Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.
I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.
Here's how I approached every section.
Prerequisites
A free TryHackMe account.
The room: CC: Pen Testing.
The AttackBox, or your own Kali/Parrot box over OpenVPN.
A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.
Section 1 — Network Utilities
Nmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:
nmap -sC -sV <target-ip>
-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.
Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.
Section 2 — Web Enumeration
Gobuster brute-forces hidden paths from a wordlist:
gobuster dir -u http://<target-ip> \
-w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.
Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.
Section 3 — Metasploit
Launch it with msfconsole. The workflow is always search → use → inspect:
search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.
For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.
Section 4 — Hash Cracking
Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.
Hashcat:
hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.
John the Ripper:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Identifying the hash type is the real skill; cracking is the easy part.
Section 5 — SQL Injection
sqlmap automates detection and exploitation:
sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.
Section 6 — Samba (SMB)
Misconfigured shares leak credentials, backups, and footholds.
smbmap lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.
smbclient gives an interactive prompt: apt install smbclient, then connect and browse.
Impacket is worth bookmarking for later Active Directory rooms.
Section 7 — Final Exam (Mini-CTF)
Everything chained on one box:
nmap -sC -sV <target-ip> — map the services.
Gobuster the web root.
Recurse into the hidden directory you find (this is the step people miss).
Recover the username + hashed password inside; crack the hash (Section 4).
Log in and read the user flag:
cd ~
cat user.txt
Escalate — on this box it needs no password:
sudo su
cd ~
cat root.txt
Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.
I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.
Conclusion
That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.
If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.
Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.
I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.
Here's how I approached every section.
PrerequisitesNmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:
nmap -sC -sV <target-ip>
Enter fullscreen mode Exit fullscreen mode
-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.
Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.
Gobuster brute-forces hidden paths from a wordlist:
gobuster dir -u http://<target-ip> \
-w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Enter fullscreen mode Exit fullscreen mode
Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.
Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.
Section 3 — MetasploitLaunch it with msfconsole. The workflow is always search → use → inspect:
search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
Enter fullscreen mode Exit fullscreen mode
options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.
For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.
Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.
Hashcat:
hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
Enter fullscreen mode Exit fullscreen mode
-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.
John the Ripper:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Enter fullscreen mode Exit fullscreen mode
Identifying the hash type is the real skill; cracking is the easy part.
Section 5 — SQL Injectionsqlmap automates detection and exploitation:
sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
Enter fullscreen mode Exit fullscreen mode
The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.
Section 6 — Samba (SMB)Misconfigured shares leak credentials, backups, and footholds.
apt install smbclient, then connect and browse.Everything chained on one box:
nmap -sC -sV <target-ip> — map the services.cd ~
cat user.txt
Enter fullscreen mode Exit fullscreen mode
sudo su
cd ~
cat root.txt
Enter fullscreen mode Exit fullscreen mode
Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.
I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.
ConclusionThat's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.
If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Know Your Enemy: Browser-Based Attack Techniques in 2026 | 0 | 10.1 | 30-09-2026 |
| 2 | Daily Hacker News for 2026-09-28 | 0 | 9.42 | 29-09-2026 |
| 3 | Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks | 0 | 7.93 | 28-09-2026 |
| 4 | Пивотинг в аду легаси: MIPS-сервер, BusyBox и ядро 2014 года | 0 | 23.68 | 29-09-2026 |
| 5 | Cve-2026-59873 | 0 | 30.13 | 29-07-2026 |
| 6 | Sudden Spike in Vulnerability Scanning Across Domains Prompts Enhanced Security Measures | 0 | 6.24 | 30-09-2026 |
| 7 | #blog@mikhail_tarasovcom #forensics@mikhail_tarasovcom Форензика спутниковых снимков: OSINT из открытого космоса Спутниковый ... | 0 | 6.47 | 29-09-2026 |
| 8 | Daily Hacker News for 2026-09-23 | 0 | 9.59 | 24-09-2026 |
| 9 | Daily Hacker News for 2026-09-24 | 0 | 11.62 | 25-09-2026 |
| 10 | Cómo proteger tus datos en internet: los consejos de un hacker | 0 | 9.71 | 22-09-2026 |