TryHackMe 5 Minute Hacks - TakeOver Writeup
Abstract
This is yet another very simple challenge, judging by the its instructions. It is a subdomain enumeration challenge.
The Challenge - Compiled
![]() | Level: Easy Time: 5 min Type: Web Requirements: - Basics of file/directory and subdomain enumeration. Resources Used: - Kali Linux (VM) - gobuster - nikto - SecLists Github Repo |
|---|
Walkthrough
The challenge provides the following instructions:
I am the CEO and one of the co-founders of futurevera.thm. In Futurevera, we believe that the future is in space. We do a lot of space research and write blogs about it. We used to help students with space questions, but we are rebuilding our support.
Hint: Don't forget to add the MACHINE_IP in /etc/hosts for futurevera.thm ; )
Recently blackhat hackers approached us saying they could takeover and are asking us for a big ransom. Please help us to find what they can takeover.
Our website is located at https://futurevera.thm
As mentioned in the last line of the goal, after configuring our “/etc/hosts” with the futurevera.thm domain with the IP given by the challenge, we can start scanning its services using “nmap”:
nmap -sC -sV futurevera.thm
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-03 22:00 -0400
Nmap scan report for futurevera.thm (10.129.165.111)
Host is up (0.031s latency).
Not shown: 997 closed tcp ports (reset)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 26:41:3a:52:61:90:6e:30:8d:4e:84:cc:da:5e:f6:ef (RSA)
| 256 74:5a:01:19:c7:1a:5b:5a:63:25:5e:e4:f0:b1:d0:35 (ECDSA)
|_ 256 37:7a:fa:b5:4c:66:1e:6c:f7:a0:47:cc:ff:cb:4a:27 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Did not follow redirect to https://futurevera.thm/
443/tcp open ssl/http Apache httpd 2.4.41
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: FutureVera
| ssl-cert: Subject: commonName=futurevera.thm/organizationName=Futurevera/stateOrProvinceName=Oregon/countryName=US
| Not valid before: 2022-03-13T10:05:19
|_Not valid after: 2023-03-13T10:05:19
|_ssl-date: TLS randomness does not represent time
| tls-alpn:
|_ http/1.1
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 30.25 seconds
There are 3 services in place, 22/TCP (SSH), 80/TCP (HTTP) and 443/TCP (HTTPS).
Let’s run “nikto” to scan our website for vulnerabilities, and see what we can find:
nikto -h https://futurevera.thm
- Nikto v2.6.1
---------------------------------------------------------------------------
+ Target IP: 10.129.165.111
+ Target Hostname: futurevera.thm
+ Target Port: 443
---------------------------------------------------------------------------
+ SSL Info: Subject: /C=US/ST=Oregon/L=Portland/O=Futurevera/OU=Thm/CN=futurevera.thm
CN: futurevera.thm
Ciphers: TLS_AES_256_GCM_SHA384
Issuer: /C=US/ST=Oregon/L=Portland/O=Futurevera/OU=Thm/CN=futurevera.thm
+ Platform: Unknown
+ Start Time: 2026-10-03 22:05:17 (GMT-4)
---------------------------------------------------------------------------
+ Server: Apache/2.4.41 (Ubuntu)
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [999990] OPTIONS: Allowed HTTP Methods: OPTIONS, HEAD, GET, POST .
+ [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
+ [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
+ [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
+ [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
+ [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
+ [600050] Apache/2.4.41 appears to be outdated (current is at least 2.4.68).
+ [750500] /css/: Directory indexing found. See: CWE-548
+ [001631] /css/: This might be interesting.
+ [007342] /: X-Frame-Options header is deprecated and was replaced with the Content-Security-Policy HTTP header with the frame-ancestors directive. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options
+ [007352] /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ 8127 requests: 0 errors and 11 items reported on the remote host
+ End Time: 2026-10-03 22:09:56 (GMT-4) (279 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested
OK, there is not much going on with the website in terms of vulnerabilities. Inspecting the website we have this:
Inspecting the code with CTRL+U revealed nothing useful in terms of sensitive information, comments, etc. The website certificate also showed no useful information.
