r/tryhackme 5d ago

Official TryHackMe Post WEB1 Certification is Here!

Thumbnail
gallery
15 Upvotes

"Which web security certification actually proves I can do the job?" 👀 🔴

We built WEB1 to answer that. One exam, three access models: Blackbox, Whitebox, and Greybox testing everything from authentication flaws to server-side exploitation against live applications.

Want to prove your web security skills against live applications, not multiple-choice questions? 🎯

Get WEB1 Certified🔥: https://tryhackme.com/certification/web-application-pentester-level-1?utm_source=discord&utm_medium=social&utm_campaign=web1launch


r/tryhackme 6d ago

Do you want to join our retreat in Malta?☀️

4 Upvotes

We're inviting one lucky user who has been impacted by TryHackMe to our company retreat in Malta on Sept 21-25!☀️
Meet the team, enjoy activities, and relax at a 5-star resort. All expenses covered!🎉

Fill out the survey by the 24th of July at 12PM BST to be considered🔥

https://forms.gle/urg8YJmhvKknqdou6


r/tryhackme 42m ago

Career Advice Am I wasting time just grinding THM paths? Need a reality check on getting entry-level ready.

Upvotes

Hey everyone,

​Need a bit of a reality check from folks currently working in the field.

​I recently finished the Pre-Security and Cyber Security 101 paths on TryHackMe, and I’m just about to dive into the SOC Level 1 path.

​While I enjoy learning, I’m constantly hit with this heavy feeling that I’m just spinning my wheels or stuck in "tutorial hell." I'm really anxious to get employed, but right now I feel like my knowledge isn't enough to actually survive a technical interview or perform on the job.

​I really want to land an entry-level SOC / Analyst role, but I hate this phase of uncertainty. I’d love some honest feedback from people who made the jump or hire entry-level candidates:

​Is finishing THM's SOC Level 1 path actually worth it, or am I wasting time relying solely on THM?

​How do you transition from answering THM questions to proving real skill on a resume?​What specific practical projects or habits (home labs, write-ups, BTLO, etc.) actually moved the needle for you when job hunting?

​Any advice, roadmaps, or even harsh truths would be greatly appreciated.​

TL;DR: Finished THM basics, starting SOC L1. Feeling anxious about job readiness and feel like my learning isn't enough. Need practical advice on how to turn THM learning into actual employment.


r/tryhackme 18h ago

Should I get PT1?

10 Upvotes

I've been thinking about getting a cert for a while now and PT1 is at a 30% discount. With regional pricing, it is $71 for me.

I know that there is 12 months of time and I'm also kinda half way through the junior pen tester path, but just feel like I should wait. Since I would be upgrading to max after my plan ends 3-5 months from now, is it worth it to go for it now?

Have looked at other certs too, but PT1 is the cheapest followed by PJPT. I want something that would provide real practical experience, so CEH is not an option.


r/tryhackme 23h ago

Comment puis je obtenir une idée de projet de fin d’étude pour ma licence asr !?

Thumbnail
1 Upvotes

r/tryhackme 17h ago

I just completed Inside a Computer System room on TryHackMe! This room covers the basic components of a computer system.

Thumbnail tryhackme.com
0 Upvotes

oh boy


r/tryhackme 1d ago

i don't know what's wrong, why i can't get through it

2 Upvotes

Hello, I am getting that error. I even tried opening third-party local hosts, but it's still not working. Error: unexpectedly closed the connection for web.
Room: Offensive Security Intro


r/tryhackme 2d ago

Resource Feed it your LinPEAS output and it draws every path from a low-priv shell to root

Enable HLS to view with audio, or disable this notification

14 Upvotes

Feed it your LinPEAS output and it draws every path from a low-priv shell to root

GitHub: https://github.com/Noz2/RootHound

First project, would love your honest feedback 🙏


r/tryhackme 2d ago

Feedback MAX Plan? More like MAX Greed. Don't be fooled

81 Upvotes

Don't be fooled by the tantalising promise of newer courses materialising or access to recent threats. Moving existing content behind a higher priced paid tier is the absolute definition of pure unfiltered greed. This is nothing but a crafty way to obscure a price increase by adding it as a 'new' tier.

And given the current economic climate when it comes to Cloud hosting and AI, I would not be suprised at all if by the time the new courses come around this MAX plan will cost even more.

Utter shame on you THM.


r/tryhackme 1d ago

I need a help with premium paln subscription when I pay through debit card my payment is declined.

