Checkmate is the capstone of the Password Attacks module in the Jr Penetration Tester path, and it strings together every idea from the earlier rooms into one target. Where Introduction to Wordlists taught building lists from OSINT and Password Cracking taught turning hashes into plaintext, this challenge makes you do both against Marco Bianchi’s internal systems: a firewall, a careers portal, a social platform, and SSH. Five levels, one lesson repeated five ways: a reused, predictable password is an open door.

Everything runs on one host. The main app on port 5000 is a scoreboard that verifies each level’s password and unlocks the next; the actual work happens on the sub-services (firewall.thm:5001, jobs.thm:5002, social.thm:5003, and SSH on 22). All of them were reachable straight from my Mac by IP, so no AttackBox was needed. One rule the app states up front: blind brute-forcing the main port 5000 is out of scope and trips a cooldown, so the attacks belong on the sub-services.

Level 1: default credentials on the firewall

The firewall console at firewall.thm:5001 is a login form whose own banner says “Initial deployment completed with default admin credentials.” The username placeholder is admin, and the classic weak default did it: admin / 12345 returns a redirect instead of “Invalid credentials.” The Level 1 password is 12345.

Level 2: a company keyword on the careers portal

The Employee Login on jobs.thm:5002 sits behind a careers site that scatters the company’s values across the page: “Innovation. Excellence. Security.” Marco used one of those as his password. Logging in as marco with each keyword, excellence lands (redirect to /profile). That is the Level 2 password, and the profile it unlocks is the real prize: Marco’s personal details.

  # marco/excellence unlocks the employee profile
First Name   Marco
Surname      Bianchi
Nickname     marky
Birthdate    14021995   (DDMMYYYY = 14 Feb 1995)
Firewall default creds, the excellence keyword, and Marco’s profile details

Those four facts, nickname and birthdate especially, are the seed for the next level.

Level 3: generate a wordlist with CUPP, then crack the social login

social.thm:5003 is a Facebook clone, and its login page hints plainly: “Use the details from jobs.thm to generate Marco’s password.” This is where the room wants a password profiler rather than manual guessing, and I learned why the hard way. I threw thousands of hand-built name + date combinations (marky140295, Marco@1995!, Bianchi1995, every date encoding I could think of) at both the login and the app’s verify endpoint. Every one came back “Incorrect,” and the verify endpoint eventually hit its cooldown. The predictable password was not as guessable as it looked.

The intended tool is CUPP, which mangles a person’s details into a wordlist far larger than anything you would type by hand:

cupp -i
  # First Name: Marco  Surname: Bianchi  Nickname: marky  Birthdate: 14021995
  # -> marco.txt  (14,000+ candidates, including digit-permuted variants)

Filtering CUPP’s output to the 11-character length the room hints at and brute-forcing the social login (username marco) with response-size detection, one credential succeeded with a 302 redirect and a social_authed cookie: Bianchi2495. It is Marco’s surname with a number CUPP generated by permuting his birth digits, exactly the kind of “predictable but not obvious” password a real audit turns up.

  # the winning credential from the generated list
marco:Bianchi2495  ->  HTTP 302 (login success = Level 3 password)
CUPP generates the wordlist, Bianchi2495 logs into social.thm, and the feed reveals the SSH pattern

A quick tooling note: Hydra’s http-post-form module refused to parse in my shell, so I used a curl loop with size detection for the web login. Hydra worked fine for the SSH step later.

Level 4: crack the SHA256 profile-picture filename

Logged into social.thm, Marco’s profile serves his avatar at a hashed path. The Level 4 task explains the scheme: uploads are renamed to SHA256(original filename).png. The stored file was:

d34a569ab7aaa54dacd715ae64953455d86b768846cd0085ef4e9e7471489b7b.png

The answer is the 6-character original filename that hashes to that value. Since SHA256 is fast and unsalted and the filename is short, this is a direct Hashcat mask attack, mode 1400, the same technique the Password Cracking room drilled:

hashcat -m 1400 -a 3 hash.txt '?l?l?l?l?l?l'   # 6 lowercase letters

It falls instantly: the original filename is family.

Hashcat cracks the profile-picture SHA256 to the original filename: family

Level 5: read the pattern, then brute-force SSH

Marco’s social feed hands over the last piece. One of his posts is a security “tip”:

take a company keyword, capitalize it, then append the year like 2024 or any other number and an exclamation mark

That is a password-generation rule, not a password. Combined with the keyword list (security, excellence, innovation, digital, cloud), it defines a small, targeted wordlist: Security2024!, Excellence2024!, Innovation2024!, and so on. The Level 5 answer is 13 characters, which fits Security (8) + a 4-digit year (4) + ! (1) exactly. Generating that list and pointing Hydra at SSH as marco:

hydra -l marco -P pattern-wordlist.txt -t 4 -f 10.48.137.121 ssh
  # [22][ssh] login: marco   password: Security2024!

The SSH password is Security2024!, and it logs straight in as marco@tryhackme-2404, completing the compromise.

Hydra brute-forces SSH with the pattern wordlist and logs in as marco

That closes all five levels.

Checkmate room completed 100 percent

Two takeaways

A password profiler beats hand-guessing, and it is the point of the exercise. I burned real time hand-crafting name + birthdate combinations that felt obvious and were all wrong. CUPP found Marco’s social password because it permutes the birth digits into forms a human would not bother typing (Bianchi2495). When a room says “generate” a password from personal info, reach for the generator; the answer usually lives in the long tail of mutations, not the first ten you think of.

A stated password rule is worse than a single leaked password. Marco’s “strong password tip” told everyone exactly how he builds passwords: capitalized keyword, year, exclamation mark. That collapsed the SSH keyspace from impossible to a wordlist of a few dozen entries that Hydra cleared in seconds. Reused patterns are the same weakness as reused passwords, one step removed, and OSINT that reveals the pattern is as valuable as OSINT that reveals a credential.

Room solved 100%: 1 task, 5 answers.