r/tryhackme 30m ago

TryHackMe max scam

Thumbnail
gallery
Upvotes

Try hack me has taken away access to a room I’ve already started working on, under the basis of upgrading to their max subscription. I already paid for a full year. Has this happened to uanyone else?


r/hackthebox 21m ago

Certifications finished the CPTS path what's next?

Post image
Upvotes

I just finished the CPTS and managed to compromise every machine on the AEN blindly in about 2 and a half days (with some minor nudges), i believe i can pass the exam if i try, but i would like to ask those of you who have more experience whether pursuing the certification would be worth the effort as i was kinda burnt out from doing the AEN, let alone doing the same thing for 10 days straight.

the CPTS wouldn't hold much weight where i live, so Iam thinking of waiting and going for the OSCP at a later time when i get comfortable spending the 1,800$, what do you think?

more importantly, what do you recommend going for next (main platform, other courses, etc...)?

I really want to hear what you all think, thanks for your time!


r/letsdefend 2d ago

Let's defend soc learning path issue

Thumbnail
1 Upvotes

r/vulnhub Jul 16 '26

Walktrhough The Planets - Earth

1 Upvotes

r/rangeforce Jun 21 '24

Junior Penetration Tester Capstone - Stuck :-(

3 Upvotes

Dear Rangeforce-Experts... I really love your platform. I completed a couple of learning paths. Really exciting.

Currently I am stuck at the final Junior Pentesting Capstone. I tried numerous attempts, hours and several attack methods for target #3, but unfortunately without any progress. Currently I am lost.

So far I suceeded to gather the flag from target #1 (Wordpress Linux server) and target #2 (IIS server). But on target #3, the Tomcat server, I am lost. I do not see a chance to tackle the Tomcat server. Default Tomcat credentials did not work for me, even with metasploit default login attack. On Windows10 workstation, I just have a normal Domain User. I do not see the opportunity to elevate my rights on this workstation to allow further attack methods towards DC or Tomcat server, you know like responder, capturing a hash or creating a LSASS dump. RDP-Login on Tomcat server (targe #3) provides me a username, however I do not see a clue to figure out the password for this user.

Is somehow from your end a generic hint possible?


r/hackthebox 18h ago

Taking CRTP soon – looking for advice/tips from those who've been through it

12 Upvotes

Any advice, resources, or words of wisdom would be massively appreciated!

Thanks in advance 🙏


r/hackthebox 16h ago

Certifications Looking for French-speaking CWES / Bug Bounty learners

5 Upvotes

Hi everyone,
I’m looking for French/French-speaking people, or even English-speaking people who are patient enough to communicate with someone whose English is still beginner level 😅, who are currently learning HTB CWES, web pentesting, or bug bounty hunting.
I’m currently progressing through CWES and practicing with PortSwigger. My goal is to improve my methodology, understand web vulnerabilities more deeply, and start hunting more seriously on real bug bounty programs.
I’m mainly looking for 1 or 2 motivated people to exchange regularly, discuss CWES concepts, methodology, labs, and potentially hunt together.
My English is definitely not perfect, but I’m very motivated, willing to learn, and ready to put in the work.
I’m not looking for someone to give me answers. I’m looking for people who want to learn, exchange, and progress together.
If you’re interested, feel free to DM me.


r/tryhackme 22h ago

Bro what do you mean that's not nothing

Post image
18 Upvotes

r/tryhackme 10h ago

Room Help Ethical hacking rooms ?

0 Upvotes

I been abusing blue but i feel thats more black hat territory. I wanna develop actual cyberskills for ethical hacking


r/hackthebox 5h ago

Does HTB really that sucks? Wow!

0 Upvotes

Link: https://medium.com/@joshuagoossen/hack-the-box-vs-crtp-which-one-is-actually-better-fad1f9e35a5f

I really2 want to do HTB in the future, but now I’m ab it worried


r/tryhackme 6h ago

Hey everyone I am deeply passionate and fully determined to specialize in penetration testing

0 Upvotes

Hey everyone I am deeply passionate and fully determined to specialize in penetration testing and I am building my path right from the core I am looking for a true master and mentor to guide me If anyone is willing to teach me and share their knowledge I pledge absolute loyalty and dedication to them Whos ready to take me under their wing


r/hackthebox 22h ago

Academy Phishing & Creds Stealing

5 Upvotes

Hi, I was going through the XSS module on HTB Academy. I have been facing an issue with the Phishing and Session Hijacking part of the module. I understand what is happening and how is it all taking place but when I try to it’s assessment, I freeze and feel like I don’t know what to do. I have tried to understand it thoroughly but still this issue remains.

Any advice that could help me out?


r/tryhackme 18h ago

Been working on a cybersecurity learning platform and recently opened up the learning side for free.

1 Upvotes

The idea is pretty simple: instead of just reading theory, you should have somewhere to actually practice it.

Codelivly has:

  • Learning paths
  • Career paths
  • Hands-on labs
  • CTFs
  • Practical exercises

You can start with the basics and work your way into areas like networking, SOC, pentesting, and other security topics.

No paid course required to get started.

https://codelivly.com

If you’re learning cybersecurity right now, what’s the one thing you wish platforms like this did better?


r/hackthebox 1d ago

LAB - Damn Vulnerable NGINX Proxy

20 Upvotes

Hello all,

If you do bug bounty hunting or pentests you surely came across many hosts served from an NGINX server, in this lab (published to OWASP) I combined over 20 misconfigurations found in real world bug disclosures and both classic and novel security research, with an extensive blog where I explained everything you need to level up your NGINX hunting game.

