DEV Community

Cover image for TryHackMe CC: Pen Testing - Full Walkthrough (2026)
Mehmood Ali (Mr. Professor)
Mehmood Ali (Mr. Professor)

Posted on Originally published at crackingstation.org

TryHackMe CC: Pen Testing - Full Walkthrough (2026)

Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.

I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.

Here's how I approached every section.

Prerequisites

  • A free TryHackMe account.
  • The room: CC: Pen Testing.
  • The AttackBox, or your own Kali/Parrot box over OpenVPN.
  • A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.

Section 1 — Network Utilities

Nmap. Most questions come straight from the man page (man nmap). Then deploy the box and run:

nmap -sC -sV <target-ip>
Enter fullscreen mode Exit fullscreen mode

-sV fingerprints service versions; -sC runs the default scripts. Read the version column first — a banner like "vsftpd 2.3.4" is often an instant lead.

Netcat. Read man nc. You won't build a reverse shell here, but understanding a basic listener (nc -lvnp 4444) now makes later rooms click.

Section 2 — Web Enumeration

Gobuster brute-forces hidden paths from a wordlist:

gobuster dir -u http://<target-ip> \
  -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Enter fullscreen mode Exit fullscreen mode

Add -x php,txt,html to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to recurse into it.

Nikto is a fast web-server vuln scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised-test tool, not a stealth one.

Section 3 — Metasploit

Launch it with msfconsole. The workflow is always search → use → inspect:

search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
Enter fullscreen mode Exit fullscreen mode

options lists required settings and hints most answers. Meterpreter questions are about the post-exploitation session you land in — learn getuid, sysinfo, hashdump and shell early.

For the final Metasploit task: set RHOSTS to the machine IP and LHOST to your VPN IP (ip addr show tun0), then exploit and read the flag. The #1 mistake here is using your eth0 address instead of tun0 — if no session opens, check that first.

Section 4 — Hash Cracking

Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.

Hashcat:

hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
Enter fullscreen mode Exit fullscreen mode

-m is the hash mode (17600 = SHA3-512), -a 0 is a dictionary attack. Change only -m for the other hashes.

John the Ripper:

john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Enter fullscreen mode Exit fullscreen mode

Identifying the hash type is the real skill; cracking is the easy part.

Section 5 — SQL Injection

sqlmap automates detection and exploitation:

sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
Enter fullscreen mode Exit fullscreen mode

The dump gives you the database and table names the questions ask for. Don't skip the manual part — learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.

Section 6 — Samba (SMB)

Misconfigured shares leak credentials, backups, and footholds.

  • smbmap lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.
  • smbclient gives an interactive prompt: apt install smbclient, then connect and browse.
  • Impacket is worth bookmarking for later Active Directory rooms.

Section 7 — Final Exam (Mini-CTF)

Everything chained on one box:

  1. nmap -sC -sV <target-ip> — map the services.
  2. Gobuster the web root.
  3. Recurse into the hidden directory you find (this is the step people miss).
  4. Recover the username + hashed password inside; crack the hash (Section 4).
  5. Log in and read the user flag:
cd ~
cat user.txt
Enter fullscreen mode Exit fullscreen mode
  1. Escalate — on this box it needs no password:
sudo su
cd ~
cat root.txt
Enter fullscreen mode Exit fullscreen mode

Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.

I've deliberately left the flag values out — earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.

Conclusion

That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound.

If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.

Top comments (0)