September 7, 2026
๐ง๐ฟ๐๐๐ฎ๐ฐ๐ธ๐ ๐ฒ โ ๐ฅ๐ผ๐ผ๐บ ๐ฐ๐ฌ๐ฐ ๐ช๐ฟ๐ถ๐๐ฒ๐๐ฝ
Room 404 is a very easy web security challenge from TryHackMe where the main focus is directory enumeration and exposed Git repositories.

By mayhack
4 min read
๐ง๐ฟ๐๐๐ฎ๐ฐ๐ธ๐ ๐ฒ โ ๐ฅ๐ผ๐ผ๐บ ๐ฐ๐ฌ๐ฐ ๐ช๐ฟ๐ถ๐๐ฒ๐๐ฝ
The application is running on port 8080, and the goal is to find something that the website was not supposed to expose.
๐ฅ๐ผ๐ผ๐บ ๐ข๐๐ฒ๐ฟ๐๐ถ๐ฒ๐
Room Name: Room 404 Platform: TryHackMe Difficulty: Very Easy Category: Web / Directory Enumeration
The challenge description gives us an important hint:
Port 8080 is open, and the rooms the application never lists are the ones worth finding.
So I started with enumeration.
๐ฅ๐ฒ๐ฐ๐ผ๐ป๐ป๐ฎ๐ถ๐๐๐ฎ๐ป๐ฐ๐ฒ
First, I scanned the target machine to identify the open ports and running services.
Command:
nmap -sC -sV 10.48.181.30
The important results were:
22/tcp open ssh 8080/tcp open http Werkzeug httpd 3.0.1
Nmap also detected something very interesting on port 8080:
http-git: 10.48.181.30:8080/.git/ Git repository found!
This immediately stood out.
The web server appeared to have an exposed .git directory.
๐ช๐ต๐ ๐ถ๐ ๐๐ต๐ฒ ๐๐ถ๐ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐?
Git repositories contain much more than the current website files.
A .git directory can contain:
โข Previous commits โข Deleted files โข Configuration files โข Developer changes โข Old versions of source code โข Sensitive information accidentally committed in the past
So even if the current website does not display something, the information may still exist inside the Git history.
๐ฉ๐ฒ๐ฟ๐ถ๐ณ๐๐ถ๐ป๐ด ๐๐ต๐ฒ ๐๐ ๐ฝ๐ผ๐๐ฒ๐ฑ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐
Since Nmap identified the .git directory, I checked whether it was directly accessible through the web server.
Command:
curl http://10.48.181.30:8080/.git/
The server responded successfully, confirming that the .git directory was exposed.
At this point**, I knew that the Git** repository could potentially be downloaded and analyzed locally.
๐๐๐บ๐ฝ๐ถ๐ป๐ด ๐๐ต๐ฒ ๐๐ถ๐ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐
To recover the repository, I used git-dumper.
Initially, installing it directly with pip gave an externally-managed-environment error.
Instead of installing packages globally, I created a Python virtual environment.
Command:
python3 -m venv venv1
Then I activated it:
source venv1/bin/activate
After activating the virtual environment, I installed git-dumper:
python -m pip install โ upgrade pip
python -m pip install git-dumper
๐ช๐ต๐ฎ๐ ๐ถ๐ ๐ด๐ถ๐-๐ฑ๐๐บ๐ฝ๐ฒ๐ฟ?
git-dumper is a tool used to recover a Git repository when the .git directory is exposed through a web server.
It downloads the available Git objects and repository metadata and reconstructs the repository locally.
๐๐๐บ๐ฝ ๐๐ต๐ฒ ๐ฅ๐ฒ๐ฝ๐ผ๐๐ถ๐๐ผ๐ฟ๐
I then used git-dumper against the target:
git-dumper http://10.48.181.30:8080/ ./dump
The tool detected the exposed .git directory and started fetching the repository data.
After the process completed, the repository was available locally inside the dump directory.
I then moved into it:
cd dump
And checked the files:
ls
The directory contained:
app.js index.html README.md
Now we had access to the application's source code and Git repository history.