Let’s try to enumerate files and directories of the website with gobuster to see if we can find anything useful. I’m using a common kali enumeration list:
gobuster dir -u https://futurevera.thm -w /usr/share/wordlists/dirb/common.txt -k
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: https://futurevera.thm
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/wordlists/dirb/common.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.8.2
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
.hta (Status: 403) [Size: 280]
.htaccess (Status: 403) [Size: 280]
.htpasswd (Status: 403) [Size: 280]
assets (Status: 301) [Size: 319] [--> https://futurevera.thm/assets/]
css (Status: 301) [Size: 316] [--> https://futurevera.thm/css/]
index.html (Status: 200) [Size: 4605]
js (Status: 301) [Size: 315] [--> https://futurevera.thm/js/]
server-status (Status: 403) [Size: 280]
Progress: 4613 / 4613 (100.00%)
===============================================================
Finished
===============================================================
The initial 3 files can’t be accessed, and none of the other files and directories proved to contain anything usefull.
As the challenge is all about take over, let’s start performing some subdomain enumeration to see if we can find more actionable information.
Let’s first clone SecLists github repository to assist us:
git clone https://github.com/danielmiessler/seclists
I’ll keep using gobuster for this operation, along with SecLists enumeration wordlist.
gobuster vhost -vv -k --append-domain -u https://futurevera.thm -w seclists/Discovery/Web-Content/common.txt -o output
Inspecting our “output” file we can see it found several entries:
cat output | grep -i -v "missed"
Found: .git/HEAD.futurevera.thm Status: 400 [Size: 307]
Found: .git/config.futurevera.thm Status: 400 [Size: 307]
Found: .git/logs/.futurevera.thm Status: 400 [Size: 307]
Found: .git/index.futurevera.thm Status: 400 [Size: 307]
Found: .svn/entries.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/acme-challenge.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/apple-app-site-association.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/apple-developer-merchantid-domain-association.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ashrae.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/assetlinks.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/browserid.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/autoconfig/mail.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/carddav.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/coap.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/caldav.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/core.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/change-password.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dnt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dnt-policy.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/csvm.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dots.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ecips.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/enterprise-transport-security.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/genid.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/hoba.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/est.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/host-meta.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/http-opportunistic.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/host-meta.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/idp-proxy.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/jwks.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/jmap.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/keybase.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/matrix.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mercure.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/looking-glass.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mta-sts.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ni.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mud.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/nfv-oauth-server-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/oauth-authorization-server.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/nodeinfo.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openid-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openid-federation.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openpgpkey.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openorg.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/pki-validation.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/reload-config.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/pvd.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/posh.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/resourcesync.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/repute-template.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/security.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ssf-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/stun-key.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/thread.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/humans.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/timezone.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/uma2-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/time.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/webfinger.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/void.futurevera.thm Status: 400 [Size: 307]