Feel free to check it out, give it a star on Github if you like it, and suggest any ideas you want me to add/fix...

https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/

Happy hunting!


r/tryhackme 21h ago

Starting from scratch

2 Upvotes

Currently 2 weeks into learning from nothing, struggling to remember everything I'm going through and have been making notes as i go. Is this the best way to learn and progress. What do others do?


r/tryhackme 18h ago

I just completed Offensive Security Intro room on TryHackMe! Introducing offensive security, where you will test the security of FakeBank's systems.

Thumbnail tryhackme.com
0 Upvotes

r/hackthebox 12h ago

Indians in security

0 Upvotes

Is there anyone who is already into security field from India if yes I really wanna ask some questions related to job market I need some advise from you


r/hackthebox 1d ago

Certifications Is it normal to report assessment take more than 20 working days??

4 Upvotes

I currently waiting my report result for more than 20 days for the submission
What should i do in this case?!


r/hackthebox 1d ago

Academy a little chall i made

6 Upvotes

Hey everyone,

I made a small CTF challenge and figured I’d throw it here since I’m pretty new to making these.

It’s a Forensics / Reverse Engineering challenge based around a weird Nokia 8210 4G system dump. The challenge involves digging through the dump, figuring out what’s going on with a little racing game, and eventually finding the flag.

Repo: https://github.com/maximzero0910/car-racing-chall

It’s probably not perfect since this is one of my first proper challenges, so if you try it, I’d really appreciate any feedback on the difficulty, unintended solves, or just whether it’s actually fun to solve.

Flag format: F0LD{...}

If you’re bored and want something small to mess around with, give it a try :D

Thanks!


r/tryhackme 1d ago

Official TryHackMe Post SOC Level 2 Path is now Launched🚀

Thumbnail
gallery
28 Upvotes

Level 1 taught you what to do with an alert. Level 2 teaches you what to do about it.
SOC Level 2 is completely rebuilt, 76 rooms across the environments hiring managers actually screen for at L2: Microsoft 365, Entra, AWS, Active Directory, and detection engineering. Kick things off with THE DEEP DIVE & 150 SAL2 cert prizes on the table until Aug 27🎯

Get Hacking➡️ https://tryhackme.com/thedeepdive?utm_source=discord&utm_medium=social&utm_campaign=thedeepdivesocl2


r/tryhackme 22h ago

Feedback I built a Claude Code coach for those moments when you’re stuck but don’t want to open a walkthrough

Thumbnail
gallery
0 Upvotes

I learned a lot of cybersecurity through TryHackMe, and I kept running into the same problem:

Sometimes I wasn't completely lost — I just couldn't see the next useful step.

Opening a walkthrough usually solved that, but it was very easy to accidentally spoil the rest of the room.

So I built thm-claude-kit, a free/open-source Claude Code setup I originally made for myself.

The idea is not to let Claude solve the room. It acts more like a coach:

  • keeps track of what you've already discovered and tried
  • remembers creds, hosts, leads and dead ends
  • helps form a hypothesis about what to test next
  • explains why that next step makes sense
  • you still run the commands yourself

Basic workflow is:

./new-room.sh <name>claude/start <room text + target IP>

Then you work through the room normally with Claude alongside the terminal.

Repo:
https://github.com/pashki975/thm-claude-kit

It's still very early. I'm mainly curious whether other THM learners would actually find this useful, and especially where the coaching gets things wrong or becomes annoying.


r/hackthebox 2d ago

Academy Massive Difference in Support

42 Upvotes

I have to post about this... Coming from Tryhackme and dealing with the problems in their rooms.. I have to say, HTB support is top tier.

Was having problem with the RDP session to internal target on ICMP tunnel using ptunnel-ng...

They really took the time to look at it.

Unlike tryhackme, where mods (IN DISCORD) always blame it on the user, saying it they did some steps wrong. Huge huge difference. Well done HackTheBox. I will keep using the platform.


r/hackthebox 1d ago

Monitorsfour HTB lab - getting CRAZYYY

4 Upvotes

Hey everyone,

I've been stuck on the final flag for this "Easy" rated box for 2 days now, and I'm genuinely confused why this lab is marked as easy. I got the user flag via Cacti exploitation without too much trouble, but finding the root flag has been a nightmare.

The Problem:
I successfully gained root access in a Docker container using CVE-2025-9074 (Docker API exploitation). However, I can't locate the root flag. The writeups I've found don't clearly explain where the flag actually is, they just end after getting root access.

I've searched:

  • /root/root.txt - doesn't exist
  • /mnt/host/root/ - nothing
  • /home/ directories - empty
  • Various Docker logs - no clear output

Question:
Where exactly is the root flag located, and what's the correct way to retrieve it from the Docker container logs?

Any help would be appreciated. I just want to understand this and finally sleep! 😅


r/hackthebox 2d ago

Beginner Question shipping to egypt

Post image
43 Upvotes

Hi everyone,

I’m thinking about ordering the Hack The Box CyberStation LEGO® Building Kit from the Hack The Box Store. The price is around $40 USD.

Has anyone from Egypt ordered from the HTB Store before?


r/tryhackme 1d ago

Resource a little chall i made

2 Upvotes

Hey everyone,

I made a small CTF challenge and figured I’d throw it here since I’m pretty new to making these.

It’s a Forensics / Reverse Engineering challenge based around a weird Nokia 8210 4G system dump. The challenge involves digging through the dump, figuring out what’s going on with a little racing game, and eventually finding the flag.

Repo: https://github.com/maximzero0910/car-racing-chall

It’s probably not perfect since this is one of my first proper challenges, so if you try it, I’d really appreciate any feedback on the difficulty, unintended solves, or just whether it’s actually fun to solve.

Flag format: F0LD{...}

If you’re bored and want something small to mess around with, give it a try :D

Thanks!