CTF walkthroughs & pentest methodology - TryHackMe rooms.
- GhostBoss — recon & navigation (Chromium/CDP), énumération web, sélection des rooms, payloads.
- GhostHunter — scans (nmap/ffuf), exploitation, flags.
- Choisir la room (difficulté / thème OWASP).
- Connecter le VPN TryHackMe (
tun0up), démarrer la machine, récupérer l'IP cible. - Recon en parallèle : GhostBoss côté browser/web, GhostHunter côté scans.
- Exploitation → flag.
- CyberHeroes — Authentication Bypass (auth côté client, OWASP A07)
- Room 404