TheStickerShop Walkthrough
Today we are solving another easy-rated TryHackMe machine called TheStickerShop.
189 entries tagged “Thm”. Browse all tags
Today we are solving another easy-rated TryHackMe machine called TheStickerShop.
Today we are solving another Linux-based TryHackMe machine called Oh My WebServer. This machine focuses on exploiting vulnerable web services, container breakout-style enumeration,
Today we are investigating another TryHackMe Defensive Security challenge where we are provided with Windows event logs that have already been ingested into Splunk.
Today we are solving another Defensive Security challenge from TryHackMe called Carnage. In this challenge we are provided with a packet capture (PCAP) file from a real-world malwa
Today we are solving another TryHackMe machine called Break Out The Cage, a Linux-based challenge inspired by Nicolas Cage. The machine contains multiple stages including anonymous
The infamous cosmic hacker Super-spam has returned. Originating from the planet Alpha Solaris IV, Super-spam's mission is to eliminate Linux systems across the galaxy and replace t
This challenge focuses on bypassing PHP security restrictions, specifically the disablefunctions directive commonly configured in hardened PHP environments.
Today we are solving another TryHackMe machine named TechSupport.
One of the employees at Lockman Group reported that all of his files had suddenly been renamed with an unfamiliar extension. After a quick inspection, the IT department suspected r
We are working as a SOC Analyst for an MSSP called TryNotHackMe.
We are presented with a Linux machine that heavily relies on automation pipelines.
Today we are solving another TryHackMe machine named DevelPy.
Today we solved a very easy TryHackMe challenge focused on IDOR (Insecure Direct Object Reference).
Today we are investigating a ransomware incident involving Conti Ransomware, one of the most notorious Ransomware-as-a-Service (RaaS) operations.
It is a Friday evening at PandaProbe Intelligence when SwiftSpend Finance submits an urgent threat intelligence request.
The FTP server contained no useful files.
Based on threat intelligence reports, an APT group known as IronShade has been actively targeting Linux servers across the region.
As usual, we begin with a full port scan to identify exposed services.
Operation ColdStart is an easy Linux-based machine where our objective is to compromise the target, gain user access, and ultimately escalate privileges to root.
Years after leaving the hacking scene, a retired hacker has unintentionally left traces of his identity scattered across the public internet.
During routine SOC monitoring, Analyst John observed an IDS alert indicating potential Command and Control (C2) communication originating from a user named Browne in the HR departm
Additional HTTP service on a high port.
You are up for promotion at Hadron Security. Your senior lead, Mara, has handed you a solo engagement against RecruitCorp, a small recruiting firm with a public-facing portal.
The room provides the following information:.
Only SSH and HTTP are exposed.
Swiftspend Finance, a fintech company, has recently deployed Wazuh and Sysmon to strengthen endpoint monitoring and improve threat detection capabilities.
At this point, web enumeration becomes the primary attack path.
Dreaming is a Linux-based machine that focuses on web enumeration, CMS assessment, credential discovery, database abuse, and privilege escalation through insecure permissions and s
Madness - an easy TryHackMe walkthrough with full steps and screenshots.
Goal: Run a phishing page, send a convincing email with SET, harvest creds, then check if those creds are reused on the email portal to find the toys count.
In this challenge, we investigate suspicious activity on tbfc-web01, a Linux server responsible for processing Christmas wishlists. McSkidy, who left behind a cryptic trail of clue
This room introduces fundamental concepts in Large Language Model (LLM) security, specifically focusing on input manipulation and prompt injection attacks. Unlike traditional softw
Living Off the Land (LoL) attacks represent a sophisticated attack methodology where adversaries leverage pre-installed, legitimate Windows utilities instead of deploying custom ma
The Elevating Movement room simulates a post-compromise forensic investigation at DeceptiTech following a network collapse. This scenario focuses on the second attack stage where a
This writeup mirrors exactly what was done, showing each command, page interaction, and how the tester progressed from a visitor to root. Follow along to see how each flag was obta
Welcome to an in‑depth walkthrough of TryHackMe's Linux Threat Detection 1 room. This document mirrors the hands‑on investigation steps used to detect Linux attacks via log analysi
When I began this room, I reminded myself of one important truth:.