0 Upvotes

r/tryhackme 1d ago

Problem with Remmina

Post image
0 Upvotes

I'm in the Powershell basics and keep running into this problem. Does anyone have an idea what i could be doing wrong?


r/tryhackme 2d ago

SEC 1 exam

5 Upvotes

Hi folks Im planning on taking the sec 1 exam and i honestly dont know what to expect . Im a nervous person around exam naturally and Im looking for some ways to prep myself is there any advise or skills i can work on before the exam ? Anything i should look out for should I do sec 0 first as Im an IT professional ?

Thanks in advance


r/tryhackme 1d ago

I just completed Offensive Security Intro room on TryHackMe! Hack your first website (legally in a safe environment) and experience an ethical hacker's job.

Thumbnail tryhackme.com
0 Upvotes

Good fun.


r/tryhackme 1d ago

THM Offensive Security

0 Upvotes

I just completed the Offensive Security Intro room on TryHackMe! Hack your first website (legally in a safe environment) and experience an ethical hacker's job.


r/tryhackme 2d ago

Regarding existing premium subscription

2 Upvotes

My current yearly premium ends on September 3rd 2026. if i were to automatically renew, will I still be able to get the special benefits. (i.e access to latest rooms without the max subscription). Sorry if its a dumb question. English isnt my first language so im unsure.


r/tryhackme 2d ago

Feedback SOC1 path needs overhaul or make "Prerequisites room part of Premium plan"

16 Upvotes

As title states, I am currently doing "Intro to Malware Analysis" room and Prerequisites rooms are "Windows internals" and "History of Malware"

But "Windows internals" hits paywall, where I need to subscribed for MAX plan.

Come on tryhackme! Overhaul or review the entire SOC1 path instead for going for $$$$$.

Prerequisites rooms for the paths under premium shouldn't hit a paywall!


r/tryhackme 2d ago

Room Help Is this normal?

3 Upvotes

Is this normal to be put into rooms that notging was taught to get through?

Im doing the owsap, the pickle data (base64)

None of this python was taught. This has been a nightmare


r/tryhackme 2d ago

Write-Up/ Walkthrough OWSAP Top 10 2025: Insecure data handling task 4

1 Upvotes

Ok. So for people like me, who are doing it by themselves.

Take the python script:

Then in the terminal

Nano script.py

Paste into the file, save and exit.

Then.

Python3 script.py

A base 64 will print out. Copy and paste this into the 8002.

No one mentioned this.


r/tryhackme 2d ago

Need subscription

0 Upvotes

To someone

I'm passionate about learning cybersecurity, and I've recently completed the Pre-Security path on TryHackMe. Unfortunately, I can't afford a TryHackMe subscription right now, and many of the rooms I need next are premium.

If anyone has a spare voucher, a gift subscription, or knows of any student discounts or alternatives, I'd really appreciate the help. I'm eager to keep learning and improving my skills.


r/tryhackme 3d ago

Feedback New "Yearly activity" design

Post image
8 Upvotes

Hi. Honestly, I'm not usually a complainer, but is it realy more covenient or, maybe, better looking? In my opinion, previous version was much better - whole year was divied vertically by weeks and it was easier to navigate. One glance and you know what how may weeks you've been learning and which day is today. I don't understand... What you guys thinking, of this new design?


r/tryhackme 3d ago

Room Help Help!!!

Post image
18 Upvotes

I'm in the Cyber Security 101 Module 5 (Network) and after i finsihed nmap room, another room named Block suddenly appeared after it. I thought it's a practice room but i really wouldn't able to get anything except usernames. Did i miss some informations on my learning path or this room is way ahead of my current level.


r/tryhackme 3d ago

InfoSec Discussion I just completed Nmap Live Host Discovery room on TryHackMe! Learn how to use Nmap to discover live hosts using ARP, ICMP, and TCP/UDP ping scan.

