◄ BACKPOST2026-10-05

TryHackMe 5 Minute Hacks - TakeOver Writeup

thmtryhackmechallengectfenumerationhackersbountygobusternikto

Abstract

This is yet another very simple challenge, judging by the its instructions. It is a subdomain enumeration challenge.

The Challenge - Compiled

thm-takevoerLevel: Easy
Time: 5 min
Type: Web
Requirements:
- Basics of file/directory and subdomain enumeration.
Resources Used:
- Kali Linux (VM)
- gobuster
- nikto
- SecLists Github Repo

Walkthrough

The challenge provides the following instructions:

I am the CEO and one of the co-founders of futurevera.thm. In Futurevera, we believe that the future is in space. We do a lot of space research and write blogs about it. We used to help students with space questions, but we are rebuilding our support.  

Hint: Don't forget to add the MACHINE_IP in /etc/hosts for futurevera.thm ; )

Recently blackhat hackers approached us saying they could takeover and are asking us for a big ransom. Please help us to find what they can takeover.  
  
Our website is located at https://futurevera.thm

As mentioned in the last line of the goal, after configuring our “/etc/hosts” with the futurevera.thm domain with the IP given by the challenge, we can start scanning its services using “nmap”:

nmap -sC -sV futurevera.thm
Starting Nmap 7.99 ( https://nmap.org ) at 2026-10-03 22:00 -0400
Nmap scan report for futurevera.thm (10.129.165.111)
Host is up (0.031s latency).
Not shown: 997 closed tcp ports (reset)
PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   3072 26:41:3a:52:61:90:6e:30:8d:4e:84:cc:da:5e:f6:ef (RSA)
|   256 74:5a:01:19:c7:1a:5b:5a:63:25:5e:e4:f0:b1:d0:35 (ECDSA)
|_  256 37:7a:fa:b5:4c:66:1e:6c:f7:a0:47:cc:ff:cb:4a:27 (ED25519)
80/tcp  open  http     Apache httpd 2.4.41 ((Ubuntu))
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: Did not follow redirect to https://futurevera.thm/
443/tcp open  ssl/http Apache httpd 2.4.41
|_http-server-header: Apache/2.4.41 (Ubuntu)
|_http-title: FutureVera
| ssl-cert: Subject: commonName=futurevera.thm/organizationName=Futurevera/stateOrProvinceName=Oregon/countryName=US
| Not valid before: 2022-03-13T10:05:19
|_Not valid after:  2023-03-13T10:05:19
|_ssl-date: TLS randomness does not represent time
| tls-alpn: 
|_  http/1.1
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 30.25 seconds

There are 3 services in place, 22/TCP (SSH), 80/TCP (HTTP) and 443/TCP (HTTPS).

Let’s run “nikto” to scan our website for vulnerabilities, and see what we can find:

nikto -h https://futurevera.thm
- Nikto v2.6.1
---------------------------------------------------------------------------
+ Target IP:          10.129.165.111
+ Target Hostname:    futurevera.thm
+ Target Port:        443
---------------------------------------------------------------------------
+ SSL Info:           Subject:  /C=US/ST=Oregon/L=Portland/O=Futurevera/OU=Thm/CN=futurevera.thm
                      CN:       futurevera.thm
                      Ciphers:  TLS_AES_256_GCM_SHA384
                      Issuer:   /C=US/ST=Oregon/L=Portland/O=Futurevera/OU=Thm/CN=futurevera.thm
+ Platform:           Unknown
+ Start Time:         2026-10-03 22:05:17 (GMT-4)
---------------------------------------------------------------------------
+ Server: Apache/2.4.41 (Ubuntu)
+ No CGI Directories found (use '-C all' to force check all possible dirs). CGI tests skipped.
+ [999990] OPTIONS: Allowed HTTP Methods: OPTIONS, HEAD, GET, POST .
+ [013587] /: Suggested security header missing: x-content-type-options. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options
+ [013587] /: Suggested security header missing: permissions-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
+ [013587] /: Suggested security header missing: strict-transport-security. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security
+ [013587] /: Suggested security header missing: content-security-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP
+ [013587] /: Suggested security header missing: referrer-policy. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy
+ [600050] Apache/2.4.41 appears to be outdated (current is at least 2.4.68).
+ [750500] /css/: Directory indexing found. See: CWE-548
+ [001631] /css/: This might be interesting.
+ [007342] /: X-Frame-Options header is deprecated and was replaced with the Content-Security-Policy HTTP header with the frame-ancestors directive. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/X-Frame-Options
+ [007352] /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/
+ 8127 requests: 0 errors and 11 items reported on the remote host
+ End Time:           2026-10-03 22:09:56 (GMT-4) (279 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested

OK, there is not much going on with the website in terms of vulnerabilities. Inspecting the website we have this:

thm-site01 Inspecting the code with CTRL+U revealed nothing useful in terms of sensitive information, comments, etc. The website certificate also showed no useful information.

