Capture the FlagMedium
Reverse Shell at Login
Lab for Cron, systemd & Startup Persistence
Scenario
The intruder wants a shell every time someone logs in. The usual spot is a login script that runs automatically. Read the user's shell startup file and find the callback they hid.
Objective
Find the reverse-shell implant hidden in a startup file.
lab ~ reverse shell at loginnothing real runs
booting lab sandbox…
This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.