Guardian

HardBash

Overview

SCENARIO

A system monitoring service is running on this machine, quietly keeping an eye on temperatures and system load. It runs as root. You do not.

You land as a regular user. The path to root is somewhere in how that service works and the privileges it carries. Find it.

Credentials: user:user

Infrastructure

- Docker Container — HTTP on port 7681

Provided Files

- None

Job Positions

Penetration Tester

Tags

Privilege EscalationSuidEnvironment VariablesPath VariableBash Pitfalls