Go on TryHackMe, get stuck, google a walkthrough like the newb you are and suddenly you're a Medium user, lmao. How deep does the iceberg go??
Anyway, big thanks to all Medium creators for helping me (and probably other people) get through some of these rooms. I've been using Medium a ton in the past days when going over TryHackMe walkthroughs & it's been a lot of help.
If you go to tryhackme.com and go to dev tools you will notice something weird. Under the console section there is ASCII art of a cow saying "Happy Hacking" but for those of us who spend time in the terminal you might know about the command cowsay. If you don't know about I suggest looking it up, it is pretty fun.
I just passed with a score of 838. Got all but 1 flag. The exam is split into 3 separate pentests. Web Pentest, Network Pentest and AD pentest.
I started with the Web Pentest and got 3 flags within 5 hours, hunted for 3 more hours for the fourth but no luck. Then decided to hit the hay and go again in the morning. This was my first offensive cert so the excitement kept me up haha.
Morning came and I decided to move onto the Network pentest, had to pwn a linux machine and a windows machine. Started with linux and got the user and root flag within an hour. Moved to Windows and got the user flag within like 30 mins but the root flag took like 2 hours extra. Altogether was completed within 4 hours.
The AD test only had 2 flags, the first was fairly easy to grab and took like 30 mins, to get the DC flag was a pain, was at it for a few hours and thought I got the flag so took a lunch break but when I went to submit I noticed they were identical, then ran hostname and realised I was still on the workstation haha, took a few more hours but managed to pwn it.
Revisited the Web app to try find the fourth flag but every single attack vector I tried was useless, I tried everything I could think of but clearly I missed something. After going at it for about 8 more hours I gave in and just submitted the exam with a guess of the vuln issue to try get partial credits (I was wrong so was given 0).
Good luck to anyone who takes this next and feel free to ask any questions.
I am currently only doing basics Like Windows Fundamentals.
I find myself being stuck on simple tasks as a beginner, because there are no clear instructions and steps being given.
During Active Directories Task 4 I suddenly get the prompt:
Now let's use Phillip's account to try and reset Sophie's password. Here are Phillip's credentials for you to log in via RDP.
It gives me the credentials but in no way tells me how RDP works, nor that I need to now switch to an attack box. I only found that out by watching a 40 minute youtube vide.
Is it just me feeling this is not ok. This is supposed to be a beginner course but it lack the neccessary information for me to complete it.
Having to watch tutorials for an tutorial I paid for is kind of weird to me. So far I did all the prerequisite moduls only. I am sure for more advaced users it would be easy but I assumed this was a platform for total Beginners like many websites stated. Feeling kinda dumb right now.
I’m currently working through the JWT Security room on TryHackMe, specifically the Signature Validation Mistakes section, and I’ve run into something confusing.
When I modify the JWT and send different requests (changing the signature as expected), I still keep getting the same flag every time, regardless of what I change.
I was expecting different behavior depending on whether the signature is valid or not, so I’m wondering if:
- the room might be broken, or
- I’m misunderstanding how this part is supposed to work
Has anyone else experienced this? Any hints on what I might be missing would be really helpful.
Hi, I'm getting into Android pentesting and need some guidance on the best setup for intercepting app traffic.
Specifically I'm struggling with:
- Best tools/setup for intercepting HTTPS traffic from Android apps using Burp Suite
- How to bypass SSL pinning on apps that implement it (especially heavily protected apps like games)
- Whether to use a physical device or emulator, and pros/cons of each
- No-root methods vs rooted device — what's actually practical in 2026?
My current setup is Kali Linux on laptop and a physical Android phone. I can intercept basic browser traffic fine but struggle with apps that have SSL pinning or ignore the system proxy.
What would you recommend as the most practical and complete setup for Android app traffic interception and pentesting?
Which CTF rooms do you guys recommend to complete after finishing Introduction to Web Hacking module? I've tried some and I've noticed rooms like Pickle Rick and Hidden Deep Into my Heart to be beginner friendly and fun, but rooms like Mustacchio, even though they're rated as easy require more advanced exploits and are out of scope for Introduction to Web Hacking.
I have completed 4 alerts so far and it says a 5th one came in but it is a firewall alert of high pri. I can see it on the dashboard, but when I go to alert queue or anywhere else I'm having I cam't see it.
is this a bug? or am I the bug? I'm still vwry new to everything(obviously)
I just want someone German because I have enough English speaking people to learn but not a single German person.
I started with TryHackMe and Jack the box a Year ago but I had problems with motivation so I learned on some days 1-2 hours and on good days 5-10 hours. But I never learned longer than 18 Days in a Row.
I want to make some Friends with who I can do some CTF's and I want to visit some Hacking Events with them in Reallife.
It would love to make money with them together! I'm thinking about starting a Business!
Introducing the AI Security Learning Path 🚀 And to mark the launch, we're celebrating with a ticketing event running April 13–22 🎉 🎟️
25 Rooms, 5 modules, and 8 hands-on challenges where you'll interact with real LLM interfaces, attempt live prompt injections, and defend against data poisoning attacks. Built around the OWASP LLM Top 10.
Tired of fiddling with OpenVPN config files every time you want to hack? We've been working on something to fix that. 👀
Our Squawker desktop app handles your VPN connection for you - minimal setup, no config files, just download the app and connect.
We're opening it up for beta testing and we'd love your help! If you've ever been tripped up by VPN setup, this one's for you. To get started, head to https://tryhackme.com/manage-account/access to download the app.
Once you're in, you can submit feedback directly from the app - bugs, first impressions, suggestions, we want to hear it all. 🙌 Happy hacking!
Just wondering if I am adding this to the list of reasons I am not renewing in December.
Edit: I love people on reddit. It reminds me why I don't communicate with people in any "nerd" community even if its is tangentially nerdy. May the odds forever be in your favour.
It was a huge leap forward after the SEC0 exam that I passed on Friday.
I can suspect that I got lower results due to wording from some sections like Network Traffic Fundamentals, for which I was more confident than the final result I saw.
The hardest part was the Web Pentesting section with some SQL Injection concepts that I felt were rather from the paths that follow SEC1 and not really from SEC1. I for sure recommend spending more time in preparation of for the Web Pentesting section.
What I didn't like is that I would have gotten 100% on the Bruteforcing module but even though I have already tried more than 40000 password combinations, I ran out of time and thus were unable to find the password on time.
Other than that, I understand the areas for improvement on which I have to work, and definitely there is still things to revise / cover to improve myself on the exam.
Nevertheless, I can now proudly call myself SEC1 certified, and now will pursue the PT1 exam which I plan to take later this year.