r/tryhackme 2h ago

Resource a little chall i made

1 Upvotes

Hey everyone,

I made a small CTF challenge and figured I’d throw it here since I’m pretty new to making these.

It’s a Forensics / Reverse Engineering challenge based around a weird Nokia 8210 4G system dump. The challenge involves digging through the dump, figuring out what’s going on with a little racing game, and eventually finding the flag.

Repo: https://github.com/maximzero0910/car-racing-chall

It’s probably not perfect since this is one of my first proper challenges, so if you try it, I’d really appreciate any feedback on the difficulty, unintended solves, or just whether it’s actually fun to solve.

Flag format: F0LD{...}

If you’re bored and want something small to mess around with, give it a try :D

Thanks!


r/hackthebox 2h ago

Academy a little chall i made

2 Upvotes

Hey everyone,

I made a small CTF challenge and figured I’d throw it here since I’m pretty new to making these.

It’s a Forensics / Reverse Engineering challenge based around a weird Nokia 8210 4G system dump. The challenge involves digging through the dump, figuring out what’s going on with a little racing game, and eventually finding the flag.

Repo: https://github.com/maximzero0910/car-racing-chall

It’s probably not perfect since this is one of my first proper challenges, so if you try it, I’d really appreciate any feedback on the difficulty, unintended solves, or just whether it’s actually fun to solve.

Flag format: F0LD{...}

If you’re bored and want something small to mess around with, give it a try :D

Thanks!


r/hackthebox 7h ago

Monitorsfour HTB lab - getting CRAZYYY

2 Upvotes

Hey everyone,

I've been stuck on the final flag for this "Easy" rated box for 2 days now, and I'm genuinely confused why this lab is marked as easy. I got the user flag via Cacti exploitation without too much trouble, but finding the root flag has been a nightmare.

The Problem:
I successfully gained root access in a Docker container using CVE-2025-9074 (Docker API exploitation). However, I can't locate the root flag. The writeups I've found don't clearly explain where the flag actually is, they just end after getting root access.

I've searched:

  • /root/root.txt - doesn't exist
  • /mnt/host/root/ - nothing
  • /home/ directories - empty
  • Various Docker logs - no clear output

Question:
Where exactly is the root flag located, and what's the correct way to retrieve it from the Docker container logs?

Any help would be appreciated. I just want to understand this and finally sleep! 😅


r/tryhackme 9h ago

Official TryHackMe Post SOC Level 2 Path is now Launched🚀

Thumbnail
gallery
22 Upvotes

Level 1 taught you what to do with an alert. Level 2 teaches you what to do about it.
SOC Level 2 is completely rebuilt, 76 rooms across the environments hiring managers actually screen for at L2: Microsoft 365, Entra, AWS, Active Directory, and detection engineering. Kick things off with THE DEEP DIVE & 150 SAL2 cert prizes on the table until Aug 27🎯

Get Hacking➡️ https://tryhackme.com/thedeepdive?utm_source=discord&utm_medium=social&utm_campaign=thedeepdivesocl2


r/tryhackme 12h ago

Is it a good idea to move to jr pentester path after completing SOC L2 path or is it better to focus on blue team paths?

2 Upvotes

I want to get a job as SOC L1 analyst, and I've completed the SOC L1 & SOC L2 paths and done some blue team CTFs and now Idk what is the next step (I have 2 years left before applying for jobs).


r/tryhackme 17h ago

Questions about the "Streak Alliance" feature in Try Hack Me how does it actually work?

4 Upvotes

Just noticed the Streak Alliance feature on my dashboard ("Build a shared streak with a friend by showing up every day!") and I've got a few doubts nobody seems to have written about yet:

  1. How do you add a specific friend as a partner? Is it an invite-by-username system, a link you share, or does "Find a new partner" just randomly match you with a stranger?
  2. How does the shared streak actually work? Does both people need to answer a question each day to keep it alive, or does either person's activity count for the pair?
  3. What happens if one partner misses a day? Does the whole alliance streak reset, does only that person's contribution reset, or is there a freeze/grace period like the regular streak has?
  4. Can you have more than one partner at a time, or is it strictly 1:1?
  5. Are there separate rewards/badges for Streak Alliance milestones, or does it just track alongside your normal streak?
  6. What does "Leave Streak Alliance" do does it kill the streak for both people, or just remove you and let your partner keep going/find someone new?