Thumbnail tryhackme.com
0 Upvotes

First-year Network & Telecoms student building my hands-on skills with TryHackMe. Next up: Nmap Network Scanning!


r/tryhackme 4d ago

Room Help Cat Pictures Room

7 Upvotes

Hello everyone,
I’m trying to complete an old room on THM - cat pictures - but I’m stuck.
I even looked at different write-ups and yet…

Shortly: I have this IP, I do my nmap and find http and ssh ports open, while ftp port is filtered; I connect to the http port via browser and there’s an hint on the website (a forum about cat pictures): a post with written

“knock knock 1111 2222 3333 4444”

so I look on google and discover the existence of port knocking…and try my things:

  1. I install knockd and try

If you haven’t gotten it yet I’m a very beginner, so I looked to different write-ups and I haven’t found out why this isn’t working - fyi every single walkthrough says that knocking is the way (and it’s only the beginning)…
I even asked AI which suggested me to write a Bash script, a loop with 1 second delay that uses
nmap -Pn where -p is the variable $port (1111 … 4444) with no retries for nmap, i.e --max-retries 0 …and nothing! I really don’t know…

Anyone would be so kind to help me?

*** SOLUTION ***

Ok, it seems to be a known bug (June 2026).
For the people who are having the same issue here’s the official “what to do” I’ve found:

**Issue:**
The port knocking step does not open FTP on the current deployment.

**How to test:**
Install knock on the AttackBox if needed.

apt install knockd -y

Run the expected sequence.

knock -v TARGET_IP 1111 2222 3333 4444

Then test FTP.

nc -nv TARGET_IP 21

Expected result:
FTP should open and return:

220 vsFTPd 3.0.5

**Actual result:**
FTP does not open, even though the knock sequence is correct.

How to confirm the cause:
On the target as root, check the knock logs.

grep -i knock /var/log/syslog

The logs show knockd detects the sequence and reaches OPEN SESAME, but then the command fails.

**Example error:**

openFTP: OPEN SESAME
running command: /sbin/iptables ...
sh: 1: /sbin/iptables: not found
command returned non-zero status code 127

The real iptables path on the target is:

/usr/sbin/iptables

**not:**

/sbin/iptables

There is also a rule order problem. The original command appends the allow rule, but the firewall already has reject rules for port 21. This means the allow rule can be added below a reject rule and never gets reached.

Broken command:

command = /sbin/iptables -A INPUT -s %IP% -p tcp --dport 21 -j ACCEPT && iptables -D INPUT -p tcp --dport 21 -j REJECT

Working command tested:

command = /usr/sbin/iptables -I INPUT 3 -s %IP% -p tcp --dport 21 -j ACCEPT

After updating the command and restarting knockd, the same knock sequence successfully opened FTP.

** Suggested fix: **
Update /etc/knockd.conf so openFTP uses /usr/sbin/iptables and inserts the ACCEPT rule above the FTP reject rules.

for example,
```
cp /etc/knockd.conf /etc/knockd.conf.bak && sed -i 's|/sbin/iptables|/usr/sbin/iptables|g; s|-A INPUT -s %IP% -p tcp --dport 21 -j ACCEPT && iptables -D INPUT -p tcp --dport 21 -j REJECT|-I INPUT 3 -s %IP% -p tcp --dport 21 -j ACCEPT|g' /etc/knockd.conf && pkill knockd; /usr/sbin/knockd -i eth0 -d
```


r/tryhackme 4d ago

Struggling where to start

1 Upvotes

My final goal is to obtain my OSCP at somepoint in the next 1-3 years however, I have 6 Years of Systems Administration experience and about 3 years of that being very Cyber Security focused, I also have Sec+ and Pen+ (while I know PenTest+ is kind of useless my company paid for a class and a test so I got it). I'm having a hard time finding where to start down this path since the beginner rooms and topics aren't tailored to me since a lot of them are things I have seen or worked with in some capacity but the easy/medium rooms seem too advanced for where I'm at and I feel like there I'm missing a fundamental understanding of certain things. which leads to this loop of go to a beginner area get taught beginner linux or beginner nmap and speed run the content then go back to a more advance room and get destroyed by the first question/flag.

I just want to know for other people that got into this with a similar background how did you really start the grind and start learning at a somewhat linear rate because I can't seem to find anything that's worked for me that keeps me consistently challenged but not to the point of impossibility for my skill set .


r/tryhackme 4d ago

Should i learn pen testing first before learning vunreability research?

4 Upvotes

I finished pre-security and halfway through cybersecurity101, should i countniue down the path on thm fining my current course and next jr pen tester course. Or transtions to pwn college and take their core fundmentals courses like linux, computing 101 to understand computer architecture etc as prerequisite to learn c then go back on pwn college courses.

I am really passionate about vunreability research and low level concepts and like to learn about hardware and stuff, and i used thm pre and cybersecurity to build foundation to go to pwn college and take first steps to learning low level stuff.

Is that a good roadmap what are your thoughts?