October 10, 2026
Article on Introduction to web Hacking a Tryhackme .
Module 1. Walking An application

By Prince Kumar
4 min read
NO Needed
Task 2. Exploring The Website
" Crawl the each page on the website that link inside the href "
Anser no needed
Task 3. Viewing the page source
"View the Source by putting view-source: on each page or if your browser support press ctrl+u "
Q. What is the flag from the html comment ?
Solution step
- view source page of lab host .
- go to the path/new-home-beta
- flag โ THM{HTML_COMMENTS_ARE_DANGEROUS
Q What is the flag from the secret link?
- Check for the secret page on the /
- request to secret link path
- THM{NOT_A_SECRET_ANYMORE}
Q. What is the directory listing flag?
-
visit the /assets path
-
THM{INVALID_DIRECTORY_PERMISSIONS}
Q What is the framework flag?
- check for the flag.txt
- THM{KEEP_YOUR_SOFTWARE_UPDATED}
Task 4. Developers Tool โ Inspector
"Edit & change web page on client side through inpector "
Q. What is the flag behind the paywall?
- go to /news & open the dev tool
- the 3 article is premium click on it and inpect the page
- div premium-customer-block click on it to see link css file ,
- change the display= block to display= none &
- THM{NOT_SO_HIDDEN}
Task 5 Developers tool โ Debugger
"Enable dev to run instruction step by step by creating the breakpoint"
- on the contact page something flash red quicly
- go to Dev tool & click on the debugger
- find the flash.min.js file & at the end you can see the flash remove somthing .
- make the breakpoint and reload the site to see the flag
- THM{CATCH_ME_IF_YOU_CAN}
Task 6 Developers tool โ Network
"Monitor the Network traffic "
Q What is the flag shown on the contact-msg network request?
- open the network tab on dev tool
- send the message on contact
- check for the Respose for the send request
- THM{GOT_AJAX_FLAG}
Module : Content Discovery
Task 1.
"content โ anything such as audi , video , image , backup etc .
but content discovery is addressing the detail of page like page for staff , older versioin of website , backup , configuration , administration panel etc "
"The method for content discovery manual , automated , osint '
Q task 1. Do it YourSelf
Task 2. manual discovery โ robots.txt
"robots.txt file basically configuration file for the search engine it tell the search engine which path can show or not ior ban specific search engine to show result "
Q What is the directory in the robots.txt that isn't allowed to be viewed by web crawlers?
- visit the website and /robots.txt
- /staff-portal
Task 3. Manual Discovery โ favicon
"favicon is small icon display in the browser or tab "
Q What framework did the favicon belong to?
- inpect the page https://static-labs.tryhackme.cloud/sites/favicon/
curl https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico | md5sum
f276b19aabcb4ae8cda4d22625c6735fcurl https://static-labs.tryhackme.cloud/sites/favicon/images/favicon.ico | md5sum
f276b19aabcb4ae8cda4d22625c6735fThen check find f276b19aabcb4ae8cda4d22625c6735f
on
https://wiki.owasp.org/index.php/OWASP_favicon_database.
- cgiirc
Task 4 . Manual discovery โ sitemap.xml
" more detailed version of robots.txt"
Q What is the path of the secret area that can be found in the sitemap.xml file?
- labadd/sitemap.xml
- /s3cr3t-area
Task 5 Manual Discovery โ Http Headers
"http header tell more detailed about the server like the server version , name which we can search it for vulnerability "
Q What is the flag value from the X-FLAG header?
- curl http://10.48.179.144 -v
- Read the header & you will able to find the flag
- THM{HEADER_FLAG}
Task 6 Manual Discovery โ Framework Stack
" check for website framework "
Q What is the flag from the framework's administration portal?
- visit https://static-labs.tryhackme.cloud/sites/thm-web-framework.
- check the documentation , find /thm-framework-login
- back to lab ip//thm-framework-login username admin password admin
- THM{CHANGE_DEFAULT_CREDENTIALS}
Task 7 OSINT Google hacking /Dorking
" Google Dorking is an advanced google search operator use for specific search" " use domain specific result use site:example.com , filetype:pdf for file , inurl:test search url that contain test , intitle: contain word in link "
Q What Google dork operator can be used to only show results from a particular site?
Do it Yourself
Task 8 OSINT โ wappalyzer
" A content discovery open source intelligence "
Q What online tool can be used to identify what technologies a website is running?
Do it Yourself
Task 9 OSINT โ Wayback machine
" wayback machine store previos or older version of page "
Q What is the website address for the Wayback Machine?
Do it Yourself
Task 10 OSINT โ Github
" Git is version control system and github which host the page which can public , private "
Q What is Git ?
Do it YourSelf
Task 11 . S3 Buckets
" S3 are a storage service provide by amazon aws.
Q What URL format do Amazon S3 buckets end in?
Do it Yourself
Task 12 Automated Discovery
"Automated discovery is the process of using tool to discover content "
" Their is lot of discovery tool like ffuf , dirb and gobuster you can use "
"for tool guidance use manual page "
Q What is the name of the directory beginning "/moโฆ." that was discovered?
/monthly
Q What is the name of the log file that was discovered?
/development.log
Module Subdomain Enumeration
Task 1. Brief
"subdomain enumerate using the brute force , osint , virtual host "
Do it yourself
Task 2 . ssl/tls certificate
" from here we can enumerate the subdomain when ssl/tls certificate created by CA , CA Take a part in what is called Certificate Transparency logs . which is publicaly available on https://cert.sh"
Q What domain was logged on crt.sh at 2020โ12โ26?
A store.tryhackme.com
Task 3 OSINT โ Search Engine
" You need learn google dorking, or every search engine offer advance search operator for advanced search . you have find them for google dork here it is "
site:"*.com" filetype:pdf "google dorking" | "google hacking" "
Q What is the TryHackMe subdomain beginning with S discovered using the above Google search?
A store.tryhackme.com
Task 4 DNS Bruteforce
"using bruteforce , to check the name in wordlist has subdomain on domain"
Q What is the first subdomain found with the dnsrecon tool?
A api.acmeitsupport.thm
Task 5 OSINT Sublist3r tool
Q What is the first subdomain discovered by sublist3r?
A web55.acmeitsupport.thm
Task 6 virtual Hosts
"some /etc/host or C:\windows\system32\drivers\etc\hosts"
Q What is the first subdomain discovered?
A Delta
Q What is the second subdomain discovered?
A yellow
That it .. i'll cover next module in other article .
Thanks for Reading .
if You learn something just say thanks to me