57 seconds

Two services were identified, 22/TCP (SSH) and 80/TCP (HTTP). We can immediatelly see it works with an Apache/2.4.53 (Debian) and is also running some sort of PHP site.

After opening it in our browser, the site shows a simple authentication form.

thm-n01

Notice that the observation asks to use a guest account (found inside the HTML code) in case we don’t have one. Hitting CTRL+U, I found the guest account credentials in a comment at the end of the code:

 
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>Login</title>
    <link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.5.2/css/bootstrap.min.css">
    <style>
        body{ font: 14px sans-serif; }
        .wrapper{ width: 360px; padding: 20px; margin: 0 auto; }
    </style>
</head>
<body>
    <div class="wrapper">
        <h2>Login</h2>
        <p>Please fill in your credentials to login.</p>

        
        <form action="/index.php" method="post">
            <div class="form-group">
                <label>Username</label>
                <input type="text" name="username" class="form-control " value="">
                <span class="invalid-feedback"></span>
            </div>    
            <div class="form-group">
                <label>Password</label>
                <input type="password" name="password" class="form-control ">
                <span class="invalid-feedback"></span>
            </div>
            <div class="form-group">
                <input type="submit" class="btn btn-primary" value="Login">
            </div>
            <p>Don't have an account? Use the guest account! (<code>Ctrl+U</code>)</p>
            <!-- use guest:guest credentials until registration is fixed. "admin" user account is off limits!!!!! -->
        </form>
    </div>
</body>
</html>

Once signing with “guest:guest¨, we have the following:

thm-n02

Inspecting the code shows nothing out of the ordinary for the “guest” user.

Notice that on the browser URL there is a “user=guest” parameter. Do you remember the challenge description?

You definitely wouldn't be able to find any secrets that other people have in their profile, right?

So, after trying a few attempts with different users such as root, admin, etc, we found our flag:


<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>Welcome</title>
    <!-- admin account could be vulnerable, need to update -->
    <link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.5.2/css/bootstrap.min.css">
    <style>
        body{ font: 14px sans-serif; text-align: center; }
    </style>
</head>
<body>
    <h1 class="my-5">Hi, <b>admin</b>. Welcome to your site. The flag is: flag{REDACTED}</h1>
    <p>
        <a href="logout.php" class="btn btn-danger ml-3">Sign Out of Your Account</a>
    </p>
</body>
</html>

I hope you enjoyed this simple yet fun challenge.

Related Posts