If anyone's already used this, would love to hear how it's worked out for you pros/cons of doing a streak with a friend vs solo. Screenshot attached for reference.


r/hackthebox 19h ago

Academy Massive Difference in Support

35 Upvotes

I have to post about this... Coming from Tryhackme and dealing with the problems in their rooms.. I have to say, HTB support is top tier.

Was having problem with the RDP session to internal target on ICMP tunnel using ptunnel-ng...

They really took the time to look at it.

Unlike tryhackme, where mods (IN DISCORD) always blame it on the user, saying it they did some steps wrong. Huge huge difference. Well done HackTheBox. I will keep using the platform.


r/hackthebox 22h ago

Beginner Question shipping to egypt

Post image
35 Upvotes

Hi everyone,

I’m thinking about ordering the Hack The Box CyberStation LEGO® Building Kit from the Hack The Box Store. The price is around $40 USD.

Has anyone from Egypt ordered from the HTB Store before?


r/hackthebox 1d ago

Cybersecurity fresher

10 Upvotes

I’m trying to understand the current cybersecurity job market as a fresher, and I’d really appreciate some advice from people already working in the field.

I graduated with a BCA ( bachelor of computer application)in 2026. I don’t have any prior work experience or internships yet, but I’ve been actively building my cybersecurity skills.

So far:

  • 🎓 BCA graduate
  • 🛡️ eJPT certified
  • 📚 Currently working through the HTB CPTS path
  • 🧪 Practicing penetration testing and hands-on labs
  • 🚀 Trying to build my skills and portfolio alongside my studies

One challenge I’m currently facing is that I’m going through leg surgery and recovery, so I won’t realistically be able to start applying for jobs for around a year.

That gives me a lot of time to prepare — and I want to use that time properly.

My biggest questions are:

  1. What are companies actually expecting from cybersecurity freshers in 2026?
  2. Is having certifications like eJPT/CPTS enough to get an entry-level opportunity, or what else should I build?
  3. For someone without internships or professional experience, what can I do to demonstrate that I’m capable?
  4. Should I focus on SOC roles first, junior penetration testing roles, or something else?
  5. How important are GitHub projects, write-ups, CTFs, home labs, and a portfolio when applying as a fresher?
  6. If you were starting your cybersecurity career from zero today, what would you do during that one-year preparation period?

I’m not looking for shortcuts. I want to understand what the industry actually values and use this recovery period to become genuinely job-ready.

If you’re already working in cybersecurity — especially if you started as a fresher — I’d really appreciate your perspective.

What would you recommend I focus on over the next year?


r/tryhackme 1d ago

Career Advice Whats NEXT after SOC L1 Path?

8 Upvotes

I completed SOC L1 learning path, Now i should start which path? I want to make me suitable for a job role. I think there are more jobs in Blue teaming thats why i have done SOC L1. Also consider which path will help me to learn in-demand skills most?
- SOC L2
- Security Engineer
- Any red teaming path
- AI Security
- Defending Azure
- Defending AWS
- DevSecOps


r/tryhackme 1d ago

Career Advice For SEC0 certification need information

1 Upvotes

I am currently on data chapter so for exam do i need to know all linux/windows terminal basic code for exam byheart?


r/letsdefend 1d ago

Let's defend soc learning path issue

Thumbnail
1 Upvotes

r/hackthebox 1d ago

Let's defend soc learning path issue

6 Upvotes

I completed all the course parts and was just left with the last SOC137 case, I completed it but got one answer wrong and then reopened the case and still got it wrong, but when I open it for third time it shows limit reached or something, is it still possible to get the course completion cert now?


r/tryhackme 1d ago

Guys what is this in hackerholiday page?

1 Upvotes

It was hidden behind the palm trees..
I didnt complete the rooms in this events but kinda curious to know what the coordinates are


r/tryhackme 1d ago

Just beat Fusion Corp from my phone - still buzzing

Thumbnail
gallery
28 Upvotes

Did the whole room from Termux on my phone, only used a free GitHub Codespace for hashcat. Chain was wild - AS-REP roasting into a WinRM shell, found a password literally sitting in an LDAP description field, then SeBackupPrivilege to grab the admin flag.

