Sws202_seasonalctf
“Be black or white, don’t try to be grey.”
Room Information
- Room Name: Darkcorp
- Difficulty Level: Insane
- Room type: Seasonal machine(CTF)
- Platform: Hack the box
Reconnaissance
Let’s run nmap and check what ports are open.
We have discovered 2 open ports: 22(ssh) and 80(http). Since port 80 is open let’s check the website.
We can see that the website redirects us to “drip.htb”, so let’s add that to our hosts file.
Let’s refresh the website.
I found that it is a mailing website. Next I try that functionality of that dripmail.
the contact us is working fine and my message is sent successfully. I have also sign up to that dripmail site.
But the sign in is blocking by firewall.
I notice that it is re-directed to “mail.drip.htb”.
Let’s add that to our host file.( sudo nano /etc/hosts)
When refreshed, I got the login form.
So I used my credential that i signup.
I was welcome by gmail like page.
Next i also try to search for subdirectory.
I found dashboard sudirectory, let’c check that.
ohh, that page is not found. Now i am struck.













