Stuck @ Academy > HACKING WORDPRESS> Skills Assessment - WordPress -

First, a caveat. I haven’t looked at this academy lab so I have no idea what the correct path is here.

In general, I’d be hesitant when it comes to launching any packets at what could be a legitimate website. Most resources on HTB use a .HTB or .LOCAL TLD to prevent any traffic accidentally hitting the internet. However, I do notice that the website you’ve mentioned seems… weird (the phone number is 1800 HTB 8888)

The version of WP on that public website does appear to be 5.6.2 but it’s worth noting that was only released in Feb 2021, so unless the lab is constantly updated, it is unlikely they planned ahead and put that as the answer.

So I’d focus on the IP address or http://blog.inlanefreight.local domain.

When you visit http://10.129.195.42 in your browser what do you see?

Have you tried adding blog.inlanefreight.local and inlanefreight.local to your hosts file and visiting them to see if the header change makes a difference?

2 Likes