Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

TryHackMe CC: Pen Testing - Full Walkthrough (2026)

Дата публикации: 30-09-2026 22:12:15


Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.
I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.
Here's how I approached every section.


Prerequisites
A free TryHackMe account.
The room: CC: Pen Testing.
The AttackBox, or your own Kali/Parrot box over OpenVPN.
A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.


Section 1 — Network Utilities
Nmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:
nmap -sC -sV <target-ip>
-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.
Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.


Section 2 — Web Enumeration
Gobuster brute-forces hidden paths from a wordlist:
gobuster dir -u http://<target-ip> \
-w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.
Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.


Section 3 — Metasploit
Launch it with msfconsole. The workflow is always search → use → inspect:
search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.
For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.


Section 4 — Hash Cracking
Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.
Hashcat:
hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.
John the Ripper:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Identifying the hash type is the real skill; cracking is the easy part.


Section 5 — SQL Injection
sqlmap automates detection and exploitation:
sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.


Section 6 — Samba (SMB)
Misconfigured shares leak credentials, backups, and footholds.
smbmap lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.
smbclient gives an interactive prompt: apt install smbclient, then connect and browse.
Impacket is worth bookmarking for later Active Directory rooms.


Section 7 — Final Exam (Mini-CTF)
Everything chained on one box:
nmap -sC -sV <target-ip> — map the services.
Gobuster the web root.
Recurse into the hidden directory you find (this is the step people miss).
Recover the username + hashed password inside; crack the hash (Section 4).
Log in and read the user flag:
cd ~
cat user.txt
Escalate — on this box it needs no password:
sudo su
cd ~
cat root.txt
Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.
I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.


Conclusion
That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.
If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.


Основное содержимое страницы с новостью.

Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.

I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.

Here's how I approached every section.

Prerequisites
  • A free TryHackMe account.
  • The room: CC: Pen Testing.
  • The AttackBox, or your own Kali/Parrot box over OpenVPN.
  • A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.
Section 1 — Network Utilities

Nmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:

nmap -sC -sV <target-ip>

Enter fullscreen mode Exit fullscreen mode

-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.

Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.

Section 2 — Web Enumeration

Gobuster brute-forces hidden paths from a wordlist:

gobuster dir -u http://<target-ip> \
  -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt

Enter fullscreen mode Exit fullscreen mode

Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.

Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.

Section 3 — Metasploit

Launch it with msfconsole. The workflow is always search → use → inspect:

search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options

Enter fullscreen mode Exit fullscreen mode

options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.

For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.

Section 4 — Hash Cracking

Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.

Hashcat:

hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt

Enter fullscreen mode Exit fullscreen mode

-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.

John the Ripper:

john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt

Enter fullscreen mode Exit fullscreen mode

Identifying the hash type is the real skill; cracking is the easy part.

Section 5 — SQL Injection

sqlmap automates detection and exploitation:

sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump

Enter fullscreen mode Exit fullscreen mode

The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.

Section 6 — Samba (SMB)

Misconfigured shares leak credentials, backups, and footholds.

  • smbmap lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.
  • smbclient gives an interactive prompt: apt install smbclient, then connect and browse.
  • Impacket is worth bookmarking for later Active Directory rooms.
Section 7 — Final Exam (Mini-CTF)

Everything chained on one box:

  1. nmap -sC -sV <target-ip> — map the services.
  2. Gobuster the web root.
  3. Recurse into the hidden directory you find (this is the step people miss).
  4. Recover the username + hashed password inside; crack the hash (Section 4).
  5. Log in and read the user flag:
cd ~
cat user.txt

Enter fullscreen mode Exit fullscreen mode

  1. Escalate — on this box it needs no password:
sudo su
cd ~
cat root.txt

Enter fullscreen mode Exit fullscreen mode

Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.

I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.

Conclusion

That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.

If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Know Your Enemy: Browser-Based Attack Techniques in 2026010.130-09-2026
2Daily Hacker News for 2026-09-2809.4229-09-2026
3Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks07.9328-09-2026
4Пивотинг в аду легаси: MIPS-сервер, BusyBox и ядро 2014 года023.6829-09-2026
5Cve-2026-59873030.1329-07-2026
6Sudden Spike in Vulnerability Scanning Across Domains Prompts Enhanced Security Measures06.2430-09-2026
7#blog@mikhail_tarasovcom #forensics@mikhail_tarasovcom Форензика спутниковых снимков: OSINT из открытого космоса Спутниковый ...06.4729-09-2026
8Daily Hacker News for 2026-09-2309.5924-09-2026
9Daily Hacker News for 2026-09-24011.6225-09-2026
10Cómo proteger tus datos en internet: los consejos de un hacker09.7122-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 12.12. Источник: dev.to.