
This course is about how to create a CTF and upload in websites like TryHackMe and VulnHub where you can get recognized and will be useful in the future. This allows a person to learn about configuring Linux servers too. Before starting this course, I would recommend everyone to know basic Linux commands and play some CTFs.
If not, try to do these TryHackMe Rooms
TRYHACKME ROADMAP
# Level 1 - Intro
➤ OpenVPN
➤ Welcome
➤ Intro to Researching
➤ Learn Linux
➤ Crash Course Pentesting
Introductory CTFs to get your feet wet
➤ Google Dorking
➤ OHsint
➤ Shodan.io
# Level 2 - Tooling
➤ Tmux
➤ Nmap
➤ Web Scanning
➤ Sublist3r
➤ Metasploit
➤ Hydra
➤ Linux Privesc
➤ Web Scanning
More introductory CTFs
➤ Vulnversity -
➤ Blue -
➤ Simple CTF
➤ Bounty Hacker
# Level 3 - Crypto & Hashes with CTF practice
➤ Crack the hash
➤ Agent Sudo
➤ The Cod Caper
➤ Ice
➤ Lazy Admin
➤ Basic Pentesting
# Level 4 - Web
➤ OWASP top 10
➤ Inclusion
➤ Injection
➤ Vulnversity
➤ Basic Pentesting
➤ Juiceshop
➤ Ignite
➤ Overpass
➤ Year of the Rabbit
➤ DevelPy
➤ Jack of all trades
➤ Bolt
# Level 5 - Reverse Engineering
➤ Intro to x86 64
➤ CC Ghidra
➤ CC Radare2
➤ CC Steganography
➤ Reverse Engineering
➤ Reversing ELF
➤ Dumping Router Firmware
# Level 6 - PrivEsc
➤ Sudo Security Bypass
➤ Sudo Buffer Overflow
➤ Windows Privesc Arena
➤ Linux Privesc Arena
➤ Windows Privesc
➤ Blaster
➤ Ignite
➤ Kenobi
➤ Capture the flag
➤ Pickle Rick
# Level 7 - CTF practice
➤ Post Exploitation Basics
➤ Smag Grotto
➤ Inclusion
➤ Dogcat
➤ LFI basics
➤ Buffer Overflow Prep
➤ Overpass
➤ Break out the cage
➤ Lian Yu
Learn how to install Ubuntu 18 server in VirtualBox, configure memory and disk space, create a user, boot from ISO, and troubleshoot networking for a CTF server setup.
Configure the UFW firewall to permit SSH on port 22 and verify status. Gain root access with sudo, enable or disable UFW, and ensure 22/tcp is allowed.
Create a new user on the ubuntu server, choosing a handy username such as Millennial and setting a simple password, then save all credentials in a document for future reference.
Learn how to set a password for the root user so you can switch to root when sudo is unavailable, choosing and saving a root password.
Download Drupal 7.54
CREATE USER <user name>@localhost IDENTIFIED BY "<password of the user>";
CREATE DATABASE <database name>;
GRANT ALL ON <database name>.* TO <user name>@localhost;
FLUSH PRIVILEGES;
Ownership code:
chmod -R www-data:www-data /var/www/html/
drupal.conf code:
<VirtualHost *:<Port>>
<Directory /var/www/html/<Folder>>
Options Indexes FollowSymLinks
AllowOverride None
Require all granted
</Directory>
DocumentRoot /var/www/html/<Folder>/
</VirtualHost>
Patch command:
Patch -p1 < <File name>
Learn privilege escalation techniques by configuring sudo to grant a user root access, editing the sudoers file with vim or nano, and leveraging gtfo bins for non‑interactive root privilege.
USE MySQL;
UPDATE user SET authentication_string=PASSWORD("<Password>") WHERE User='root';
FLUSH PRIVILEGES;
Explains port scanning and service discovery, ssh brute-forcing with hydra, and exploiting drupal 7.54 via metasploit to gain remote access and escalate to root in a ctf.
Walk through creating a TryHackMe ctf room: set title, description, type, tags, points, and tasks with VMs, flags, hints, and public or private sharing for collaborative room design.
Welcome to the World of Capture The Flag (CTF) Challenges!
In this course, we'll delve into the world of Capture The Flag (CTF) challenges, catering specifically to beginners in the field of IT. Whether you're a university student seeking to fulfill an assignment requirement or simply intrigued by the idea of crafting your own CTF room for entertainment or educational purposes, this course is designed to equip you with the necessary skills.
Throughout the journey, we'll cover fundamental concepts, starting from scratch and gradually progressing to more advanced topics. You'll learn essential tasks such as configuring ports, handling errors, utilizing Content Management Systems (CMSs) within a server environment, and managing databases by creating users and granting permissions.
We'll also delve into the critical aspect of patching CMSs to enhance security, exploring various escalation methods to elevate your understanding. Additionally, you'll gain insights into configuring servers to maintain vulnerabilities, essential for users to access root privileges.
Furthermore, an introductory overview of TryHackMe will be provided, offering a platform for hands-on practice and application of learned skills. Finally, we'll explore methods for acquiring necessary resources at no cost, ensuring accessibility for all learners.
Join us on this journey as we unravel the intricacies of building and navigating through CTF challenges. Good luck with your project endeavors, and thank you for embarking on this educational voyage with us.