<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Mehmood Ali (Mr. Professor)</title>
    <description>The latest articles on DEV Community by Mehmood Ali (Mr. Professor) (@crackingstation).</description>
    <link>https://dev.to/crackingstation</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4153180%2Fd3b4dc3a-d8e2-40c9-9c0d-823a6a531b2d.png</url>
      <title>DEV Community: Mehmood Ali (Mr. Professor)</title>
      <link>https://dev.to/crackingstation</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/crackingstation"/>
    <language>en</language>
    <item>
      <title>TryHackMe CC: Pen Testing - Full Walkthrough (2026)</title>
      <dc:creator>Mehmood Ali (Mr. Professor)</dc:creator>
      <pubDate>Wed, 30 Sep 2026 22:12:15 +0000</pubDate>
      <link>https://dev.to/crackingstation/tryhackme-cc-pen-testing-full-walkthrough-2026-5bn7</link>
      <guid>https://dev.to/crackingstation/tryhackme-cc-pen-testing-full-walkthrough-2026-5bn7</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; I originally published this guide on my blog, &lt;a href="https://crackingstation.org/tryhackme-cc-pen-testing-walkthrough/" rel="noopener noreferrer"&gt;Cracking Station&lt;/a&gt;. This is the syndicated version. Everything here is performed inside the TryHackMe &lt;a href="https://tryhackme.com/room/ccpentesting" rel="noopener noreferrer"&gt;CC: Pen Testing&lt;/a&gt; room — an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I'm Mehmood Ali (Mr. Professor) — a CEH-certified EC-Council instructor. I've trained 1,700+ people, and the number-one reason beginners stall is that they go &lt;em&gt;deep&lt;/em&gt; before they go &lt;em&gt;broad&lt;/em&gt;. &lt;strong&gt;CC: Pen Testing&lt;/strong&gt; fixes that. It's a crash course that gives you one hands-on pass over every core stage of a penetration test, then makes you chain them together in a final CTF.&lt;/p&gt;

&lt;p&gt;Here's how I approached every section.&lt;/p&gt;

&lt;h2&gt;
  
  
  Prerequisites
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;A free &lt;a href="https://tryhackme.com" rel="noopener noreferrer"&gt;TryHackMe&lt;/a&gt; account.&lt;/li&gt;
&lt;li&gt;The room: &lt;a href="https://tryhackme.com/room/ccpentesting" rel="noopener noreferrer"&gt;CC: Pen Testing&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The AttackBox, or your own Kali/Parrot box over OpenVPN.&lt;/li&gt;
&lt;li&gt;A notes file open the whole time. Good notes separate people who &lt;em&gt;finish&lt;/em&gt; rooms from people who &lt;em&gt;redo&lt;/em&gt; them.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Section 1 — Network Utilities
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Nmap.&lt;/strong&gt; Most questions come straight from the man page (&lt;code&gt;man nmap&lt;/code&gt;). Then deploy the box and run:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;nmap &lt;span class="nt"&gt;-sC&lt;/span&gt; &lt;span class="nt"&gt;-sV&lt;/span&gt; &amp;lt;target-ip&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;-sV&lt;/code&gt; fingerprints service versions; &lt;code&gt;-sC&lt;/code&gt; runs the default scripts. Read the &lt;em&gt;version&lt;/em&gt; column first — a banner like "vsftpd 2.3.4" is often an instant lead.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Netcat.&lt;/strong&gt; Read &lt;code&gt;man nc&lt;/code&gt;. You won't build a reverse shell here, but understanding a basic listener (&lt;code&gt;nc -lvnp 4444&lt;/code&gt;) now makes later rooms click.&lt;/p&gt;

&lt;h2&gt;
  
  
  Section 2 — Web Enumeration
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Gobuster&lt;/strong&gt; brute-forces hidden paths from a wordlist:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;gobuster &lt;span class="nb"&gt;dir&lt;/span&gt; &lt;span class="nt"&gt;-u&lt;/span&gt; http://&amp;lt;target-ip&amp;gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-w&lt;/span&gt; /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Add &lt;code&gt;-x php,txt,html&lt;/code&gt; to find files too. Note the hidden directory — you'll need it in the exam, where the trick is to &lt;strong&gt;recurse&lt;/strong&gt; into it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Nikto&lt;/strong&gt; is a fast web-server vuln scanner. Where Gobuster finds &lt;em&gt;content&lt;/em&gt;, Nikto finds &lt;em&gt;problems&lt;/em&gt;. It's noisy, so it's a lab/authorised-test tool, not a stealth one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Section 3 — Metasploit
&lt;/h2&gt;

&lt;p&gt;Launch it with &lt;code&gt;msfconsole&lt;/code&gt;. The workflow is always search → use → inspect:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;options&lt;/code&gt; lists required settings and hints most answers. &lt;strong&gt;Meterpreter&lt;/strong&gt; questions are about the post-exploitation session you land in — learn &lt;code&gt;getuid&lt;/code&gt;, &lt;code&gt;sysinfo&lt;/code&gt;, &lt;code&gt;hashdump&lt;/code&gt; and &lt;code&gt;shell&lt;/code&gt; early.&lt;/p&gt;

