First of all, we add the machine to known hosts like:
Then I performed an Nmap scan:
So I decided to take a look at http://airplane.thm:8000
:
Once here, I decided to perform some enumeration using dirsearch ๐
Letโs inspect /airplane
directory:
Itโs some kind of gif
So I decided to perform a deeper enumeration inside /airplane
:
As I didnโt found anything, I decided to take a look back into a โpossibleโ lfi on the main page, so I started Burp and caught the request:
Found a lfi vulnerability