Let’s try to enumerate files and directories of the website with gobuster to see if we can find anything useful. I’m using a common kali enumeration list:

gobuster dir -u https://futurevera.thm -w /usr/share/wordlists/dirb/common.txt -k
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     https://futurevera.thm
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/wordlists/dirb/common.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
.hta                 (Status: 403) [Size: 280]
.htaccess            (Status: 403) [Size: 280]
.htpasswd            (Status: 403) [Size: 280]
assets               (Status: 301) [Size: 319] [--> https://futurevera.thm/assets/]
css                  (Status: 301) [Size: 316] [--> https://futurevera.thm/css/]
index.html           (Status: 200) [Size: 4605]
js                   (Status: 301) [Size: 315] [--> https://futurevera.thm/js/]
server-status        (Status: 403) [Size: 280]
Progress: 4613 / 4613 (100.00%)
===============================================================
Finished
===============================================================

The initial 3 files can’t be accessed, and none of the other files and directories proved to contain anything usefull.

As the challenge is all about take over, let’s start performing some subdomain enumeration to see if we can find more actionable information.

Let’s first clone SecLists github repository to assist us:

git clone https://github.com/danielmiessler/seclists

I’ll keep using gobuster for this operation, along with SecLists enumeration wordlist.

gobuster vhost -vv -k --append-domain -u https://futurevera.thm -w seclists/Discovery/Web-Content/common.txt -o output

Inspecting our “output” file we can see it found several entries:

cat output | grep -i -v "missed"

