Skip to content
pentestguides.com
  • CTF & Bug Bounty
    • Bug Bounty
      • Bug Bounty Cheatsheets
      • My Bug Bounty Experience
    • Hack The Box
      • HTB Machines
      • HTB Challenges
    • TryHackMe
      • THM Challenges
  • Pentest Methodology
    • Pentest Tools
      • Networking
      • Password Attacks
      • Web
  • Fundamentals
    • Linux Commands
  • Dev & Scripting
    • Coding Challenges
      • Code Golf Cheatsheet
      • Breaking Browser Games
      • Clash of Code
  • Toolbox

ffuf

Solving Lookup – TryHackMe Challenge Writeup

February 16, 2026February 12, 2026 by pentestguides
Lookup TryHackme cover image

Complete walkthrough of Lookup room on TryHackMe: form brute-forcing, elFinder CVE and 2 Linux misconfigurations lead us to the root flag.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, hydra, linux, nmap, path hijacking, php, python, reverse shell, ssh, sudo, suid, tryhackme, web Leave a comment

Solving Basic Pentesting – TryHackMe Challenge Writeup

February 17, 2026February 11, 2026 by pentestguides
Basic Pentesting THM cover image

Full walkthrough of the TryHackMe Basic Pentesting room: web enumeration, SMB usernames, SSH access and SSH private key brute-force.

Categories TryHackMe Challenge Tags brute forcing, brute-force, ctf, ffuf, hydra, john, nmap, private key, privilege escalation, rockyou, smb, ssh, tryhackme, web Leave a comment

RootMe Writeup – Full TryHackMe CTF Solution

February 16, 2026February 8, 2026 by pentestguides
TryHackMe RootMe room official image

Full walkthrough of RootMe: reconnaissance, getting a PHP shell then a reverse shell, and elevating our privileges through a SUID misconfiguration

Categories TryHackMe Challenge Tags apache, ctf, ffuf, find, gobuster, nmap, php, privesc, privilege escalation, reconnaissance, reverse shell, suid, tryhackme, web, web shell Leave a comment

Corridor Writeup – TryHackMe IDOR Challenge

February 16, 2026February 7, 2026 by pentestguides
Corridor TryHackMe official image

Full walkthrough of the Corridor Challenge on TryHackMe. We find the flag by exploiting IDOR through a MD5 id in the URL of the web app.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, hash, hashes, idor, MD5, md5sum, nmap, tryhackme, web Leave a comment

TryHackMe TakeOver Writeup – Subdomain Challenge

February 16, 2026February 5, 2026 by pentestguides
TakeOver TryHackMe challenge official image

Full writeup of TakeOver from TryHackMe. Subdomain enumeration and TLS certificate inspection leads to the discovery of a secret subdomain

Categories TryHackMe Challenge Tags ctf, ffuf, https, nmap, ssl, ssl certificate, subdomain takeover, takeover, tls, tls certificate, tryhackme Leave a comment

Lazy Admin Writeup – TryHacKme Challenge

February 15, 2026February 2, 2026 by pentestguides
Lazy Admin TryHackMe Challenge

In this post, we solve the Lazy Admin CTF from TryHackMe by exploiting 2 CVE of SweetRice CMS and a sudo misconfiguration to get root.

Categories TryHackMe Challenge Tags cms, ctf, ffuf, mysql, nmap, php, reverse shell, sql, sudo, sweetrice, tryhackme, web Leave a comment

Pickle Rick Writeup – Easy TryHacKme CTF

February 16, 2026January 29, 2026 by pentestguides
TryHackMe Pickle Rick CTF image

Pickle Rick is a very easy TryHackMe CTF. We complete it by accessing a web portal, getting a reverse shell and exploiting sudo to become root.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, find, html, nc, php, python, reverse shell, sudo, tryhackme, web Leave a comment

Fuzz Websites with ffuf – Complete Tutorial

January 25, 2026 by pentestguides
ffuf screenshot - using ffuf to fuzz websites

Learn how to master ffuf, from discovering hidden directories and files to revealing virtual hosts. Ffuf is a fast, reliable, simple and flexible web pentesting tool

Categories Pentest Tools - Web Tags bug bounty, ffuf, hackthebox, pentest, pentest tool, tryhackme, virtual hosts, web Leave a comment

Solving Pyrat – an Easy TryHackMe Challenge

February 17, 2026January 23, 2026 by pentestguides
Pyrat TryHackMe logo

Pyrat is an easy TryHackMe challenge where we exploit a Python code execution and use a .git folder to further compromise the server.

Categories TryHackMe Challenge Tags ctf, ffuf, fuzz, git, nmap, python, reverse shell, tryhackme, web Leave a comment

Conversor Writeup – An Easy Linux Hack The Box Machine

February 15, 2026January 20, 2026 by pentestguides
Hack The Box Conversor image

Conversor is an easy linux Hack THe Box machine, where we exploit XSLT injection to get a shell and use a needrestart CVE to get root access

Categories Hack The Box Machine Tags ctf, database, ffuf, hackthebox, hackthebox machine, nmap, python, sqlite, web, xslt Leave a comment
Older posts
Page1 Page2 Next →
  • Pyrat TryHackMe logoSolving Pyrat – an Easy TryHackMe Challenge
    January 23, 2026
  • Corridor TryHackMe official imageCorridor Writeup – TryHackMe IDOR Challenge
    February 7, 2026
  • Whatweb - Linux Web Pentesting toolwhatweb Tutorial: Identify Website Technologies
    January 31, 2026
  • TryHackMe Pickle Rick CTF imagePickle Rick Writeup – Easy TryHacKme CTF
    January 29, 2026
  • Knife machine on Hack The Box - Easy Linux CTFKnife Walkthrough – HTB Easy Machine
    January 14, 2026
  • TryHackMe RootMe room official imageRootMe Writeup – Full TryHackMe CTF Solution
    February 8, 2026
  • nmap results running a NSE scriptnmap Tutorial – the Ultimate Network Scanner
    February 14, 2026

arbitrary file read backdoor binary brute forcing bug bounty bug bounty cheatsheet clash of code cms code golf ctf curl dns ffuf file transfer find ftp hackerone hackthebox hydra idor intigriti kali linux linux linux command nc nmap penetration testing pentest pentesting php privilege escalation python reconnaissance reverse shell scp sftp smb ssh sudo suid tcp tls tryhackme udp web

Legal notice
Privacy policy
Ethical Disclaimer & Terms of Use
About Us
Contact Us

This site is hosted on Hostinger ↗

© 2026 pentestguides.com • Built with GeneratePress