
TryHackMe Creative
URL: https://tryhackme.com/room/creative Title Rating Creative Easy Recon Nmap gets us port 22 and port 80. Note: Remember to add creative.thm to /etc/hosts Lets checkout the webserver: Nothing stands out in particular. I did a directory fuzzing still nothing. Finally vhost scan gives us a beta.creative.thm SSRF via found domain Whenever we see a field requesting a URL, always first test SSRF: And we do get a request confirming SSRF....