CTF Writeup: ContainMe - TryHackMe
Difficulty: MediumTheme: Container escape / lateral movement / pivoting Overview A multi-stage machine involving command injection via a PHP web app, SUID binary abuse for privilege escalation inside

Search for a command to run...

Series
Step-by-step writeups and walkthroughs for TryHackMe rooms covering web exploitation, cryptography, steganography, privilege escalation, and more.
Difficulty: MediumTheme: Container escape / lateral movement / pivoting Overview A multi-stage machine involving command injection via a PHP web app, SUID binary abuse for privilege escalation inside

Room: Ra | Difficulty: Hard | OS: Windows Server 2019 (Active Directory) Flags Captured: 3/3 | Topics: OSINT, SMB, Spark CVE-2020-12772, NTLM Relay, Account Operator Abuse, Scheduled Task Exploitation

Difficulty: Medium Reconnaissance Port Scan nmap -sCV -A <MACHINE-IP> -oA nmap-VulnNet Two open ports: Port Service 22 OpenSSH 7.6p1 (Ubuntu) 80 Apache 2.4.29 The HTTP root served a "comin

Field Details Platform TryHackMe Room VulnNet: dotpy Difficulty Medium OS Linux Web Stack Python / Flask (Werkzeug 1.0.1) Reconnaissance Port Scan nmap -sCV -A MACHINE-IP -oA output Onl

Platform: TryHackMeDifficulty: Easy Reconnaissance Nmap nmap -sC -sV -A MACHINE-IP -oA nmap The scan immediately tells us this is a Domain Controller — port 88 (Kerberos), 389/3268 (LDAP), and 5985

Platform: TryHackMeDifficulty: Medium Reconnaissance Nmap nmap -sC -sV -A MACHINE-IP -oA nmap Starting Nmap 7.98 at 2026-06-12 06:47 -0400 Nmap scan report for 10.49.133.153 Host is up (0.075s lat
