Include — TryHackMe Writeup
Nmap uncovered SSH (22), a full mail stack — SMTP (25), POP3 (110/995), IMAP (143/993) — a Node.js/Express app on port 4000 with guest:guest login, and a PHP System Monitoring Portal on port 50000.
The Node.js app's activity feature allowed overwriting arbitrary object properties (BOPLA), including setting isAdmin to true. The admin panel exposed an internal API endpoint and a settings page vulnerable to SSRF, which leaked base64-encoded credentials for the System Monitoring Portal.
The profile image endpoint on port 50000 was vulnerable to Local File Inclusion via path traversal. Automated fuzzing with ffuf confirmed the vulnerability, and /etc/passwd was read to extract valid system usernames.
Using the extracted usernames from /etc/passwd, Hydra brute-forced SSH credentials for joshua and charles. After logging in, a targeted file search across the filesystem located the final flag hidden in the web root.
Introduction
Include is a medium-rated TryHackMe Linux machine that chains together multiple web application vulnerabilities to progressively escalate access. The target runs a full mail stack alongside two distinct web applications — a Node.js/Express app on port 4000 and a PHP System Monitoring Portal on port 50000.
The attack path flows through Broken Object Property Level Authorization (BOPLA) to gain admin privileges on the Node.js app, SSRF to exfiltrate internal API credentials, LFI on the monitoring portal to extract system users from /etc/passwd, and finally SSH brute-forcing with Hydra to gain a shell and locate the hidden flag.
Reconnaissance
::Nmap Scan
A full TCP port scan reveals eight listening services — including a complete mail stack:
The scan reveals a Linux machine acting as a mail server and hosting two web applications:
| Port | Service | Version | Notes |
|---|---|---|---|
| 22 | SSH | OpenSSH 8.2p1 | Standard SSH service |
| 25 | SMTP | Postfix smtpd | Mail server (mail.filepath.lab) |
| 110, 143, 993, 995 | POP3/IMAP | Dovecot | Standard mail retrieval services |
| 4000 | HTTP | Node.js (Express) | "Sign In" page |
| 50000 | HTTP | Apache 2.4.41 | "System Monitoring Portal" (PHP) |
The machine has a full mail stack running (Postfix + Dovecot). There are two web applications —
port 4000 is a Node.js login page, and port 50000 is an Apache server running PHP
(indicated by the PHPSESSID cookie). Given the machine's name is "Include", port 50000 is the
prime target for File Inclusion attacks.
::Initial Web Exploration
Browsing to http://10.113.170.46:4000 presents a login page. The application helpfully tells us we can log in as guest:guest:

Port 50000 hosts a System Monitoring Portal with its own login form — we'll return to this later once we have credentials.

Enumeration — Port 4000 (Node.js App)
::Guest Login & Feature Discovery
After logging in with guest:guest, we land on a social activity feed. Taking a tour around the application, we discover the ability to add activities — and more importantly, we notice some interesting details attached to our user profile:
- ▹
id: 1 - ▹
isAdmin: false - ▹Various profile attributes like
age,name, etc.

::Intercepting Requests with Caido
Opening Caido to inspect how the "Add Activity" feature works, we observe that adding a new activity sends a simple POST request:


The request body is straightforward:
The critical insight: the activity feature doesn't just add activities — it updates user profile properties directly. If we can control the activityType parameter, we can overwrite any property on our user object.
BOPLA — Broken Object Property Level Authorization
::Overwriting User Properties
Testing the theory — can we modify our own profile fields through the activity feature?
It works — our age is updated to 1000.

Broken Object Property Level Authorization (BOPLA): The API blindly accepts any property name
via the activityType parameter and writes it directly to the user object. There is no allowlist
or authorization check to prevent modification of sensitive properties like isAdmin.
::Escalating to Admin
If we can overwrite age, we can overwrite isAdmin. Sending:
We are now admin. The navigation menu immediately shows new admin-only tabs: /admin with sub-pages including /api and /settings.

