{"id":1488,"date":"2026-01-13T19:56:00","date_gmt":"2026-01-13T19:56:00","guid":{"rendered":"https:\/\/zombierollz.blog\/?p=1488"},"modified":"2026-01-13T17:56:51","modified_gmt":"2026-01-13T17:56:51","slug":"detecting-web-attacks","status":"publish","type":"post","link":"https:\/\/zombierollz.blog\/?p=1488","title":{"rendered":"Detecting Web Attacks"},"content":{"rendered":"\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-1 wp-block-paragraph\"><a href=\"https:\/\/tryhackme.com\/room\/detectingwebattacks\">https:\/\/tryhackme.com\/room\/detectingwebattacks<\/a><br>Created by: tryhackme, ryla, TactfulTurtle<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"651\" height=\"240\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-10-114439.png\" alt=\"\" class=\"wp-image-1489\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-10-114439.png 651w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-10-114439-300x111.png 300w\" sizes=\"auto, (max-width: 651px) 100vw, 651px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-2 wp-block-paragraph\">THM links to other rooms per the prerequisites. These rooms cover the most recent update to OWASP! <br><br>&#8220;<a href=\"https:\/\/tryhackme.com\/module\/owasp-top-10-2025\">OWASP\u00a0Top 10<\/a>\u00a0covers the ten most critical web security risks. Complete\u00a0<a href=\"https:\/\/tryhackme.com\/room\/introtologanalysis\">Intro to Log Analysis<\/a>\u00a0for an overview of logs and useful indicators. <a href=\"https:\/\/tryhackme.com\/room\/wiresharkthebasics\">Wireshark: The Basics<\/a>\u00a0provides a great introduction to packet capture analysis.&#8221;<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-3 wp-block-paragraph\">Task 2: Client-Side Attacks!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"423\" height=\"430\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064217.png\" alt=\"\" class=\"wp-image-1490\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064217.png 423w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064217-295x300.png 295w\" sizes=\"auto, (max-width: 423px) 100vw, 423px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"427\" height=\"774\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064805.png\" alt=\"\" class=\"wp-image-1491\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064805.png 427w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064805-166x300.png 166w\" sizes=\"auto, (max-width: 427px) 100vw, 427px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-4 wp-block-paragraph\">Before we address our questions, THM links to two other rooms: https:\/\/tryhackme.com\/room\/axss for XSS attacks and https:\/\/tryhackme.com\/room\/csrfV2 for CSRF attacks.<br><br>For questions &#8220;What class of attacks relies on exploiting the user&#8217;s behavior or device?&#8221; and &#8220;What is the most common client-side attack?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"426\" height=\"414\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064842.png\" alt=\"\" class=\"wp-image-1492\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064842.png 426w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-064842-300x292.png 300w\" sizes=\"auto, (max-width: 426px) 100vw, 426px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5 wp-block-paragraph\">On to Task 3, Server-Side Attacks!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"422\" height=\"392\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065106.png\" alt=\"\" class=\"wp-image-1493\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065106.png 422w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065106-300x279.png 300w\" sizes=\"auto, (max-width: 422px) 100vw, 422px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"428\" height=\"524\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065423.png\" alt=\"\" class=\"wp-image-1494\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065423.png 428w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065423-245x300.png 245w\" sizes=\"auto, (max-width: 428px) 100vw, 428px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"398\" height=\"623\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065450.png\" alt=\"\" class=\"wp-image-1495\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065450.png 398w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065450-192x300.png 192w\" sizes=\"auto, (max-width: 398px) 100vw, 398px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background wp-block-paragraph\">THM links to three rooms in this task: https:\/\/tryhackme.com\/room\/passwordattacks, https:\/\/tryhackme.com\/room\/sqlinjectionlm, and https:\/\/tryhackme.com\/room\/oscommandinjection\/<br><br>For questions: &#8220;What class of attacks relies on exploiting vulnerabilities within web servers?&#8221; and &#8220;Which server-side attack lets attackers abuse forms to dump database contents?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"418\" height=\"375\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065807.png\" alt=\"\" class=\"wp-image-1496\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065807.png 418w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-065807-300x269.png 300w\" sizes=\"auto, (max-width: 418px) 100vw, 418px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-6 wp-block-paragraph\">On to Task 4, Log-Based Detection! It appears that this room will be more technical than the previous tasks.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"424\" height=\"335\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-070939.png\" alt=\"\" class=\"wp-image-1497\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-070939.png 424w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-070939-300x237.png 300w\" sizes=\"auto, (max-width: 424px) 100vw, 424px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-7 wp-block-paragraph\">We are tasked with opening a log file from the desktop to obtain our answers.<br><br>&#8220;What is the attacker&#8217;s User-Agent while performing the directory fuzz?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"258\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071733-1024x258.png\" alt=\"\" class=\"wp-image-1498\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071733-1024x258.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071733-300x76.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071733-768x194.