© 2026 Hashnode
Scenario You are contracted to perform a penetration test for a company, and through your pentest, you stumble upon an interesting file manager web application. As file managers tend to execute system commands, you are interested in testing for comma...

Scenario You are tasked to perform a security assessment of a client's web application. Apply what you have learned in this module to obtain the flag. Walkthrough Accessing the target URL redirects us to the next page: After browsing the site for a ...

This article will cover the Upload Vulnerabilities write-up under the Web Fundamentals on THM. Getting Started Please read and follow the instructions in this task carefully. If you skip over this task and encounter connectivity errors as a result, t...

This article will cover the How Websites Work write-up under the Web Fundamentals on THM. How websites work By the end of this room, you'll know how websites are created and will be introduced to some basic security issues. When you visit a website, ...

This article will cover the Burp Suite: The Basics write-up under the Web Fundamentals on THM. Introduction Welcome to Burp Suite Basics! This particular room aims to understand the basics of the Burp Suite web application security testing framework....

This article will cover the Walking An Application write-up under the Web Fundamentals on THM. Walking An Application In this room, you will learn how to manually review a web application for security issues using only the in-built tools in your brow...

This article will cover the Content Discovery write-up under the Web Fundamentals on THM. What is Content Discovery Firstly, we should ask, in the context of web application security, what is content? Content can be many things, a file, video, pictur...
