Back to lessonhackingpath / lab
Capture the FlagHard

GTFOBins to Root

Lab for GTFOBins: SUID & sudo to Root

Scenario

Your `sudo -l` shows you may run one specific binary as root. On GTFOBins, that same binary has a known trick to break out and run any command as root. Use it to read the root flag.

Objective

Abuse a sudo-allowed binary to read a file you shouldn't be able to.

lab ~ gtfobins to rootnothing real runs
booting lab sandbox…

This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.