BOPLA vs Prototype Pollution: This vulnerability is distinct from prototype pollution. Here,
the API directly writes attacker-controlled key-value pairs onto the user object — no __proto__
chain manipulation is needed. OWASP classifies this as API3:2023 — Broken Object Property Level
Authorization.
SSRF — Internal API Credential Extraction
::Discovering the Internal API
The newly visible /api tab under /admin reveals documentation for an internal API running on 127.0.0.1:5000:
The passwords are redacted in the API documentation — but we now know the exact endpoint that holds the real credentials.
::Exploiting SSRF via Admin Settings
The /settings tab contains an "Update Banner Image URL" feature — a classic SSRF vector. Instead of providing an image URL, we feed it the internal API endpoint:

The server fetches this URL internally and returns the response as a base64-encoded data URI:
::Decoding the Credentials
Two sets of credentials recovered: The ReviewApp credentials are for the Node.js app (port
4000), and the SysMonApp credentials are for the System Monitoring Portal (port 50000). The
SysMonApp credentials are our ticket in.
System Monitoring Portal — Flag 1
::Logging In to Port 50000
Using the extracted credentials to log into the System Monitoring Portal:
We land on the monitoring dashboard — and immediately spot the first flag:

LFI — Local File Inclusion
::Discovering the Vulnerable Parameter
While browsing the System Monitoring Portal with Caido running, a very interesting request catches our eye:

A file inclusion parameter (img) loading a local image file — this screams LFI.
::Automated LFI Fuzzing with ffuf
Rather than manually testing traversal payloads, we save the request and use ffuf with a dedicated LFI wordlist to automate discovery:
The results flood in — the ....// traversal variant (which bypasses simple ../ stripping filters) works consistently:
Why ....// instead of ../? The server likely has a filter that removes ../ sequences
from the input. The ....// pattern exploits this — after the filter strips the inner ../, what
remains is ../, which the filesystem interprets as a valid traversal. This is a classic filter
bypass technique.
::Reading /etc/passwd
Confirming the LFI by manually fetching /etc/passwd:

Filtering for users with a login shell reveals five candidates:
| Username | UID | Home Directory | Shell |
|---|---|---|---|
root | 0 | /root | /bin/bash |
ubuntu | 1000 | /home/ubuntu | /bin/bash |
tryhackme | 1001 | /home/tryhackme | /bin/bash |
joshua | 1002 | /home/joshua | /bin/bash |
charles | 1003 | /home/charles | /bin/bash |
Target Users Identified: joshua and charles are non-default users likely created for this
challenge. They are our primary targets for SSH brute forcing.
SSH Brute Force — Shell Access
::Building the Attack
With a shortlist of valid usernames extracted from /etc/passwd, we create a users file and launch Hydra against SSH:
Hydra cracks both target accounts quickly:
Both joshua and charles use the password 123456 — the most common password in history.
::SSH Login & Flag Hunt
Logging in as joshua:
The home directory only contains a Maildir folder — no flag here. Time for a targeted filesystem search:
The flag is hidden in the web root with an MD5-hash filename — intentionally obscured to prevent casual discovery:
References
- ▹OWASP API3:2023 — Broken Object Property Level Authorization
- ▹OWASP — Server-Side Request Forgery (SSRF)
- ▹OWASP — Path Traversal / Local File Inclusion
- ▹HackTricks — LFI to RCE Techniques
- ▹HackTricks — SSRF Bypass Techniques
- ▹Hydra — Network Login Cracker
- ▹SecLists — LFI Fuzzing Wordlists
- ▹Linux Privilege Escalation: Enumeration & Recon
- ▹Linux Privilege Escalation: Basics & Exploitation

Red Team Consultant · Penetration Tester · Bug Bounty Hunter
Offensive security professional with 250+ vulnerabilities reported across 50+ organizations including Atlassian, Vimeo, and AT&T. Sharing research, tools, and field notes.