Member-only story

Lo-Fi: TryHackMe Writeup.

Ansul Kotadia
T3CH
Published in
3 min readJan 17, 2025
Lo-Fi THM

Tackling the Lo-Fi TryHackMe room turned out to be a fascinating adventure! With a mix of curiosity and determination, I jumped right into it, and what followed was an enjoyable learning experience plus a little bit of brute forcing the directory! Follow the steps below to reach to the flag!!!!

Step 1: The Foundation — Scouting the Terrain:

As always the very first step to any challenge is the very well known reconnaissance phase using Nmap. As seen in the below image we get two open ports: 22 for ssh and 80 for http.

Step 2: Peeling Back the Layers:

Opening the web application in my browser, I began analyzing its structure. The source code hinted at a potential Local File Inclusion (LFI) vulnerability, and I decided to test it out.

How to Perform an LFI Attack

1. Inputs: Look for parameters in the URL or form fields that load files, such as ?page= or ?file=.
2

Create an account to read the full story.

The author made this story available to Medium members only.
If you’re new to Medium, create a new account to read this story on us.

Or, continue in mobile web

Already have an account? Sign in

T3CH
T3CH

Published in T3CH

Snoop & Learn about Technology, AI, Hacking, Coding, Software, News, Tools, Leaks, Bug Bounty, OSINT & Cybersecurity !¡! But, not limited 2, anything that is Tech Linked…You’ll probably find here ! ;) — Stay ahead with Latest Tech News! -> You write about? Just ping to join !

No responses yet

Write a response