Back to lessonhackingpath / lab
Capture the FlagEasy

The Extra Key

Lab for SSH Keys & Account Backdoors

Scenario

An attacker added their own public key so they can log back in without a password, no matter how often you rotate it. Read the authorized_keys file and find the key that doesn't belong.

Objective

Find the attacker's SSH key planted in authorized_keys.

lab ~ the extra keynothing real runs
booting lab sandbox…

This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.