TryHackMe's Web App PenTest -- Hammer:
https://tryhackme.com/r/room/hammer
00:00 Introduction
01:58 nmap scan
03:32 Authentication Enumeration
05:54 Directory Fuzzing
10:18 Brute Force OTP
15:46 Locked out by Rate-limiting
21:15 Flag 1
22:06 Modify cookie expiration date
23:40 Flag 2