Skip to content
pentestguides.com
  • CTF & Bug Bounty
    • Bug Bounty
      • Bug Bounty Cheatsheets
      • My Bug Bounty Experience
    • Hack The Box
      • HTB Machines
      • HTB Challenges
    • TryHackMe
      • THM Challenges
  • Pentest Methodology
    • Pentest Tools
      • Networking
      • Password Attacks
      • Web
  • Fundamentals
    • Linux Commands
  • Dev & Scripting
    • Coding Challenges
      • Code Golf Cheatsheet
      • Breaking Browser Games
      • Clash of Code
  • Toolbox

path hijacking

Solving Lookup – TryHackMe Challenge Writeup

February 16, 2026February 12, 2026 by pentestguides
Lookup TryHackme cover image

Complete walkthrough of Lookup room on TryHackMe: form brute-forcing, elFinder CVE and 2 Linux misconfigurations lead us to the root flag.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, hydra, linux, nmap, path hijacking, php, python, reverse shell, ssh, sudo, suid, tryhackme, web Leave a comment
  • Python logo10 Clash of Code Challenges Explained #1
    January 22, 2026
  • Dig Dug image - TryHackMe easy DNS server roomSolving Dig Dug – an Easy TryHackMe DNS Challenge
    January 19, 2026
  • Lookup TryHackme cover imageSolving Lookup – TryHackMe Challenge Writeup
    February 12, 2026
  • Pyrat TryHackMe logoSolving Pyrat – an Easy TryHackMe Challenge
    January 23, 2026
  • Corridor TryHackMe official imageCorridor Writeup – TryHackMe IDOR Challenge
    February 7, 2026
  • TryHackMe Neighbour roomNeighbour Writeup – Easy IDOR TryHacKme Challenge
    January 28, 2026
  • Code iconSolving ReactOOPS – Exploiting React2Shell on Hack The Box
    January 20, 2026

arbitrary file read backdoor binary brute forcing bug bounty bug bounty cheatsheet clash of code cms code golf ctf curl dns ffuf file transfer find ftp hackerone hackthebox hydra idor intigriti kali linux linux linux command nc nmap penetration testing pentest pentesting php privilege escalation python reconnaissance reverse shell scp sftp smb ssh sudo suid tcp tls tryhackme udp web

Legal notice
Privacy policy
Ethical Disclaimer & Terms of Use
About Us
Contact Us

This site is hosted on Hostinger ↗

© 2026 pentestguides.com • Built with GeneratePress