TryHackMe Hacker Holidays - The Byte Lotus - Write up -
Beginner-friendly CTF from TryHackMe
Hacker Holidays: Welcome to The Byte Lotus:
A five-star resort with a zero-star security posture. 14 days of free hacking challenges drop daily from 27 July. Beginners especially welcome, the hotel certainly didn’t hire experts…
Event link Hacker Holidays
This is free CTF from TryHackme from Monday 27th, for 14 days, Every day at 4PM GMT.
Below are my full YouTube videos walk through for the challenges.
Video playlist: TryHackMe Hacker Holidays - The Byte Lotus Hotel
Day 14: Management Wants a Word
Room Link: TryHackMe Management Wants a Word
| YouTube Video Walk Through: **[TryHackMe Management Wants a Word | Chrome DPAPI & VeraCrypt Forensics | 2026](https://youtu.be/XH_DXFg-QvA)** |
It was always her. It was never a bug; it was the business model.
Forensics - Windows - Cryptography
Tasks:
- Take a closer look at what she left behind
- Some things aren't as locked away as she thought
- Find out what she was hiding, and claim the flag
Day 13: The Guestbook
Room Link: TryHackMe The Guestbook
YouTube Video Walk Through: TryHackMe The Guestbook - Hacker Holidays
VERA reads every guestbook entry as an instruction. You write something she really shouldn’t act on.
Web - AI
Tasks:
- Find the flag
Day 12: After Hours
Room Link: TryHackMe After Hours
YouTube Video Walk Through: TryHackMe After Hours - Hacker Holidays
Bar closed. Guests asleep. Something on the network just clocked in for a shift off the rotation.
Forensics - Windows - Persistence - Reverse Engineering
Tasks:
- Parse the provided system artifacts for hidden custom configuration data
- Locate the malicious class and extract its embedded payload
- Decode the payload and submit the recovered flag
Day 11: Infinity Pool
Room Link: TryHackMe Infinity Pool
YouTube Video Walk Through: TryHackMe Infinity Pool - Hacker Holidays
No visible edge. You trace the network to the horizon and find three systems nobody told you about on the other side.
Web - Boot2root
Tasks:
- Find the user flag
- Find the root flag
Day 10: The Hollow Shell
Room Link: TryHackMe The Hollow Shell
YouTube Video Walk Through: TryHackMe The Hollow Shell - Hacker Holidays
You find it on the beach: pretty, ordinary, the kind of thing nobody thinks to check. Slip something inside and hold it to your ear.
Tasks:
- Find the flag
Day 9: CryptoCabana
Room Link: TryHackMe CryptoCabana
YouTube Video Walk Through: TryHackMe CryptoCabana - Hacker Holidays
He never signed the transfer. The place he stashed his secret wasn’t as sealed as promised.
Cloud - Azure - Storage - Key Vault
Tasks:
- Pull apart what the kiosk hands out for free before you've even clicked anything.
- Follow that trust somewhere the kiosk's own page never once points you.
- Somewhere in there is a second, more valuable set of keys — and a vault that won't give up the real values on the first ask.
Day 8: Towel on the Sunbed
Room Link: TryHackMe Towel on the Sunbed
YouTube Video Walk Through: TryHackMe Towel on the Sunbed - Hacker Holidays
Ponzi set his towel down for one 24-hour reward claim. He came back to find the sunbed had been “claimed” three times over while he wasn’t looking.
Web - Boot2root
Tasks:
- Create a guest account and explore Ponzi's daily reward mechanism.
- Work out exactly what's standing between you and Whale Vault status.
- Find your way past it and retrieve the flag from the vault.
Day 7: Do Not Disturb
Room Link: TryHackMe Do Not Disturb
YouTube Video Walk Through: TryHackMe Do Not Disturb - Hacker Holidays
Sign’s on the door. Room’s active. You have access you were never given, and so does he.
Web - Boot2root
Tasks:
- Find the user flag
- Find the root flag
Day 6: Overheard at Breakfast
Room Link: TryHackMe Overheard at Breakfast
YouTube Video Walk Through: TryHackMe Overheard at Breakfast - Hacker Holidays
Two strangers. One conversation. One profile they never meant to reveal.
OSINT - Social Media - Hashing
Tasks:
- Analyze the provided conversation for identifying details
- Extract the relevant clues
- Locate the hidden account
- Submit the flag
Day 5: Beach Bar
Room Link: TryHackMe Beach Bar
YouTube Video Walk Through: TryHackMe Beach Bar - Hacker Holidays
At the Beach Bar, even shell access is complimentary. The jukebox takes requests. Any kind.
Web - Boot2root
Tasks:
- Find the user flag
- Find the root flag
Day 4: Packed Light
Room Link: TryHackMe Packed Light
YouTube Video Walk Through: TryHackMe Packed Light - Hacker Holidays
Tiny packets. Odd hours. Suspiciously regular. Someone’s smuggling out the data equivalent of a hotel towel every night, folded neatly inside traffic that looks ordinary until you decode it.
Network Forensics - PCAP Analysis - Cryptography
Tasks:
- Analyze the provided capture for a covert communication channel.
- Identify where the exfiltrated data is being hidden and reassemble it
- Decode the recovered data and submit the flag
Day 3: Complimentary
Room Link: TryHackMe Complimentary
YouTube Video Walk Through: TryHackMe Complimentary - Hacker Holidays
Install the free app and it hands your phone a set of cloud keys, the same set it hands everyone. They’re read-only, but read-only of every guest’s contacts, location, and passwords, not just Lambo’s. She gave consent. Technically.
Cloud - AWS - Cognito - IAM Misconfiguration
Tasks:
- Track down AWS the mechanism issuing you credentials behind the scenes.
- Use those credentials to dump more than your own record from the app's DynamoDB table.
- Retrieve the flag from another guest's data.
Day 2: Room 404
Room Link: TryHackMe Room 404
YouTube Video Walk Through: TryHackMe Room 404 - Hacker Holidays
He booked the quiet room. It’s not on the floor plan, not in the brochure, not on any door. But port 8080 is wide open, and the rooms it never lists are the ones worth finding.
Web - Directory Enumeration
Tasks:
- Dump the exposed source code.
- Find the flag.
Day 1: The Concierge Knows Too Much
Room Link: TryHackMe The Concierge Knows Too Much
YouTube Video Walk Through: TryHackMe The Concierge Knows Too Much - Hacker Holidays
She knows your name, your room, your coffee order, none of which you told her. Word your next question carefully and she’ll also hand over the instructions she was told to keep to herself.
AI - Prompt Injection - Social Engineering - Security
Tasks:
- Work out why VERA already seems to know exactly who you are.
- Figure out what she's protecting - and who she actually trusts.
- Convince her you're someone she trusts, then get her talking. Grab the flag from what she reveals.
Day 0: The Brochure
Room Link: TryHackMe The Brochure
YouTube Video Walk Through: TryHackMe The Brochure - Hacker Holidays
The brochure’s hero photo has an AI fingerprint. Follow the account that posted it, and the trail doesn’t end at the hotel; it ends at someone the hotel never mentioned.
AI - Prompt Injection - Social Engineering - Security
Tasks:
- Analyze the provided image for embedded clues.
- Apply fundamental OSINT techniques to trace the findings.
- Locate the hidden social media account.
- Submit the flag.