Linux is everywhere---from traditional servers to cloud-native.
In the bustling digital bazaar of Valoria, every merchant’s stall is a web application, and every traveler’s purse is a user account. Few notice the tiny cracks between wooden boar
Goal: Learn where the SOC sits in an organization, what Blue Team does, how SOC roles are structured, and how a SOC L1 analyst can advance their career. The room mixes conceptual k
This room is designed to simulate the kind of real-world investigation SOC teams conduct when faced with potential intrusions. It combines file analysis, malware family identificat
Welcome to the thrilling crossover of Application Security (AppSec) and Incident Response (IR)! In this room, we explored how attackers target applications, how security teams resp
Web Security Essentials is a foundational TryHackMe room that introduces cybersecurity professionals to the multi-layered defense approach required for modern web application secur
In this epic cyber-voyage, we’ll exploit Joomla!’s gossiping API, sneak into a container using a stolen map (aka credentials), conjure dark magic with Python pickle, and finally un
The TryFlufMe (TFM) team called me in. Something wasn’t right.
The Security Footage challenge involves analyzing a network capture file (.pcap) to recover a lost security camera feed. The goal is to extract the video from the packet capture an
This introductory room teaches the foundational concepts and ethical framework behind penetration testing (“pentesting”). You’ll learn what pentesting is, the importance of ethics
In this beginner-friendly room, you're introduced to Offensive Security and get hands-on experience hacking a simulated web application—FakeBank—using the directory brute-forcing t
Once upon a time in SOC land, I was handed the keys to a dashboard glowing red with alerts. My mission? Classify malware like a true cyber-detective and prove my worth. Spoiler: it
Focus: Role overview, triage mindset, quick alert investigation, escalation, containment.
Endpoint Detection and Response (EDR) extends beyond traditional antivirus by providing continuous endpoint telemetry, behavioral and anomaly detection, IOC-based matching, ATT&CK
File and Hash Threat Intel is a beginner-friendly blue team challenge on TryHackMe designed for SOC analysts and cybersecurity learners. This room teaches practical skills in malwa
The Extract room is TryHackMe's premium hard-level challenge that transforms you from a casual web surfer into a digital archaeologist, extracting secrets from digital libraries li
This room introduces the fundamentals of Defensive Security, also called Blue Team operations, focusing on safeguarding and monitoring networks and systems. You'll explore concepts
Directly fetch the Squid password file once discovered.
sudo apt install -y php-cli php-curl curl.
This ensures that requests to contrabando.thm resolve correctly.
Learn foundational concepts of Artificial Intelligence and Machine Learning.
and a css file...that we might as well check and oh...
weirdest book I ever read as a kid and even more as an adult.
It is guided so We wont talk much.
Welcome to your first lecture! if you wanna graduate from vulnversity you need to know some basics. Take a seat!
we visit the website (port 80 and 32768 look identical).
Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause.
I have been very busy this year and could not play much but decided to give a shot to.
A cool Osint room, and we love osint.
That room is self-explanatory...its a big no sht sherlock.
My very first ctf in the theme of one of my favorites cartoon.
the password is in the "strings" (you know what to do).
the Evil within...a videogame classic! I like this theme already!
Your machine IP is 10.10.148.206 (yours will differ).
I wanna be the very best...LIKE NO ONE EVER WAS!
If you started to learn web exploitation recently you might have heard about them.
We obviously grab the backup files.
we are provided with a PCAP file...wireshark read those better.
It's been a while I didn't play a CTF on TryHackMe. While searching for a fun room I found one named "One Piece".
After visiting the website we get a weird page with "elements".
First flag is in ftp .secret folder.
WTF is all those open ports? This scan took me a bit...
find/grep filesystem enumeration plus John cracking of GPG-encrypted files and hashes harvests reused credentials for lateral movement across users, then unrestricted sudo grants root.
Ha! the author is an arrowverse fan. cool!
Website and ssh that's a minimmum.