Found: .git/HEAD.futurevera.thm Status: 400 [Size: 307]
Found: .git/config.futurevera.thm Status: 400 [Size: 307]
Found: .git/logs/.futurevera.thm Status: 400 [Size: 307]
Found: .git/index.futurevera.thm Status: 400 [Size: 307]
Found: .svn/entries.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/acme-challenge.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/apple-app-site-association.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/apple-developer-merchantid-domain-association.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ashrae.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/assetlinks.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/browserid.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/autoconfig/mail.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/carddav.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/coap.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/caldav.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/core.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/change-password.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dnt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dnt-policy.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/csvm.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/dots.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ecips.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/enterprise-transport-security.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/genid.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/hoba.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/est.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/host-meta.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/http-opportunistic.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/host-meta.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/idp-proxy.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/jwks.json.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/jmap.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/keybase.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/matrix.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mercure.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/looking-glass.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mta-sts.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ni.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/mud.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/nfv-oauth-server-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/oauth-authorization-server.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/nodeinfo.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openid-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openid-federation.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openpgpkey.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/openorg.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/pki-validation.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/reload-config.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/pvd.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/posh.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/resourcesync.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/repute-template.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/security.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/ssf-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/stun-key.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/thread.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/humans.txt.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/timezone.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/uma2-configuration.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/time.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/webfinger.futurevera.thm Status: 400 [Size: 307]
Found: .well-known/void.futurevera.thm Status: 400 [Size: 307]
Found: @.futurevera.thm Status: 400 [Size: 307]
Found: Blog.futurevera.thm Status: 421 [Size: 408]
Found: CVS/Repository.futurevera.thm Status: 400 [Size: 307]
Found: CVS/Entries.futurevera.thm Status: 400 [Size: 307]
Found: CVS/Root.futurevera.thm Status: 400 [Size: 307]
Found: Documents and Settings.futurevera.thm Status: 400 [Size: 307]
Found: Program Files.futurevera.thm Status: 400 [Size: 307]
Found: Shibboleth.sso/Metadata.futurevera.thm Status: 400 [Size: 307]
Found: Support.futurevera.thm Status: 421 [Size: 411]
Found: _framework/blazor.boot.json.futurevera.thm Status: 400 [Size: 307]
Found: _framework/blazor.webassembly.js.futurevera.thm Status: 400 [Size: 307]
Found: _framework/wasm/dotnet.wasm.futurevera.thm Status: 400 [Size: 307]
Found: _framework/_bin/WebAssembly.Bindings.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/_vti_adm/admin.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/_vti_aut/author.dll.futurevera.thm Status: 400 [Size: 307]
Found: _vti_bin/shtml.dll.futurevera.thm Status: 400 [Size: 307]
Found: android/config.futurevera.thm Status: 400 [Size: 307]
Found: api/experiments.futurevera.thm Status: 400 [Size: 307]
Found: api/experiments/configurations.futurevera.thm Status: 400 [Size: 307]
Found: blog.futurevera.thm Status: 421 [Size: 408]
Found: cgi-bin/.futurevera.thm Status: 400 [Size: 307]
Found: federation/clients.futurevera.thm Status: 400 [Size: 307]
Found: health/live.futurevera.thm Status: 400 [Size: 307]
Found: health/ready.futurevera.thm Status: 400 [Size: 307]
Found: ios/config.futurevera.thm Status: 400 [Size: 307]
Found: lost+found.futurevera.thm Status: 400 [Size: 307]
Found: mfa/challenge.futurevera.thm Status: 400 [Size: 307]
Found: node_modules/.package-lock.json.futurevera.thm Status: 400 [Size: 307]
Found: oauth/authorize.futurevera.thm Status: 400 [Size: 307]
Found: oauth/device/code.futurevera.thm Status: 400 [Size: 307]
Found: oauth/revoke.futurevera.thm Status: 400 [Size: 307]
Found: oauth/token.futurevera.thm Status: 400 [Size: 307]
Found: oauth/token/info.futurevera.thm Status: 400 [Size: 307]
Found: oidc/register.futurevera.thm Status: 400 [Size: 307]
Found: render/https://www.google.com.futurevera.thm Status: 400 [Size: 307]
Found: render?url=https://www.google.com.futurevera.thm Status: 400 [Size: 307]
Found: reports list.futurevera.thm Status: 400 [Size: 307]
Found: servlet/GetProductVersion.futurevera.thm Status: 400 [Size: 307]
Found: status/ready.futurevera.thm Status: 400 [Size: 307]
Found: support.futurevera.thm Status: 421 [Size: 411]
Found: token/introspect.futurevera.thm Status: 400 [Size: 307]
Found: token/revoke.futurevera.thm Status: 400 [Size: 307]
Found: v1/client_configs.futurevera.thm Status: 400 [Size: 307]
Found: v2/client_configs.futurevera.thm Status: 400 [Size: 307]
Found: ~adm.futurevera.thm Status: 400 [Size: 307]
Found: ~admin.futurevera.thm Status: 400 [Size: 307]
Found: ~administrator.futurevera.thm Status: 400 [Size: 307]
Found: ~amanda.futurevera.thm Status: 400 [Size: 307]
Found: ~apache.futurevera.thm Status: 400 [Size: 307]
Found: ~bin.futurevera.thm Status: 400 [Size: 307]
Found: ~ftp.futurevera.thm Status: 400 [Size: 307]
Found: ~guest.futurevera.thm Status: 400 [Size: 307]
Found: ~httpd.futurevera.thm Status: 400 [Size: 307]
Found: ~http.futurevera.thm Status: 400 [Size: 307]
Found: ~log.futurevera.thm Status: 400 [Size: 307]
Found: ~logs.futurevera.thm Status: 400 [Size: 307]
Found: ~lp.futurevera.thm Status: 400 [Size: 307]
Found: ~mail.futurevera.thm Status: 400 [Size: 307]
Found: ~nobody.futurevera.thm Status: 400 [Size: 307]
Found: ~operator.futurevera.thm Status: 400 [Size: 307]
Found: ~root.futurevera.thm Status: 400 [Size: 307]
Found: ~sys.futurevera.thm Status: 400 [Size: 307]
Found: ~sysadmin.futurevera.thm Status: 400 [Size: 307]
Found: ~sysadm.futurevera.thm Status: 400 [Size: 307]
Found: ~test.futurevera.thm Status: 400 [Size: 307]
Found: ~www.futurevera.thm Status: 400 [Size: 307]
Found: ~webmaster.futurevera.thm Status: 400 [Size: 307]
Found: ~user.futurevera.thm Status: 400 [Size: 307]
Found: dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB.futurevera.thm Status: 400 [Size: 307]
Found: ~tmp.futurevera.thm Status: 400 [Size: 307]
Found: dns-query?name=google.com&type=A.futurevera.thm Status: 400 [Size: 307]
Found: mcp/transport.futurevera.thm Status: 400 [Size: 307]
Found: mcp/message.futurevera.thm Status: 400 [Size: 307]

The ones who have HTTP Status code 421 are:

Found: Blog.futurevera.thm Status: 421 [Size: 408]
Found: Support.futurevera.thm Status: 421 [Size: 411]
Found: blog.futurevera.thm Status: 421 [Size: 408]
Found: support.futurevera.thm Status: 421 [Size: 411]

OK, I’ve included entries for all of these in our /etc/hosts file:

# TryHackMe
10.129.165.111  *.futurevera.thm
10.129.165.111  futurevera.thm
10.129.165.111  Blog.futurevera.thm
10.129.165.111  blog.futurevera.thm
10.129.165.111  Support.futurevera.thm
10.129.165.111  support.futurevera.thm

After inspecting all of the entries in the browser and also their certificates. Both, blog and support have a website.

Inspecting the “support.futurevera.thm” site and certificate we find a new subdomain entry:

thm-site03

After creating an entry for this subdomain in our /etc/hosts and accessing this sudomain in the browser, we find another website, that looks just like the initial one.

When trying to access this website through HTTP, we have our flag.

thm-site04

Related Posts