All Posts

TryHackMe CC: Pen Testing – Full Walkthrough (2026)

By Mehmood Ali (Mr. Professor), CEH, CEI, MCT · EC-Council Certified Instructor · TryHackMe Top 1%  ·  Published 30 September 2026 · Based on my own completion of the room

Quick answer: TryHackMe CC: Pen Testing is a beginner-friendly crash course that walks you through the core stages of a penetration test on authorised, intentionally vulnerable lab machines: network scanning (Nmap, Netcat), web enumeration (Gobuster, Nikto), exploitation with Metasploit, hash cracking (Hashcat, John), SQL injection (sqlmap), Samba enumeration (smbmap, smbclient), and a final mini-CTF. This walkthrough explains what each section teaches, how I approached it in class and in the room, and the mistakes I see students make with a video for every part.

Legal & ethical note. Everything below is performed inside the TryHackMe CC: Pen Testing room a sandboxed lab you are explicitly authorised to attack. Never run these tools or techniques against systems you do not own or have written permission to test. Unauthorised access is a crime in almost every country, including under Pakistan’s PECA 2016 and the UK Computer Misuse Act. Learn on labs; work under contract.

tryhackme cc pen testing

TryHackMe CC: Pen Testing Video Walkthrough

Quick answer: This is the complete video walkthrough of the TryHackMe CC: Pen Testing room by Mehmood Ali (Mr. Professor), CEH and EC-Council instructor. Five videos cover Metasploit, hash cracking, SQL injection with sqlmap, Samba enumeration and the final exam. Every flag is solved step by step, explained in Urdu/Hindi.

Part 1: Section 3 – Metasploit

Setting up Metasploit, selecting modules, changing options and running exploits.

Part 2: Section 4 – Hash Cracking

Hash formats and salting, then cracking with Hashcat and John the Ripper.

Part 3: Section 5 – SQL Injection (sqlmap)

Automating SQL injection with sqlmap against the vulnerable web application.

Part 4: Section 6 – Samba (SMB)

Enumerating and accessing SMB shares with smbmap and smbclient.

Part 5: Section 7 – Final Exam (Live CTF)

Solving the final exam box end to end: recon, exploitation and privilege escalation.

▶ Watch the full TryHackMe series playlist · Subscribe to Mr. Professor on YouTube

Why this room matters (and who it’s for)

Over the last nine years I’ve trained more than 1,700 professionals, and the single biggest reason beginners stall is that they try to go deep before they’ve gone broad. They spend three weeks mastering Nmap flags and never touch a database, or they memorise one Metasploit exploit and freeze the moment a box needs hash cracking. CC: Pen Testing solves that problem. It is deliberately a crash course: it gives you one honest, hands-on pass over every core stage of a penetration test so that nothing later feels completely foreign.

Think of a real engagement as a pipeline reconnaissance, enumeration, exploitation, post-exploitation, and reporting. This room hands you a working tool for each of those stages and then, in the final exam, makes you chain them together on a single target. That is exactly the muscle memory you’ll reuse in harder rooms and in paid work. If you finish this room understanding why each tool exists and where it fits in the pipeline, you’ve got everything this crash course is designed to give you.

Prerequisites

  • A free TryHackMe account and internet access.
  • The room: TryHackMe – CC: Pen Testing.
  • The browser-based AttackBox, or your own Kali/Parrot machine connected over OpenVPN. New to the VPN? See my TryHackMe OpenVPN setup guide.
  • A notes file open the whole time. I keep a plain notes.md (some prefer CherryTree or Obsidian) and paste every command, IP and answer as I go. Good notes are the habit that separates people who finish rooms from people who redo them.

What you’ll learn in CC: Pen Testing

This room is broad rather than deep, and that’s the point. By the end you’ll be comfortable reading a man page under time pressure, running a service scan, driving Metasploit from search to shell, cracking a password hash, automating a SQL-injection test, and enumerating an SMB share, then combining all of it in a CTF. Below I walk each section in order, explain the concept in plain language, give the commands the room expects, and flag the errors I see most often.

Part 1: Introduction

The opening task is reading only, it sets expectations and lists the skills the room covers. Don’t rush past it. Two minutes here tells you what the room values and lets you plan your notes structure with a heading per section. When you’re done, click the green Complete button to unlock the first practical task.