Found: @.futurevera.thm Status: 400 [Size: 307]
Found: Blog.futurevera.thm Status: 421 [Size: 408]
Found: CVS/Repository.futurevera.thm Status: 400 [Size: 307]
Found: CVS/Entries.futurevera.thm Status: 400 [Size: 307]
Found: CVS/Root.futurevera.thm Status: 400 [Size: 307]
Found: Documents and Settings.futurevera.thm Status: 400 [Size: 307]
Found: Program Files.futurevera.thm Status: 400 [Size: 307]
Found: Shibboleth.sso/Metadata.futurevera.thm Status: 400 [Size: 307]
Found: Support.futurevera.thm Status: 421 [Size: 411]
Found: _framework/blazor.boot.json.futurevera.thm Status: 400 [Size: 307]
Found: _framework/blazor.webassembly.js.futurevera.thm Status: 400 [Size: 307]
Found: _framework/wasm/dotnet.wasm.futurevera.thm Status: 400 [Size: 307]
Found: _framework/_bin/WebAssembly.Bindings.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/_vti_adm/admin.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/_vti_aut/author.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/shtml.dll.futurevera.thm Status: 400 [Size: 307]
Found: android/config.futurevera.thm Status: 400 [Size: 307]
Found: api/experiments.futurevera.thm Status: 400 [Size: 307]
Found: api/experiments/configurations.futurevera.thm Status: 400 [Size: 307]
Found: blog.futurevera.thm Status: 421 [Size: 408]
Found: cgi-bin/.futurevera.thm Status: 400 [Size: 307]
Found: federation/clients.futurevera.thm Status: 400 [Size: 307]
Found: health/live.futurevera.thm Status: 400 [Size: 307]
Found: health/ready.futurevera.thm Status: 400 [Size: 307]
Found: ios/config.futurevera.thm Status: 400 [Size: 307]
Found: lost+found.futurevera.thm Status: 400 [Size: 307]
Found: mfa/challenge.futurevera.thm Status: 400 [Size: 307]
Found: node_modules/.package-lock.json.futurevera.thm Status: 400 [Size: 307]
Found: oauth/authorize.futurevera.thm Status: 400 [Size: 307]
Found: oauth/device/code.futurevera.thm Status: 400 [Size: 307]
Found: oauth/revoke.futurevera.thm Status: 400 [Size: 307]
Found: oauth/token.futurevera.thm Status: 400 [Size: 307]
Found: oauth/token/info.futurevera.thm Status: 400 [Size: 307]
Found: oidc/register.futurevera.thm Status: 400 [Size: 307]
Found: render/https://www.google.com.futurevera.thm Status: 400 [Size: 307]
Found: render?url=https://www.google.com.futurevera.thm Status: 400 [Size: 307]
Found: reports list.futurevera.thm Status: 400 [Size: 307]
Found: servlet/GetProductVersion.futurevera.thm Status: 400 [Size: 307]
Found: status/ready.futurevera.thm Status: 400 [Size: 307]
Found: support.futurevera.thm Status: 421 [Size: 411]
Found: token/introspect.futurevera.thm Status: 400 [Size: 307]
Found: token/revoke.futurevera.thm Status: 400 [Size: 307]
Found: v1/client_configs.futurevera.thm Status: 400 [Size: 307]
Found: v2/client_configs.futurevera.thm Status: 400 [Size: 307]
Found: ~adm.futurevera.thm Status: 400 [Size: 307]
Found: ~admin.futurevera.thm Status: 400 [Size: 307]
Found: ~administrator.futurevera.thm Status: 400 [Size: 307]
Found: ~amanda.futurevera.thm Status: 400 [Size: 307]
Found: ~apache.futurevera.thm Status: 400 [Size: 307]
Found: ~bin.futurevera.thm Status: 400 [Size: 307]
Found: ~ftp.futurevera.thm Status: 400 [Size: 307]
Found: ~guest.futurevera.thm Status: 400 [Size: 307]
Found: ~httpd.futurevera.thm Status: 400 [Size: 307]
Found: ~http.futurevera.thm Status: 400 [Size: 307]
Found: ~log.futurevera.thm Status: 400 [Size: 307]
Found: ~logs.futurevera.thm Status: 400 [Size: 307]
Found: ~lp.futurevera.thm Status: 400 [Size: 307]
Found: ~mail.futurevera.thm Status: 400 [Size: 307]
Found: ~nobody.futurevera.thm Status: 400 [Size: 307]
Found: ~operator.futurevera.thm Status: 400 [Size: 307]
Found: ~root.futurevera.thm Status: 400 [Size: 307]
Found: ~sys.futurevera.thm Status: 400 [Size: 307]
Found: ~sysadmin.futurevera.thm Status: 400 [Size: 307]
Found: ~sysadm.futurevera.thm Status: 400 [Size: 307]
Found: ~test.futurevera.thm Status: 400 [Size: 307]
Found: ~www.futurevera.thm Status: 400 [Size: 307]
Found: ~webmaster.futurevera.thm Status: 400 [Size: 307]
Found: ~user.futurevera.thm Status: 400 [Size: 307]
Found: dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB.futurevera.thm Status: 400 [Size: 307]
Found: ~tmp.futurevera.thm Status: 400 [Size: 307]
Found: dns-query?name=google.com&type=A.futurevera.thm Status: 400 [Size: 307]
Found: mcp/transport.futurevera.thm Status: 400 [Size: 307]
Found: mcp/message.futurevera.thm Status: 400 [Size: 307]
The ones who have HTTP Status code 421 are:
Found: Blog.futurevera.thm Status: 421 [Size: 408]
Found: Support.futurevera.thm Status: 421 [Size: 411]
Found: blog.futurevera.thm Status: 421 [Size: 408]
Found: support.futurevera.thm Status: 421 [Size: 411]
OK, I’ve included entries for all of these in our /etc/hosts file:
# TryHackMe
10.129.165.111 *.futurevera.thm
10.129.165.111 futurevera.thm
10.129.165.111 Blog.futurevera.thm
10.129.165.111 blog.futurevera.thm
10.129.165.111 Support.futurevera.thm
10.129.165.111 support.futurevera.thm
After inspecting all of the entries in the browser and also their certificates. Both, blog and support have a website.
Inspecting the “support.futurevera.thm” site and certificate we find a new subdomain entry:

After creating an entry for this subdomain in our /etc/hosts and accessing this sudomain in the browser, we find another website, that looks just like the initial one.
When trying to access this website through HTTP, we have our flag.

Related Posts
- [TryHackMe 5 Min Challenges](/blog/Writeups/challenges
