Back to lessonhackingpath / lab
Capture the FlagMedium

Reverse Shell at Login

Lab for Cron, systemd & Startup Persistence

Scenario

The intruder wants a shell every time someone logs in. The usual spot is a login script that runs automatically. Read the user's shell startup file and find the callback they hid.

Objective

Find the reverse-shell implant hidden in a startup file.

lab ~ reverse shell at loginnothing real runs
booting lab sandbox…

This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.