Section 1 – Network Utilities

Reconnaissance is the foundation of every test. If you don’t know what ports are open and what services are listening, you’re guessing and guessing wastes the limited time you have on any engagement. This section introduces the two tools you’ll reach for first on almost every box.

Nmap

Nmap (“Network Mapper”) is the industry-standard port scanner. Most of the questions in this task come straight from its man page, which is worth reading in full at least once in your career. Open it in your terminal with man nmap, or use the online nmap(1) man page. Once you’ve answered the flag questions, deploy the machine and run a service + default-script scan:

nmap -sC -sV <target-ip>

Here -sV fingerprints the version of each service it finds, and -sC runs Nmap’s default NSE scripts, which pull banner details, check for common misconfigurations, and often surface an obvious way in. That single command answers the practical questions about open ports and running services.

Teaching tip: version numbers are gold. A service banner like “vsftpd 2.3.4” or “Apache 2.4.49” is often enough to search for a matching public exploit in seconds. Train yourself to read the version column first, not the port number. If a scan feels slow on your own VM, add -T4 for a faster timing template on lab networks never on production.

Netcat

Netcat is the “Swiss-army knife” of networking. In its simplest form it opens a TCP or UDP connection to a port, or listens on one but that simplicity is exactly why it’s so useful. It can grab a service banner, transfer a file, act as a chat relay between two machines, and, most importantly for pentesters, catch a reverse shell. Read man nc (or the online nc(1) man page) and use it to answer the questions. You won’t build a reverse shell in this room, but understanding a basic listener (nc -lvnp 4444) and a connect (nc <ip> <port>) now will make later rooms click instantly instead of feeling like magic.

Section 2 – Web Enumeration

Web servers are the most common entry point on modern targets, and most of what you need is hidden one directory deep. This section covers finding those hidden paths and quickly checking a web server for known problems.

Gobuster

Gobuster brute-forces hidden directories and files by trying every entry in a wordlist against the server and watching the HTTP status codes. Skim the Kali gobuster docs, then deploy the box and enumerate directories:

gobuster dir -u http://<target-ip> \
  -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt

Add -x php,txt,html if you also want to discover files, not just folders the extensions you choose should match the tech stack Nmap revealed (PHP site → try php). Note the hidden directory Gobuster reveals; you will need it in the final exam, where the trick is to recurse run Gobuster again inside the directory you just found.

Common mistake: students pick a giant wordlist and wait ten minutes when a smaller one would have found the path in thirty seconds. Start small (common.txt), escalate only if you find nothing, and always match your wordlist to the target rather than defaulting to the biggest file on disk.

Nikto

Nikto is a fast web-server vulnerability scanner. Where Gobuster finds content, Nikto finds problems outdated software, dangerous HTTP methods, default files, and known CVEs. Read man nikto or the nikto man page and use it to answer the questions. In a real test you’d run it against the web port early to get a cheap, noisy first look just remember it is noisy, so it’s a lab-and-authorised-test tool, not a stealth one.

Section 3 – Metasploit

Metasploit is the framework that ties discovery and exploitation together. It holds thousands of exploit modules, payloads, and post-exploitation tools behind a single console, so instead of hunting down and compiling an exploit by hand, you search, select, configure, and fire. On Kali it’s pre-installed; otherwise follow the room’s install steps. Launch it with:

msfconsole

The first load can take a minute while it builds its database that’s normal. Once you’re at the msf6 > prompt, the help command lists every core command and answers the intro questions.

Selecting a module

The room has you find and load a well-known SMB module by name. The workflow is the same for every exploit in Metasploit search, use, inspect:

search eternalblue
use exploit/windows/smb/ms17_010_eternalblue
options

The options command lists every required and optional setting and gives strong hints for the remaining questions. A couple of answers need light background reading the Null Byte EternalBlue guide explains what the module actually does under the hood, which is worth understanding rather than just copying.

Meterpreter

These questions are about Meterpreter the advanced payload session you land in after a successful exploit. Meterpreter runs in memory and gives you a rich command set: file transfer, screenshotting, privilege checks, hash dumping, pivoting, and more, all without writing tools to disk. The Metasploit Unleashed: Meterpreter basics page lists the commands the room asks about. Learn getuid, sysinfo, hashdump and shell early you’ll use them constantly.

