DEV Community

Cover image for Advent of Cyber 2025: Day 4 Writeup AI-AI-AI | TryHackMe
Mahin Ahmad
Mahin Ahmad

Posted on

Advent of Cyber 2025: Day 4 Writeup AI-AI-AI | TryHackMe

Day 5 Challenge Room Page

tryhackme Connection summary

Look for this summary-picture what to start everyday. You dont need any special tools today, except for python. So if you have OpenVPN setup already then you don't need to start the Attackbox which has a 1 hour limit each day. Just start the Target Machine .
Attack box and Target Box
For the next step, open Firefox and follow this quote from the second task:

When you're ready, you can access Van SolveIT at http://10.49.141.x4x. Remember, you will need to do so either from the AttackBox or your own device connected to the VPN.

You have to chat with the AI and finish the stages, to get the first flag. For the first stage, just click "Complete Stage to Continue"
AoC Day 4 Van SolveIT Stages

Stage 2: Act as an Attacker i.e. Red Team

  • From TryHackMe room, copy the Target Machine IP into the code highlighted as MACHINE_IP
  • Save the file

Python code to sqli

  • run it python3 file.py -_-. You will get a response, and flag, put that in TryHackme's second flag's field. Python code to sqli
  • click Complete

Stage 3: Act as defender i.e. Blue Team

The chatbot tells us what to ask:

Let's solve this stage together. You can ask me to analyse an example set of logs for the attack that we just performed!

  • So ask away, and wait a minute to load
  • Read the reply, notice that the vulnerable file is called login.php
  • Click Complete

Stage 4:

  • Type 'yes' and wait for the reply πŸ₯±
  • Read and Learn about how to make login.php safe.
  • Click to Complete Showcase to finish this last stage and get the flag!

The End... In a way, easy rooms are more stressful than harder ones...

Top comments (0)