Room Link:
https://tryhackme.com/room/webhackingusingcurl-aoc2025-w8q1a4s7d0
Official walkthrough for quick onboarding:
🔗 YouTube Link:
https://youtu.be/nbJ_tuXZa24?si=0YQF4nU9Jjn2BiJ2
Refer to the TryHackMe theory section before starting this challenge.
/post.php using admin:admin. What flag do you receive?THM{curl_post_success}
/cookie.php, save the session cookie, then reuse it. What flag do you receive?THM{session_cookie_master}
/bruteforce.php, what is the admin password?
secretpass
/agent.php with the User-Agent set to TBFC. What flag do you receive?THM{user_agent_filter_bypassed}