Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.
I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.
Here's how I approached every section.
Prerequisites
- A free TryHackMe account.
- The room: CC: Pen Testing.
- The AttackBox, or your own Kali/Parrot box over OpenVPN.
- A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.
Section 1 — Network Utilities
Nmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:
nmap -sC -sV <target-ip>
-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.
Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.
Section 2 — Web Enumeration
Gobuster brute-forces hidden paths from a wordlist:
gobuster dir -u http://<target-ip> \
-w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.
Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.
Section 3 — Metasploit
Launch it with msfconsole. The workflow is always search → use → inspect:
search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.
For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.
Section 4 — Hash Cracking
Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.
Hashcat:
hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.
John the Ripper:
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Identifying the hash type is the real skill; cracking is the easy part.
Section 5 — SQL Injection
sqlmap automates detection and exploitation:
sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.
Section 6 — Samba (SMB)
Misconfigured shares leak credentials, backups, and footholds.
- smbmap lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.
-
smbclient gives an interactive prompt:
apt install smbclient, then connect and browse. - Impacket is worth bookmarking for later Active Directory rooms.
Section 7 — Final Exam (Mini-CTF)
Everything chained on one box:
-
nmap -sC -sV <target-ip>— map the services. - Gobuster the web root.
- Recurse into the hidden directory you find (this is the step people miss).
- Recover the username + hashed password inside; crack the hash (Section 4).
- Log in and read the user flag:
cd ~
cat user.txt
- Escalate — on this box it needs no password:
sudo su
cd ~
cat root.txt
Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.
I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.
Conclusion
That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.
If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.
Top comments (0)