Welcome to SweetRice - Thank your for install SweetRice as your website management system.
Seems like there will be prototype pollution involved?
SMB1 disabled -- no workgroup available.
stack smashing detected : <unknown> terminated.
Now there is some obvious command injection.
windows machines are less frequent thus my favorites.
A nice room that try to be realistic about web exploitation.
We are usually on the red side, trying to hack machines.
we can dump the repo using git tools (dumper).
Heh another ctf in the gaming theme...looks like a RPG.
Ok this one was easy so speedrun!
The port 8021 got a weird service running.
fuzzing show a simple page with 301 code...we visited and got a simple page made with cms made simple (CMSMS).
gobuster show only a forbidden cats directory (there might be dogs too).
This is a binary exploitation challenge with a buffer overflow vulnerabily.
I know I may not be ready yet but I want to see how hard things can get irl.
Yeah this one is just base 64, please do not make a fool of yourself and just decode it.
This is a guided room as it seems so I wont say much here.
Guess the CMS! lol lets check the hidden dir first.
With visual-analyser add a spectrogram layer and get this qr code.
This room says capture the flag but its actually more a challenges room.
Buffer Overflow Prep - an easy TryHackMe walkthrough with full steps and screenshots.
Haha a comedy classic. ok ftp first.
Cool a ctf in the theme of cowboy bebop.
This is actually one of my favorites rooms.
And because it is wordpress (It could not be more obvious).
It is a guided ctf. A basic introduction to classic pentesting (simplified).
classic go grab those ftp files (note.txt and idrsa).
OpenSSL> sclient -connect 10.10.19.11:54321 -cert certificate -key privatekey.
they say its an easy windows room for beginners.
I like the concept of this machine alot. many ways to exploit.
Oh boy it's christmas soon and tryhackme is bein awesome again!
Lol so many rabbit holes I fell into...
In this task, you will learn about:.
By finishing today’s task, you will learn about:.
Microservices architecture was adopted by companies like Netflix, which is a perfect example of the hypothetical company discussed above. Their need to scale up services dedicated
Reverse Engineering (RE) is the process of breaking something down to understand its function. In cyber security, reverse engineering is used to analyse how applications (binaries)
Before we dig deeper into Mayor Malware's intentions, we must learn a few essential things about C2 communication. Command and Control (C2) Infrastructure are a set of programs use
Even while penetration testing is becoming increasingly popular, game hacking only makes up a small portion of the larger cyber security field. With its 2023 revenue reaching appro
Artificial Intelligence (AI) is all the hype nowadays. Humans have been making machines to make their lives easier for a long time now. However, most machines have been mechanical
The two datasets are as follows:.
Azure is a CSP (Cloud Service Provider), and CSPs (others include Google Cloud and AWS) provide computing resources such as computing power on demand in a highly scalable fashion.
Before diving into Active Directory, let us understand how network infrastructures can be mapped out and ensure that access to resources is well managed. This is typically done thr
In today's task you will learn about:.
WebSockets let your browser and the server keep a constant line of communication open. Unlike the old-school method of asking for something, getting a response, and then hanging up
Conventional web applications are relatively easy to understand, identify, and exploit. If there is an issue in the code of the web application, we can force the web application to
Wi-Fi is the technology that connects our devices to the global network, the Internet.
Security is as strong as the weakest link. Many would argue that humans are the weakest link in the security chain. Is it easier to exploit a patched system behind a firewall or to
Governance, Risk, and Compliance (GRC) plays a crucial role in any organisation to ensure that their security practices align with their personal, regulatory, and legal obligations
Let's learn how to generate a shellcode to see what it looks like. To do this, we will use a tool called msfvenom to get a reverse shell.
To tackle file upload challenges, begin by examining the website to identify its technology and potential attack vectors (e.g. upload pages), using tools like Wappalyzer or Burpsui
Get a Reverse shell by uploading a PHP file via FTP and run it through the web page.
Use the credentials to login to the target via the open RDP Port 3389.
K33p5 y0ur ju1cy 5plu773r 70 y0ur53lf!