๐๐ป๐ฎ๐น๐๐๐ถ๐ป๐ด ๐๐ต๐ฒ ๐๐ถ๐ ๐๐ถ๐๐๐ผ๐ฟ๐
Simply checking the current files was not enough.
Since the challenge was about an exposed Git repository, I also checked the commit history.
I used:
git log -p -S "THM"
The -p option displays the actual changes introduced by each commit.
The -S option searches for commits where the specified string appears or disappears.
Here, I searched for:
THM
This is useful in CTFs because flags commonly contain the THM prefix.
The search revealed the initial commit and its patch.
๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐ต๐ฒ ๐๐น๐ฎ๐ด
While reviewing the commit diff, I found that the README.md file contained a staging flag.
The important part was that the flag was not something the current web application needed to display.
It was stored inside the Git repository history.
This is the final flag for the room.
I am not writing the actual flag here so that readers can find it themselves.
๐ช๐ต๐ ๐ช๐ฎ๐ ๐ง๐ต๐ถ๐ ๐ฃ๐ผ๐๐๐ถ๐ฏ๐น๐ฒ?
The main issue was that the application's .git directory was publicly accessible.
A developer may think that deleting a file from the current website is enough, but Git keeps historical versions of files and changes.
That means sensitive information can remain recoverable even after it has been removed from the latest version.
In this challenge, the exposed Git repository allowed us to reconstruct the repository and inspect its commit history.
๐๐ผ๐บ๐ฝ๐น๐ฒ๐๐ฒ ๐๐๐๐ฎ๐ฐ๐ธ ๐๐น๐ผ๐
The complete process was:
Nmap Scan โ Port 8080 discovered โ Exposed .git detected โ .git verified โ git-dumper used โ Repository recovered โ Git history analyzed โ Sensitive information found โ Flag retrieved
๐๐ฒ๐ ๐๐ฒ๐ฎ๐ฟ๐ป๐ถ๐ป๐ด๐
โข Always enumerate open ports and services. โข Pay attention to unusual directories and files. โข A publicly accessible .git directory can expose an entire repository. โข Git history may contain information that is no longer present in the current source code. โข Deleted files are not necessarily gone from Git history. โข Tools like git-dumper can help recover exposed repositories. โข Source code and commit history should never be publicly accessible on production servers.
๐๐ถ๐ป๐ฎ๐น ๐ง๐ฎ๐ธ๐ฒ๐ฎ๐๐ฎ๐
Room 404 looked like a simple web enumeration challenge, but the important clue was hidden in the Nmap results.
The exposed .git directory gave access to the application's Git repository.
After dumping the repository and analyzing its commit history, I was able to locate the sensitive information containing the flag.
The main lesson is simple:
๐๐ผ ๐ป๐ผ๐ ๐ฒ๐ ๐ฝ๐ผ๐๐ฒ ๐๐ผ๐๐ฟ .๐ด๐ถ๐ ๐ฑ๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐ผ๐ป ๐ฎ ๐ฝ๐๐ฏ๐น๐ถ๐ฐ ๐๐ฒ๐ฏ ๐๐ฒ๐ฟ๐๐ฒ๐ฟ.
๐๐ผ๐ป๐ฐ๐น๐๐๐ถ๐ผ๐ป
This was a great beginner-friendly challenge for understanding web enumeration and Git exposure.
The key steps were identifying port 8080, discovering the exposed .git directory, dumping the repository with git-dumper, and finally searching through the Git history.
It also shows why developers need to be careful about committing secrets or sensitive information to Git repositories.
๐ฌ Stay Connected
If you found this helpful and want to learn more about web security, hands-on labs, feel free to follow me for upcoming posts.
โ๏ธ Follow me for more cybersecurity write-ups
๐ LinkedIn โ codermayank https://www.linkedin.com/in/codermayank/
๐ธ Instagram โ @mayhack_ http://instagram.com/mayhack_/
Tags: #BugBounty #EthicalHacking #CyberSecurity #TryHackMe #CTF #CaptureTheFlag #WebSecurity #DirectoryEnumeration #Git #GitSecurity #PenetrationTesting #InfoSec