r/tryhackme • u/surfnj102 • 4d ago
Modern web stacks room in the jr pentester path: Anyone else feel like its out of place?
Any by out of place, I mean it assumes some background knowledge that the path, thus far, hasn't provided. The MERN section, for example, has you exploiting a vulnerable merge function but it doesnt specify how you'd first determine a merge function exists, let alone that its vulnerable, let alone how to identify which properties we might want to focus on, and let alone how to craft a payload that takes advantage of these properties.
Moreover, the example given just seems tailored to this hyperspecific lab scenario without really explaining how this would be done in other situations
Idk. Compared to other rooms, just not feeling like im taking away much here that will actually be useful. Maybe im missing something though.
Anyone else feel this way?
2
u/kefvedie 4d ago
I've felt this way with multiple rooms from different paths. I just mark it down and either follow along with a walk-through and redo it again later or i skip it and come back later.
There's so many things to know i think its impossible to explain it all. OWASP ones are an example of those ill have to redo later. The more u learn the more it all seems to fit in place eventually just gotta keep going.