Skip to main content

Command Palette

Search for a command to run...

Corridor

Updated
•4 min read•View as Markdown

Lab Info

Detail Info
Room Corridor
Platform TryHackMe
Difficulty Easy
Type CTF / IDOR + MD5 Hash Cracking + Lateral Thinking
Knowledge Required Web, Burp Suite, Hash Identification/Cracking

Tools Used

  • Nmap — Port scanning

  • Burp Suite (HTTP history / Proxy, no active interception needed) — Capturing the door links

  • CrackStation — Identifying and cracking the MD5 hashes

  • Any MD5 generator (CyberChef, browserling, etc.) — Hashing new numbers to test as doors

First Impressions

Small room, quick solve time on paper — but it earns its reputation as a "think outside the box" room precisely because the obvious next move (door 14) is a dead end, and the actual answer requires questioning the assumption that the corridor only goes one direction. Good one for practicing IDOR pattern recognition without any of the usual web-app noise getting in the way.

Recon

nmap -sS -sV <ip>
PORT   STATE SERVICE VERSION
80/tcp open  http    Werkzeug httpd (Python)

One port, a lightweight Python/Flask-style server. Straight to the browser.

The App — A Corridor Full of Doors

Loading the page drops you into a literal corridor with a row of doors. Clicking any door leads to an empty room — nothing overtly useful in the rendered page itself. The interesting part is what's underneath each door, not what's behind it.

Finding the Pattern — MD5 Hashes as Door IDs

Hovering over (or inspecting) any door's link shows its href pointing to a path made of a long hexadecimal string — the classic shape of an MD5 hash. Rather than clicking through all of them by hand, viewing the page source in one go shows every door's hash link at once, laid out together instead of scattered one-per-click.

Feeding a few of those hashes into CrackStation confirms the pattern immediately: each one is just the MD5 hash of a small integer — doors numbered roughly 1 through 13, hashed instead of shown as plain numbers. Weak obfuscation dressed up to look like a real access-control scheme — a textbook IDOR setup, where the only thing standing between you and "unauthorized" doors is guessing (or computing) the right identifier.

The Obvious Next Move — Door 14 (Doesn't Work)

With the pattern confirmed, the natural next step is trying to go past the last visible door — hash the number 14, drop that hash into the URL in place of an existing one, and see if it leads somewhere new (an "escape" room, presumably).

md5("14") → <hash>

Loading that path returns nothing useful — same as any other invalid path. Moving forward doesn't get you out.

The Actual Trick — Door 0

This is the part that makes the room worth doing: if the numbering starts at 1 and moving up past the visible range doesn't work, the corridor doesn't have to only go one direction. Trying the other side of the range — hashing 0 instead of 14 — is the move that actually pays off.

md5("0") → <hash>

Dropping that hash into the URL in place of an existing door number leads somewhere different from every other door — the escape, and the flag along with it.

Flag Summary

Flag Method
Room flag MD5-hash the integer 0 (not 14) and substitute it into a door URL — the escape lies before the numbered range, not after it

Key Takeaways

  1. Hashing an identifier doesn't make it unguessable — it just changes what you have to guess. MD5 of a small integer is trivially reversible; obfuscation is not the same thing as access control, and this room is a clean, minimal demonstration of exactly that gap.

  2. IDOR hunting benefits from viewing all the available identifiers at once rather than testing them one at a time. A single page-source read exposed every door's hash simultaneously instead of requiring 13 separate clicks.

  3. The "obvious" boundary to test isn't always the only one. Everyone's first instinct is to extend the sequence forward (door 14) — the room's actual lesson is to also check the boundary you're not naturally drawn to (door 0), since a sequence that starts at 1 implies a 0 exists whether or not it's ever displayed.

  4. Small, single-mechanic rooms like this one are worth doing specifically because they isolate the "aha" moment. There's no privesc chain or secondary vulnerability muddying the lesson — just one clean insight about not assuming the obvious direction is the only one.

Day 21 of 30 ✅ — See You Tomorrow

8 views