← CTF index
TryHackMe · Series

Hacker Holidays 2026: fourteen nights at the Byte Lotus — all 15 TryHackMe writeups, Day 0 to Day 14

Writeups for the TryHackMe Hacker Holidays 2026 series (Byte Lotus Hotel theme): a room a day, from OSINT to web, cloud, forensics and boot2root. Flags always redacted: the method is the point.

// Published writeups — series complete
OSINTEasy25 Jul 2026
The Brochure
Day 00, OSINT category, Easy difficulty. The kind of challenge I enjoy: you don't solve it with an exploit, you solve it by reading carefully. The tas…
read →
AI Prompt AttacksEasy27 Jul 2026
The Concierge Knows Too Much
VERA, the Byte Lotus "Very Efficient Resort Assistant", greets you like she's known you for years: room number, coffee order, all before you type a wo…
read →
WebEasy28 Jul 2026
Room 404
"Dump the exposed source and find the flag," says the room. On paper it's easy, and it really is — but the real lesson isn't that the source code is e…
read →
CloudEasy29 Jul 2026
Complimentary
A guest "wellness" site that hands AWS credentials to the first passer-by: what could go wrong? In this Cloud room I followed the crumbs from app.js t…
read →
ForensicsMedium30 Jul 2026
Packed Light
Byte Lotus guest network, a short pcap and a tip from @0xMia: her laptop "pings" some random address on port 8080 every second, clockwork-precise, and…
read →
Boot2rootEasy31 Jul 2026
Beach Bar
Byte Lotus, a beach, a web jukebox that takes requests from anyone with a phone. The DJ left behind more than music though: a demo login still switche…
read →
OSINTEasy01 Aug 2026
Overheard at Breakfast
Day 06 of Hacker Holidays, OSINT category: no exploit, no shell, just a Discord screenshot and the terrible habit of dropping your email in chat. The …
read →
Boot2rootMedium02 Aug 2026
Do Not Disturb
Byte Lotus is a booking platform for poolside cabanas and sunbeds, and someone was clearly already playing with it: wallets changing on their own, hij…
read →
WebMedium03 Aug 2026
Towel on the Sunbed
Ponzi - Wellness Rewards is the poolside "crypto rewards" app that lets you claim a staking reward once every 24 hours. The whole problem is in that "…
read →
CloudMedium04 Aug 2026
CryptoCabana
A kiosk that offers to "safely back up" your seed phrase on Azure: what could possibly go wrong? The site hands the browser a SAS token scoped so broa…
read →
WebMedium05 Aug 2026
The Hollow Shell
A portal invites you to upload a "shell" — a .zip pack of seaside ambiance for the room tablets. The room whispers at you to hunt for "automation hook…
read →
Boot2rootMedium06 Aug 2026
Infinity Pool
The edge of an infinity pool is invisible — and so is this box's boundary. A harmless "netcheck" becomes a shell, then the chain runs through three loopback services and a FreePBX phone system up to root: the access key arriv…
read →
ForensicsMedium07 Aug 2026
After Hours
Lights off, guests asleep, and a box that "clocks in" every night — yet nothing in Startup, Scheduled Tasks or Run keys. The persistence is fileless, buried in the WMI repository: you dig by hand until the…
read →
AI / WebMedium08 Aug 2026
The Guestbook
Same VERA as "The Concierge Knows Too Much", but this time you don't talk to her: you write in the guestbook and she reads it later, on her own, "on the night manager's authority". Indirect prompt injection — and at the end of the chain there's no secret to coax out: there's /bin/sh…
read →
ForensicsHard09 Aug 2026
Management Wants a Word
No box to attack: just a KAPE triage from VERA's workstation. Chrome saved a password you cannot read, but Windows autologon leaves its own in cleartext in the registry — and from there the chain reaches a 100 MiB VeraCrypt volume that looks like noise…
read →