&lt;p&gt;For the final Metasploit task: set &lt;code&gt;RHOSTS&lt;/code&gt; to the machine IP and &lt;code&gt;LHOST&lt;/code&gt; to &lt;strong&gt;your&lt;/strong&gt; VPN IP (&lt;code&gt;ip addr show tun0&lt;/code&gt;), then exploit and read the flag. The #1 mistake here is using your &lt;code&gt;eth0&lt;/code&gt; address instead of &lt;code&gt;tun0&lt;/code&gt; — if no session opens, check that first.&lt;/p&gt;

&lt;h2&gt;
  
  
  Section 4 — Hash Cracking
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Salting&lt;/strong&gt; = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson — unsalted SHA-1, cracked fast.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Hashcat:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;hashcat &lt;span class="nt"&gt;-m&lt;/span&gt; 17600 &lt;span class="nt"&gt;-a&lt;/span&gt; 0 &lt;span class="nt"&gt;-o&lt;/span&gt; cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;-m&lt;/code&gt; is the hash mode (17600 = SHA3-512), &lt;code&gt;-a 0&lt;/code&gt; is a dictionary attack. Change only &lt;code&gt;-m&lt;/code&gt; for the other hashes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;John the Ripper:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;john &lt;span class="nt"&gt;--wordlist&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;/usr/share/wordlists/rockyou.txt hashes.txt
john &lt;span class="nt"&gt;--show&lt;/span&gt; hashes.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Identifying the hash type is the real skill; cracking is the easy part.&lt;/p&gt;

&lt;h2&gt;
  
  
  Section 5 — SQL Injection
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;sqlmap&lt;/strong&gt; automates detection and exploitation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;sqlmap &lt;span class="nt"&gt;-u&lt;/span&gt; http://&amp;lt;target-ip&amp;gt; &lt;span class="nt"&gt;--forms&lt;/span&gt;
sqlmap &lt;span class="nt"&gt;-u&lt;/span&gt; http://&amp;lt;target-ip&amp;gt; &lt;span class="nt"&gt;--forms&lt;/span&gt; &lt;span class="nt"&gt;--dump&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The dump gives you the database and table names the questions ask for. &lt;strong&gt;Don't skip the manual part&lt;/strong&gt; — learn how injection works by hand via the &lt;a href="https://owasp.org/www-community/attacks/SQL_Injection" rel="noopener noreferrer"&gt;OWASP SQL Injection reference&lt;/a&gt;. Tools are for speed; understanding is what makes you employable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Section 6 — Samba (SMB)
&lt;/h2&gt;

&lt;p&gt;Misconfigured shares leak credentials, backups, and footholds.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;smbmap&lt;/strong&gt; lists shares and your permissions on each. Watch the permission column — a writable share is often the fastest path in.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;smbclient&lt;/strong&gt; gives an interactive prompt: &lt;code&gt;apt install smbclient&lt;/code&gt;, then connect and browse.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Impacket&lt;/strong&gt; is worth bookmarking for later Active Directory rooms.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Section 7 — Final Exam (Mini-CTF)
&lt;/h2&gt;

&lt;p&gt;Everything chained on one box:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;code&gt;nmap -sC -sV &amp;lt;target-ip&amp;gt;&lt;/code&gt; — map the services.&lt;/li&gt;
&lt;li&gt;Gobuster the web root.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Recurse&lt;/strong&gt; into the hidden directory you find (this is the step people miss).&lt;/li&gt;
&lt;li&gt;Recover the username + hashed password inside; crack the hash (Section 4).&lt;/li&gt;
&lt;li&gt;Log in and read the user flag:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;cd&lt;/span&gt; ~
&lt;span class="nb"&gt;cat &lt;/span&gt;user.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ol&gt;
&lt;li&gt;Escalate — on this box it needs no password:
&lt;/li&gt;
&lt;/ol&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo &lt;/span&gt;su
&lt;span class="nb"&gt;cd&lt;/span&gt; ~
&lt;span class="nb"&gt;cat &lt;/span&gt;root.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;I've deliberately left the flag values out — earn them yourself. If you get stuck, the &lt;a href="https://crackingstation.org/tryhackme-cc-pen-testing-walkthrough/" rel="noopener noreferrer"&gt;full walkthrough with a video for every section is on my blog&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;That's the whole CC: Pen Testing room — recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my &lt;a href="https://crackingstation.org/tryhackme-ctf-writeups-walkthroughs-roadmap/" rel="noopener noreferrer"&gt;TryHackMe roadmap&lt;/a&gt; orders the next rooms so your skills compound.&lt;/p&gt;

&lt;p&gt;If this helped, a follow means a lot — I post beginner-friendly cybersecurity walkthroughs regularly.&lt;/p&gt;

</description>
      <category>tryhackme</category>
      <category>cybersecurity</category>
      <category>ctf</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