A new field of forensics (the science of crime investigations) called digital forensics was born to examine crimes involving the usage of digital technologies like:.
Cyber Threat Intelligence - an easy TryHackMe walkthrough with full steps and screenshots.
Input a command to get a reverse shell.
Once logged in, the Bolt version is at the bottom of the page.
Run hhupd.exe to exploit the privilege escalation vulnerability present in the Windows Certificate Dialog box, a bug in the UAC mechanism.
Similar to the previous Phishing challenges, but with the addition of a good AntiVirus which can detect the msfvenom exe payload.
Going through the files, we understand that the binary reads shellcode from the user and executes it.
Firstly, let's configure our AWS CLI.
Same as before, we can first get the assembly code from the executable. (Or use Ghidra).
Going through the given .pcapng file, we can see that they have some sort of Blind SQL injection and the requests are URL encoded.
Firstly, we can assume ROOT since we can do sudo su.
This one is similar to the Ghost Phishing Challenge, but this time we have to attach a Windows Executable.
We find that there is a D-link Router. We can try logging into the admin portal.
Heading over to the site, we can view the contract's source code.
Since the challenge talks about a web application vulnerability, we can directly head to the website's directory to look for suspicious files.
Once again, we visit the site and view the Solidity source code.
Opening the link and logging in with the given credentials, we see that there's an email asking for a "Detailed Report".
Analyzing the given code, we see that the login() function calls the printflag() function upon successful login.
This challenge shows an "AI Command Executor" which modifies the user input and executes the commands.
Then we can check the given S3 bucket. It contains a file, which we can download and view.
We are provided with a Local Security Authority Subsystem Service (LSASS) dump, which contains all the hashes of all the users.
It's been given that the encryption is done using a repeating-key XOR cipher and that the message always starts with "ORDER".
We have a .pcapng which shows us the packets transmitted when the NFS server was infiltrated.
First, we check the file type.
The given code contains the public key components n and e and the RSA-encrypted ciphertext c.
Going throught the code, we can see that it shifts each character of the plaintext by its position in the message.
Care4Wares' infrastructure runs in the cloud, so they chose AWS as their Cloud Service Provider (CSP). Instead of their workloads running on physical machines on-premises, they run
A sandbox is an isolated environment where (malicious) code is executed without affecting anything outside the system. Often, multiple tools are installed to monitor, record, and a
XML is a commonly used method to transport and store data in a structured format that humans and machines can easily understand. Consider a scenario where two computers need to com
While it might be the utopian dream of every blue teamer, we will rarely be able to detect every attack or step in an attack kill chain. There are gaps in detection. But worry not!
In this room, you will be handed over two VMs, Linux and Windows, and your task will be to install Splunk on both machines.
In this section of the lesson, we will take a look at what tools and knowledge is required for the blue segment, that is the investigation of the attack itself using tools which en
In a SOC, events from different devices are sent to the SIEM, which is the single source of truth where all the information and events are aggregated. Certain rules are defined to
The website we are investigating is a YouTube to MP3 converter currently being shared amongst the organizers of SOC-mas. You've decided to dig deeper after hearing some concerning
RustScan: Where scanning meets swagging. 😎.
Let's do a little bit more of a vuln scan to view more information on that host machine.
Powershell is the Windows Scripting Language and shell environment built using the .NET framework. Most Powershell commands, called cmdlets, are written in .NET. Unlike other scrip
From the enumeration gathered I found two services running and two different protocols.
Scan the machine, how many ports are open?
http on port 80, running on Apache httpd 2.4.29.
Please stop leaving notes randomly on the website.
Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn.
How you redirect yourself to a secret page.
Interesting ports found to be open:.
Interesting ports found to be open:.
boy...that meme feels so old now.
Interesting ports found to be open:.
Interesting ports found to be open:.
Interesting ports found to be open:.
This is not a Capture The Flag. It's a room that has several hashes to be cracked. Description of the room:.
Interesting ports found to be open:.
Interesting ports found to be open:.
Interesting ports found to be open:.
Type to search · / or Ctrl+K to open · ↑↓ to move · Enter to open · Esc to close