Robots — TryHackMe

XSS in a registration form exfiltrates the admin’s session cookie; RFI via the admin URL-tester gives www-data code execution; double-MD5 cracking yields SSH access, and a sudo apache2 logging trick writes a root SSH key.

June 8, 2026 · 4 min · 774 words · Th3B0yWh0L1v3d