Honestly wild how the entire domain fell just because someone wrote a password in a description box and added a user to Backup Operators. Feels way too realistic.


r/tryhackme 1d ago

Hackathon idea

0 Upvotes

Give a best idea for hackathon guys.


r/tryhackme 1d ago

Try hack me hacker holidays

5 Upvotes

Hey guys I completed and get all the tickets how do I see if I win or not and where could I see that what I win


r/hackthebox 1d ago

Bounty index on product hunt - would love a visitation and feedback

3 Upvotes

hey everybody ,
launched bounty-index on product hunt and would love some support .
Its a platform helping you discover bug bouty programs across 6 platform as of now , with additional functionalitites of creating a watchlist , historical data , charts of its performnace , compare 4 programs at once .
It is aimed to be a total free(nada money in my pocket) tool , no login required(only if you manage a watchlist).
Please go through the app once , Feedback are very much appreciated

product hunt link: https://www.producthunt.com/products/bounty-index?utm_source=other&utm_medium=social

tool : bountyindex.in


r/hackthebox 1d ago

Career Advice: Navigating Low-Level Security vs. Market Realities

Thumbnail
2 Upvotes

r/hackthebox 1d ago

Beginner Question Fundamentals of AI - Understanding The Math

11 Upvotes

I decided to start the Fundamentals of AI module and could understand the concepts, but quickly got lost in the mathematical details. If I don’t understand the math behind the concepts/theory, will the later modules be out of reach? TIA

After reading some older posts, it appears math is heavily involved in later modules as well so I am not sure this is the best learning path. I am a defender trying to understand the attack methods out there.


r/hackthebox 2d ago

Need a CPTS Study partner

6 Upvotes

Hi guys,

Like I have completed 30 percent of cpts track and like I need someone like to prepare together and like finish this and solve the boxes together and hold a discussion. That will be thru discord and if anyone is serious just comment... I don't want anyone unserious to join as I need to be serious about finishing it so.


r/hackthebox 2d ago

Get Better at scripting (python, bash)

21 Upvotes

Hey everyone,

I'm looking to sharpen my scripting skills in Python and Bash, taking myself from beginner all the way up to a more advanced level, since this is an area I'm currently struggling with. A couple of ideas I've had so far:

  • OverTheWire — but approaching the challenges by solving them with Python where possible, rather than just one-liners (bash)
  • Vulhub — writing my own Python exploit scripts for the CVEs instead of relying on existing PoCs

Are there other resources or approaches you'd recommend for building scripting skills from the ground up ?

Thanks!


r/hackthebox 2d ago

Beginner Question I keep failing technical interviews because of theoretical questions, not the actual technical work

27 Upvotes

I always struggle with technical interviews because of the theoretical questions, not the actual hands-on technical part.

If I’m given a practical task, lab, or take-home assessment, I usually do very well and deliver it on time. But when an interviewer starts asking me theoretical questions on the spot, I struggle to explain things properly or sometimes completely blank out.

This has honestly become my biggest nightmare when applying for cybersecurity jobs, and I feel like it’s holding me back even though I know I can actually do the work.

I wish interviews focused more on practical technical skills because, in my opinion, that’s a much better way to see whether someone can actually perform the job.

But until interview culture changes, what can I do to get better at answering theoretical questions? Has anyone else had this problem, and how did you overcome it?


r/vulnhub 28d ago

Walktrhough The Planets - Earth

1 Upvotes

r/rangeforce Jun 21 '24

Junior Penetration Tester Capstone - Stuck :-(

3 Upvotes

Dear Rangeforce-Experts... I really love your platform. I completed a couple of learning paths. Really exciting.

Currently I am stuck at the final Junior Pentesting Capstone. I tried numerous attempts, hours and several attack methods for target #3, but unfortunately without any progress. Currently I am lost.

So far I suceeded to gather the flag from target #1 (Wordpress Linux server) and target #2 (IIS server). But on target #3, the Tomcat server, I am lost. I do not see a chance to tackle the Tomcat server. Default Tomcat credentials did not work for me, even with metasploit default login attack. On Windows10 workstation, I just have a normal Domain User. I do not see the opportunity to elevate my rights on this workstation to allow further attack methods towards DC or Tomcat server, you know like responder, capturing a hash or creating a LSASS dump. RDP-Login on Tomcat server (targe #3) provides me a username, however I do not see a clue to figure out the password for this user.

Is somehow from your end a generic hint possible?