Source Code Review: practice machines and key commands
Reading the application source is often faster than blind testing. When a box leaks code through a repository, backup, LFI or a readable share, look for hardcoded credentials, secret keys, unsafe functions and trust assumptions. In web code, trace user input from the request to dangerous sinks: database queries, file paths, command execution, template rendering and deserialisation. Grep for words like password, token, secret and eval first, then follow the routes that require no authentication. Git history deserves a pass because removed secrets often remain in earlier commits. Compare the behaviour you see in the browser with what the code does to spot logic gaps. The boxes below reward careful code reading. Time spent reading code is rarely wasted, even when a quick scan finds nothing at first.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Exposed .git Source Code Extraction
Dump full repository commits and source code from misconfigured public /.git/ directory.
git-dumper http://{TARGET_IP}/.git/ ./git-dumpPHP Filter Base64 LFI Wrapper
Read source code of PHP scripts through base64 conversion filter.
http://{TARGET_IP}/index.php?page=php://filter/convert.base64-encode/resource=config.phpffuf Directory & Endpoint Fuzzing
High-speed directory enumeration with auto-calibrated filtering and extension recursion.
ffuf -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt -u http://{TARGET_IP}/FUZZ -e .php,.html,.txt,.bak,.js -ac -mc 200,301,302,403
Keep going
- Methodology: Phase 04: Foothold Execution & Initial Access
- Cheatsheet: Web & Directory Fuzzing
Source Code Review machines (10)
Machines are matched by their technique tags. 9 Linux, 1 Windows.
Easy (3)
| Machine | Platform | OS |
|---|---|---|
| BountyHunter | HTB | Linux |
| Horizontall | HTB | Linux |
| RedPanda | HTB | Linux |
Medium (6)
| Machine | Platform | OS |
|---|---|---|
| Devzat | HTB | Linux |
| Git Happens | THM | Linux |
| Jewel | HTB | Linux |
| Obscurity | HTB | Linux |
| StreamIO | HTB | Windows |
| Waldo | HTB | Linux |
Insane (1)
| Machine | Platform | OS |
|---|---|---|
| Response | HTB | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox