TryHackMe CC: Pen Testing - Full Walkthrough (2026)
Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room - an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.
I'm Mehmood Ali (Mr. Professor) - a CEH‑certified EC‑Council instructor. I've trained 1,700+ people, and the number‑one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands‑on pass over every core stage of a penetration test, then makes you chain them together in a final CTF. Here's how I approached every section.
Prerequisites
- A free TryHackMe account.
- The room: CC: Pen Testing.
- The AttackBox, or your own Kali/Parrot box over OpenVPN.
- A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.
Section 1 - Network Utilities
Nmap
Most questions come straight from the man page (man nmap). Deploy the box and run:
nmap -sC -sV <target-ip>
-sVfingerprints service versions.-sCruns the default scripts.
Read the version column first - a banner like vsftpd 2.3.4 is often an instant lead.
Netcat
Read man nc. You won't build a reverse shell here, but understanding a basic listener now makes later rooms click:
nc -lvnp 4444
Section 2 - Web Enumeration
Gobuster
Brute‑forces hidden paths from a wordlist:
gobuster dir -u http://<target-ip> \
-w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
Add -x php,txt,html to find files too. Note the hidden directory - you'll need it in the exam, where the trick is to recurse into it.
Nikto
A fast web‑server vulnerability scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised‑test tool, not a stealth one.
Section 3 - Metasploit
Launch with msfconsole. The workflow is always search → use → inspect:
search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options
options lists required settings and hints most answers.
Meterpreter questions are about the post‑exploitation session you land in - learn getuid, sysinfo, hashdump and shell early.
For the final Metasploit task:
- Set
RHOSTSto the machine IP. - Set
LHOSTto your VPN IP (ip addr show tun0). exploitand read the flag.
#1 mistake: using your
eth0address instead oftun0- if no session opens, check that first.
Section 4 - Hash Cracking
Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson - unsalted SHA‑1, cracked fast.
Hashcat
hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
-mis the hash mode (17600= SHA3‑512).-a 0is a dictionary attack.- Change only
-mfor the other hashes.
John the Ripper
john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt
Identifying the hash type is the real skill; cracking is the easy part.
Section 5 - SQL Injection
sqlmap automates detection and exploitation:
sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump
The dump gives you the database and table names the questions ask for. Don't skip the manual part - learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.
Section 6 - Samba (SMB)
Misconfigured shares leak credentials, backups, and footholds.
-
smbmap lists shares and your permissions on each. Watch the permission column - a writable share is often the fastest path in.
-
smbclient gives an interactive prompt:
apt install smbclientthen connect and browse.
-
Impacket is worth bookmarking for later Active Directory rooms.
Section 7 - Final Exam (Mini‑CTF)
Everything chained on one box:
nmap -sC -sV <target-ip>- map the services.- Gobuster the web root.
- Recurse into the hidden directory you find (this is the step people miss).
- Recover the username + hashed password inside; crack the hash (Section 4).
- Log in and read the user flag:
cd ~ cat user.txt - Escalate - on this box it needs no password:
sudo su cd ~ cat root.txt
Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.
I've deliberately left the flag values out - earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.
Conclusion
That's the whole CC: Pen Testing room - recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound. If this helped, a follow means a lot - I post beginner‑friendly cybersecurity walkthroughs regularly.
Comments
No comments yet. Start the discussion.