TryHackMe: [Day 1] Web Exploitation Save The Gifts

Mac Leo
2 min readMar 17, 2022

--

  1. After finding Santa’s account, what is their position in the company?

ANS: The Boss!

EXPLANATION:

Step 1: Once on the website, Go to Your Activity. You will notice user_id=11 in the URL.

Step 2: Try to change the user_id=1 because usually id 1 indicates admin level.

Step 3: Once change the id to 1, you will see the Santa`s Position.

2. After finding McStocker’s account, what is their position in the company?

ANS: Build Manager

EXPLANATION:

Step 1: Follow the same steps as in Question 1 but change the user_id=3

3. After finding the account responsible for tampering, what is their position in the company?

ANS: Mischief Manager

EXPLANATION:

Step 1: Follow the same steps as in Question 1 but change the user_id=9

4. What is the received flag when McSkidy fixes the Inventory Management System?

ANS: THM{AOC_IDOR_2B34BHI3}

EXPLANATION:

Step 1: Once you find Grinch`s Profile in Your Activity ( Question 3), Revert all the Action. Then you will get, the Flag.

*****************THANK YOU****KEEP LEARNING ******************

HOPE YOU GUYS, THIS WALKTHROUGH MIGHT HELP YOU,FOLLOW MY PROFILE FOR MORE WRITE-UPS

*******PEACE*****

--

--

Mac Leo

Hacker |Cybersecurity Researcher | CTF Player |Cybersecurity Enthusiast