Skip to content
pentestguides.com
  • CTF & Bug Bounty
    • Bug Bounty
      • Bug Bounty Cheatsheets
      • My Bug Bounty Experience
    • Hack The Box
      • HTB Machines
      • HTB Challenges
    • TryHackMe
      • THM Challenges
  • Pentest Methodology
    • Pentest Tools
      • Networking
      • Password Attacks
      • Web
  • Fundamentals
    • Linux Commands
  • Dev & Scripting
    • Coding Challenges
      • Code Golf Cheatsheet
      • Breaking Browser Games
      • Clash of Code
  • Toolbox

web

curl Quick Tutorial – Everything You Need to Know

February 16, 2026 by pentestguides
downloading a file with curl

Complete curl tutorial: send HTTP GET and POST requests, interact with JSON API, send files, use custom HTTP headers, download files, etc.

Categories Linux Commands Tags API, bash, curl, download files, GET, http, HTTP methods, JSON, linux command, linux commands, REST API, shell, terminal, tls, URL, web, wget Leave a comment

Solving Lookup – TryHackMe Challenge Writeup

February 16, 2026February 12, 2026 by pentestguides
Lookup TryHackme cover image

Complete walkthrough of Lookup room on TryHackMe: form brute-forcing, elFinder CVE and 2 Linux misconfigurations lead us to the root flag.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, hydra, linux, nmap, path hijacking, php, python, reverse shell, ssh, sudo, suid, tryhackme, web Leave a comment

Solving Basic Pentesting – TryHackMe Challenge Writeup

February 17, 2026February 11, 2026 by pentestguides
Basic Pentesting THM cover image

Full walkthrough of the TryHackMe Basic Pentesting room: web enumeration, SMB usernames, SSH access and SSH private key brute-force.

Categories TryHackMe Challenge Tags brute forcing, brute-force, ctf, ffuf, hydra, john, nmap, private key, privilege escalation, rockyou, smb, ssh, tryhackme, web Leave a comment

RootMe Writeup – Full TryHackMe CTF Solution

February 16, 2026February 8, 2026 by pentestguides
TryHackMe RootMe room official image

Full walkthrough of RootMe: reconnaissance, getting a PHP shell then a reverse shell, and elevating our privileges through a SUID misconfiguration

Categories TryHackMe Challenge Tags apache, ctf, ffuf, find, gobuster, nmap, php, privesc, privilege escalation, reconnaissance, reverse shell, suid, tryhackme, web, web shell Leave a comment

Corridor Writeup – TryHackMe IDOR Challenge

February 16, 2026February 7, 2026 by pentestguides
Corridor TryHackMe official image

Full walkthrough of the Corridor Challenge on TryHackMe. We find the flag by exploiting IDOR through a MD5 id in the URL of the web app.

Categories TryHackMe Challenge Tags ctf, curl, ffuf, hash, hashes, idor, MD5, md5sum, nmap, tryhackme, web Leave a comment

Lo-Fi Writeup on TryHackMe – File Inclusion

February 16, 2026February 6, 2026 by pentestguides
Lo-Fi TryHackMe official image

This writeup covers the solution of Lo-Fi room on TryHackMe. A PHP File Inclusion along with path traversal allow us to read the flag.

Categories TryHackMe Challenge Tags arbitrary file read, ctf, file inclusion, lfi, path traversal, php, tryhackme, web Leave a comment

TryHackMe “Agent T” Writeup – Easy Challenge

February 16, 2026February 4, 2026 by pentestguides
TryHackMe Agent T official image

Writeup of TryHackMe challenge “Agent T”. We exploit the backdoored version of PHP 8.1.0-dev to get Code Execution and read the flag.

Categories TryHackMe Challenge Tags backdoor, backdoored php, ctf, nc, nmap, php, reverse shell, tryhackme, web Leave a comment

Lazy Admin Writeup – TryHacKme Challenge

February 15, 2026February 2, 2026 by pentestguides
Lazy Admin TryHackMe Challenge

In this post, we solve the Lazy Admin CTF from TryHackMe by exploiting 2 CVE of SweetRice CMS and a sudo misconfiguration to get root.

Categories TryHackMe Challenge Tags cms, ctf, ffuf, mysql, nmap, php, reverse shell, sql, sudo, sweetrice, tryhackme, web Leave a comment

wafw00f – Detect WAF (Web Application Firewalls)

February 1, 2026 by pentestguides
wafw00f - pentesting tool to detect WAF

In this tutorial, we’ll see how to use wafw00f, a Kali Linux pentesting tool, to detect WAF (Web Application Firewalls) used by websites.

Categories Pentest Tools - Web Tags bug bounty, cloudflare, firewall, kali linux, pentesting, reconnaissance, waf, wafw00f, web, web application firewall Leave a comment

whatweb Tutorial: Identify Website Technologies

January 31, 2026January 31, 2026 by pentestguides
Whatweb - Linux Web Pentesting tool

whatweb is a Linux pentesting tool that detects the technologies and frameworks of websites: HTTP servers, CMS like Wordpress, Javascript, etc.

Categories Pentest Tools - Web Tags cms, ctf, http headers, http server, joomla, linux, pentesting, php, web, whatweb, wordpress Leave a comment
Older posts
Page1 Page2 Next →
  • Lookup TryHackme cover imageSolving Lookup – TryHackMe Challenge Writeup
    February 12, 2026
  • Mines reveald on the minesweeperBreaking Google Minesweeper by Revealing the Mines
    January 24, 2026
  • TryHackMe Neighbour roomNeighbour Writeup – Easy IDOR TryHacKme Challenge
    January 28, 2026
  • c4ptur3th3fl4g tryhackme logoSolving c4ptur3-th3-fl4g – a Beginner TryHackMe Challenge
    January 23, 2026
  • Reconnaissance icons created by Freepik - FlaticonBug Bounty Reconnaissance Cheat Sheet
    January 25, 2026
  • Pyrat TryHackMe logoSolving Pyrat – an Easy TryHackMe Challenge
    January 23, 2026
  • Basic Pentesting THM cover imageSolving Basic Pentesting – TryHackMe Challenge Writeup
    February 11, 2026

arbitrary file read backdoor binary brute forcing bug bounty bug bounty cheatsheet clash of code cms code golf ctf curl dns ffuf file transfer find ftp hackerone hackthebox hydra idor intigriti kali linux linux linux command nc nmap penetration testing pentest pentesting php privilege escalation python reconnaissance reverse shell scp sftp smb ssh sudo suid tcp tls tryhackme udp web

Legal notice
Privacy policy
Ethical Disclaimer & Terms of Use
About Us
Contact Us

This site is hosted on Hostinger ↗

© 2026 pentestguides.com • Built with GeneratePress