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071733.png 1355w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-8 wp-block-paragraph\">&#8220;What is the name of the page on which the attacker performs a brute-force attack?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"221\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071843-1024x221.png\" alt=\"\" class=\"wp-image-1499\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071843-1024x221.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071843-300x65.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071843-768x166.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-071843.png 1310w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-9 wp-block-paragraph\">&#8220;What is the complete,\u00a0<a href=\"https:\/\/gchq.github.io\/CyberChef\/\">decoded<\/a>\u00a0SQLi payload the attacker uses on the\u00a0<code>\/changeusername.php<\/code>\u00a0form?&#8221;<br><br>CyberChef time! Usually, they have the offline version available in the VM, but I&#8217;m not seeing it. Go to cyberchef.org.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"359\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240-1024x359.png\" alt=\"\" class=\"wp-image-1500\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240-1024x359.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240-300x105.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240-768x269.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240-1536x538.png 1536w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072240.png 1912w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-10 wp-block-paragraph\">On to Task 5, Network-Based Detection!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"411\" height=\"399\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072333.png\" alt=\"\" class=\"wp-image-1501\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072333.png 411w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-072333-300x291.png 300w\" sizes=\"auto, (max-width: 411px) 100vw, 411px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-11 wp-block-paragraph\">Navigate to the traffic.pcap file from the desktop, and it will load Wireshark.<br><br>&#8220;What password does the attacker successfully identify in the brute-force attack?&#8221;<br><br>We can use this search filter to find successful logins(302).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"76\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075145-1024x76.png\" alt=\"\" class=\"wp-image-1502\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075145-1024x76.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075145-300x22.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075145-768x57.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075145.png 1387w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"795\" height=\"625\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075306.png\" alt=\"\" class=\"wp-image-1503\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075306.png 795w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075306-300x236.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-075306-768x604.png 768w\" sizes=\"auto, (max-width: 795px) 100vw, 795px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-12 wp-block-paragraph\">&#8220;What is the flag the attacker found in the database using SQLi?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"517\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085811-1024x517.png\" alt=\"\" class=\"wp-image-1504\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085811-1024x517.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085811-300x151.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085811-768x387.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085811.png 1356w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"780\" height=\"711\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085846.png\" alt=\"\" class=\"wp-image-1505\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085846.png 780w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085846-300x273.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-085846-768x700.png 768w\" sizes=\"auto, (max-width: 780px) 100vw, 780px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-13 wp-block-paragraph\">On to the last task, Web Application Firewall!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"419\" height=\"356\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-093424.png\" alt=\"\" class=\"wp-image-1506\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-093424.png 419w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-093424-300x255.png 300w\" sizes=\"auto, (max-width: 419px) 100vw, 419px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-14 wp-block-paragraph\">For the questions &#8220;What do WAFs inspect and filter? and &#8220;Create a custom firewall rule to block any\u00a0<code>User-Agent<\/code>\u00a0that matches\u00a0<code>\"BotTHM\"<\/code>.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"699\" height=\"261\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-094143.png\" alt=\"\" class=\"wp-image-1507\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-094143.png 699w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/01\/Screenshot-2026-01-13-094143-300x112.png 300w\" sizes=\"auto, (max-width: 699px) 100vw, 699px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/tryhackme.com\/room\/detectingwebattacksCreated by: tryhackme, ryla, TactfulTurtle THM links to other rooms per the prerequisites. These rooms cover the most recent update to OWASP! &#8220;OWASP\u00a0Top 10\u00a0covers the ten most critical web security risks. Complete\u00a0Intro to Log Analysis\u00a0for an overview of logs and useful indicators. Wireshark: The Basics\u00a0provides a great introduction to packet capture analysis.&#8221; Task 2: Client-Side [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1488","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/1488","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1488"}],"version-history":[{"count":1,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/1488\/revisions"}],"predecessor-version":[{"id":1508,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/1488\/revisions\/1508"}],"wp:attachment":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}