Post

TryHackMe Hacker Holidays - The Byte Lotus - Write up -

Beginner-friendly CTF from TryHackMe

TryHackMe Hacker Holidays - The Byte Lotus - Write up -

Hacker Holidays: Welcome to The Byte Lotus:

A five-star resort with a zero-star security posture. 14 days of free hacking challenges drop daily from 27 July. Beginners especially welcome, the hotel certainly didn’t hire experts…

Event link Hacker Holidays

This is free CTF from TryHackme from Monday 27th, for 14 days, Every day at 4PM GMT.

Below are my full YouTube videos walk through for the challenges.

Video playlist: TryHackMe Hacker Holidays - The Byte Lotus Hotel

Day 14: Management Wants a Word

Room Link: TryHackMe Management Wants a Word

YouTube Video Walk Through: **[TryHackMe Management Wants a WordChrome DPAPI & VeraCrypt Forensics2026](https://youtu.be/XH_DXFg-QvA)**

It was always her. It was never a bug; it was the business model.

Forensics - Windows - Cryptography

Tasks:

  • Take a closer look at what she left behind
  • Some things aren't as locked away as she thought
  • Find out what she was hiding, and claim the flag

Day 13: The Guestbook

Room Link: TryHackMe The Guestbook

YouTube Video Walk Through: TryHackMe The Guestbook - Hacker Holidays

VERA reads every guestbook entry as an instruction. You write something she really shouldn’t act on.

Web - AI

Tasks:

  • Find the flag

Day 12: After Hours

Room Link: TryHackMe After Hours

YouTube Video Walk Through: TryHackMe After Hours - Hacker Holidays

Bar closed. Guests asleep. Something on the network just clocked in for a shift off the rotation.

Forensics - Windows - Persistence - Reverse Engineering

Tasks:

  • Parse the provided system artifacts for hidden custom configuration data
  • Locate the malicious class and extract its embedded payload
  • Decode the payload and submit the recovered flag

Day 11: Infinity Pool

Room Link: TryHackMe Infinity Pool

YouTube Video Walk Through: TryHackMe Infinity Pool - Hacker Holidays

No visible edge. You trace the network to the horizon and find three systems nobody told you about on the other side.

Web - Boot2root

Tasks:

  • Find the user flag
  • Find the root flag

Day 10: The Hollow Shell

Room Link: TryHackMe The Hollow Shell

YouTube Video Walk Through: TryHackMe The Hollow Shell - Hacker Holidays

You find it on the beach: pretty, ordinary, the kind of thing nobody thinks to check. Slip something inside and hold it to your ear.

Tasks:

  • Find the flag

Day 9: CryptoCabana

Room Link: TryHackMe CryptoCabana

YouTube Video Walk Through: TryHackMe CryptoCabana - Hacker Holidays

He never signed the transfer. The place he stashed his secret wasn’t as sealed as promised.

Cloud - Azure - Storage - Key Vault

Tasks:

  • Pull apart what the kiosk hands out for free before you've even clicked anything.
  • Follow that trust somewhere the kiosk's own page never once points you.
  • Somewhere in there is a second, more valuable set of keys — and a vault that won't give up the real values on the first ask.

Day 8: Towel on the Sunbed

Room Link: TryHackMe Towel on the Sunbed

YouTube Video Walk Through: TryHackMe Towel on the Sunbed - Hacker Holidays

Ponzi set his towel down for one 24-hour reward claim. He came back to find the sunbed had been “claimed” three times over while he wasn’t looking.

Web - Boot2root

Tasks:

  • Create a guest account and explore Ponzi's daily reward mechanism.
  • Work out exactly what's standing between you and Whale Vault status.
  • Find your way past it and retrieve the flag from the vault.

Day 7: Do Not Disturb

Room Link: TryHackMe Do Not Disturb

YouTube Video Walk Through: TryHackMe Do Not Disturb - Hacker Holidays

Sign’s on the door. Room’s active. You have access you were never given, and so does he.

Web - Boot2root

Tasks:

  • Find the user flag
  • Find the root flag

Day 6: Overheard at Breakfast

Room Link: TryHackMe Overheard at Breakfast

YouTube Video Walk Through: TryHackMe Overheard at Breakfast - Hacker Holidays

Two strangers. One conversation. One profile they never meant to reveal.

OSINT - Social Media - Hashing

Tasks:

  • Analyze the provided conversation for identifying details
  • Extract the relevant clues
  • Locate the hidden account
  • Submit the flag

Day 5: Beach Bar

Room Link: TryHackMe Beach Bar

YouTube Video Walk Through: TryHackMe Beach Bar - Hacker Holidays

At the Beach Bar, even shell access is complimentary. The jukebox takes requests. Any kind.

Web - Boot2root

Tasks:

  • Find the user flag
  • Find the root flag

Day 4: Packed Light

Room Link: TryHackMe Packed Light

YouTube Video Walk Through: TryHackMe Packed Light - Hacker Holidays

Tiny packets. Odd hours. Suspiciously regular. Someone’s smuggling out the data equivalent of a hotel towel every night, folded neatly inside traffic that looks ordinary until you decode it.

Network Forensics - PCAP Analysis - Cryptography

Tasks:

  • Analyze the provided capture for a covert communication channel.
  • Identify where the exfiltrated data is being hidden and reassemble it
  • Decode the recovered data and submit the flag

Day 3: Complimentary

Room Link: TryHackMe Complimentary

YouTube Video Walk Through: TryHackMe Complimentary - Hacker Holidays

Install the free app and it hands your phone a set of cloud keys, the same set it hands everyone. They’re read-only, but read-only of every guest’s contacts, location, and passwords, not just Lambo’s. She gave consent. Technically.

Cloud - AWS - Cognito - IAM Misconfiguration

Tasks:

  • Track down AWS the mechanism issuing you credentials behind the scenes.
  • Use those credentials to dump more than your own record from the app's DynamoDB table.
  • Retrieve the flag from another guest's data.

Day 2: Room 404

Room Link: TryHackMe Room 404

YouTube Video Walk Through: TryHackMe Room 404 - Hacker Holidays

He booked the quiet room. It’s not on the floor plan, not in the brochure, not on any door. But port 8080 is wide open, and the rooms it never lists are the ones worth finding.

Web - Directory Enumeration

Tasks:

  • Dump the exposed source code.
  • Find the flag.

Day 1: The Concierge Knows Too Much

Room Link: TryHackMe The Concierge Knows Too Much

YouTube Video Walk Through: TryHackMe The Concierge Knows Too Much - Hacker Holidays

She knows your name, your room, your coffee order, none of which you told her. Word your next question carefully and she’ll also hand over the instructions she was told to keep to herself.

AI - Prompt Injection - Social Engineering - Security

Tasks:

  • Work out why VERA already seems to know exactly who you are.
  • Figure out what she's protecting - and who she actually trusts.
  • Convince her you're someone she trusts, then get her talking. Grab the flag from what she reveals.

Day 0: The Brochure

Room Link: TryHackMe The Brochure

YouTube Video Walk Through: TryHackMe The Brochure - Hacker Holidays

The brochure’s hero photo has an AI fingerprint. Follow the account that posted it, and the trail doesn’t end at the hotel; it ends at someone the hotel never mentioned.

AI - Prompt Injection - Social Engineering - Security

Tasks:

  • Analyze the provided image for embedded clues.
  • Apply fundamental OSINT techniques to trace the findings.
  • Locate the hidden social media account.
  • Submit the flag.
This post is licensed under CC BY 4.0 by the author.