Putting it together

The final Metasploit task has you exploit a vulnerable web service and then read a flag file. The workflow the room expects:

  1. Search for and select the target service’s exploit module.
  2. Set RHOSTS to the machine IP: set RHOSTS <target-ip>.
  3. Set LHOST to your VPN IP: find it with ip addr show tun0 if you’re on OpenVPN.
  4. Run the exploit to get a basic shell, then browse to the served web directory and read the flag inside the secret folder:
cd /var/nostromo/htdocs
ls
cd <secret-directory>
cat <flag-file>

The #1 mistake here: setting LHOST to your eth0 address instead of tun0. On TryHackMe your route to the box is the VPN tunnel, so the callback has to come back over tun0. If the exploit runs but no session opens, that’s almost always why check your LHOST before you touch anything else.

Section 4 – Hash Cracking

Once you have access, you’ll often find password hashes in a config file, a database dump, or a Meterpreter hashdump. Cracking them offline turns those hashes back into plaintext you can reuse elsewhere. This section teaches the two crackers everyone should know, and it explains an important defensive concept along the way.

Salting is random data mixed into a password before hashing, so that two people with the same password get two different hashes. Salting doesn’t make a single hash uncrackable, but it defeats precomputed “rainbow table” lookups and forces an attacker to crack each hash individually. The 2012 LinkedIn breach is the classic cautionary tale: those hashes were unsalted SHA-1, so millions fell almost immediately. Understanding this helps you both attack weak hashes and advise clients to store strong ones.

Hashcat

Hashcat is the fastest cracker, especially with a GPU. Read the Hashcat wiki, save the provided hash to a file, and run a dictionary attack:

hashcat -m 17600 -a 0 -o cracked.txt hash.txt /usr/share/wordlists/rockyou.txt

Breaking that down: -m 17600 is the hash mode (SHA3-512 in this case), -a 0 is a straight dictionary attack, -o is the output file, hash.txt holds the hash, and rockyou.txt is the wordlist. For the other hashes in the task, keep everything the same and only change the -m value to the correct mode for that hash type, the wiki’s mode table is your reference. Identifying the hash type first (by length and format) is the real skill; the cracking is the easy part.

John the Ripper

John the Ripper is the other cracker every tester should know. It auto-detects many hash formats, which makes it forgiving for beginners. Put the hashes in one file and run:

john --wordlist=/usr/share/wordlists/rockyou.txt hashes.txt
john --show hashes.txt

--show prints the cracked results after the run. If your VM is underpowered, the room notes you can use a reputable online lookup service instead, for example CrackStation.net (a separate hash-lookup site, not affiliated with Cracking Station) or hashes.com. Only ever paste lab hashes into those never a real client’s.

Section 5 – SQL Injection

SQL injection (SQLi) is one of the oldest and most damaging web vulnerabilities. It happens when user input is dropped into a database query without proper handling, letting an attacker change the query’s meaning reading data they shouldn’t, bypassing logins, or dumping an entire database. It’s a staple of bug-bounty work and a recurring OWASP Top 10 entry, so this is a section worth internalising.

sqlmap

sqlmap automates the detection and exploitation of SQL injection. Read the sqlmap man page, then point it at the target’s forms to detect injectable parameters:

sqlmap -u http://<target-ip> --forms

The output tells you which injection techniques were found (boolean-based, time-based, UNION, and so on). To retrieve the database contents on this lab box:

sqlmap -u http://<target-ip> --forms --dump

Scroll through the dump to find the database and table names the questions ask for. sqlmap is powerful, so on real targets you’d scope it tightly but here the whole box exists to be dumped.

Don’t skip the manual part. The room rightly warns against being tool-dependent, and I say the same thing to every class: a tool that finds SQLi for you is worthless if you can’t explain the injection to a client or adapt when the tool fails. Learn how it works by hand. the OWASP SQL Injection reference is the best free place to start. Tools are for speed; understanding is what makes you employable.

Section 6 – Samba (SMB)

Samba is the Linux implementation of SMB, the file-sharing protocol behind Windows network shares. Misconfigured shares are a goldmine on internal networks. they leak credentials, backups, source code, and sometimes give you a direct foothold. This section covers the two tools you’ll use to enumerate them.

smbmap

smbmap lists the shares on a target and, crucially, the permissions you have on each one (read, write, or none). Read the smbmap man page and use it to map the shares on the box. A writable share is often the fastest path to a shell, so pay attention to the permission column.

smbclient

smbclient gives you an interactive, FTP-like prompt for a single share, so you can list, download, and upload files. Install it if needed (apt install smbclient) and read the smbclient man page. Use it to connect to a share smbmap flagged and browse what’s inside.

A note on Impacket

The room points to Impacket, a collection of Python classes for working with network protocols. Its example scripts (psexec.py, smbclient.py, secretsdump.py and more) use SMB to enumerate and, on vulnerable Windows hosts, obtain a shell. You won’t need it to finish this room, but bookmark it, it’s a cornerstone of Active Directory work in later rooms.

A note on privilege escalation

This task is reading: it introduces privilege escalation, the art of turning a low-privilege foothold into full root/SYSTEM control and links to resources. Privilege escalation is where most CTFs are actually won, and you’ll apply it directly in the final exam. Skim the linked material now so the exam’s escalation step feels familiar rather than surprising.

Section 7 – Final Exam (Mini-CTF)

This is where the whole room pays off: a single box that forces you to chain every skill you just learned. Here is the approach I’d take, in order:

  1. Scan. nmap -sC -sV <target-ip> to map open ports and identify services.
  2. Enumerate the web root. gobuster dir -u http://<target-ip> \ -w /usr/share/wordlists/dirbuster/directory-list-lowercase-2.3-medium.txt
  3. Recurse into the hidden directory you find, enumerating it the same way this is the step people miss.
  4. Recover credentials. Inside, you’ll find a username and a hashed password. Crack the hash with Hashcat, John, or an online lookup (Section 4).
  5. Log in and grab the user flag: cd ~ ls cat user.txt
  6. Escalate and grab root. On this box the escalation needs no password, so: sudo su cd ~ cat root.txt

Notice how the exam mirrors a real engagement in miniature: recon → web enumeration → credential attack → foothold → privilege escalation. That flow is the whole reason the room exists, and once it feels automatic you’re ready for harder targets.

I’ve deliberately kept the actual flag values out of this post. Reading them here defeats the purpose and, frankly, it’s what separates people who learn from people who just tick a box. If you get stuck on a specific step, the section videos below show each one end to end.

Conclusion

That completes the TryHackMe CC: Pen Testing room. You’ve now touched every core stage of a penetration test reconnaissance with Nmap and Netcat, web enumeration with Gobuster and Nikto, exploitation through Metasploit, credential attacks with Hashcat and John, injection with sqlmap, and SMB enumeration with smbmap and smbclient and you’ve chained them in a CTF that behaves like a real, if small, engagement. That breadth is the foundation everything else is built on.

The natural next step is to go deeper on whichever stage you enjoyed most. My TryHackMe roadmap orders the next rooms so your skills compound in the right sequence instead of leaving gaps. Work through it steadily, keep taking notes, and stay strictly inside authorised labs – that’s how you turn a crash course into a career.

Frequently Asked Questions

Is the CC: Pen Testing room free?

Yes. It’s a free TryHackMe room aimed at beginners; you only need a free account to start it.

Is CC: Pen Testing good for beginners?

It’s one of the better first “penetration testing” rooms because it’s a crash course broad and guided rather than deep so you meet every core tool once before specialising.

How long does CC: Pen Testing take?

Most beginners finish in three to five hours across a couple of sittings. Don’t rush the final exam; treat it as a real box and let it take the time it takes.

Do I need Kali Linux for this room?

No. TryHackMe’s browser-based AttackBox has all the tools pre-installed. Kali or Parrot over OpenVPN works too if you prefer your own machine.

Is it legal to run these tools?

Only against systems you own or are authorised to test. TryHackMe rooms are sandboxed labs you’re explicitly permitted to attack – that’s what makes this practice legal.

Mehmood Ali

I am a Cybersecurity Consultant with over 8+ years of experience in SOC analyst, digital forensics, cloud security, network security, and incident response. With 20+ international certifications, I have successfully designed secure systems, led vulnerability assessments, and delivered key security projects. I am skilled at improving incident response times, mitigating threats, and ensuring compliance with ISO 27001 standards.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button