Back to lessonhackingpath / lab
Capture the FlagEasy

Creds in Plain Sight

Lab for Weak Permissions & Credential Hunting

Scenario

You have a low-privilege shell. Before reaching for exploits, hunt for credentials, people paste passwords into commands and configs constantly. Check the shell history and app configs.

Objective

Hunt the filesystem for a password a careless user left behind.

lab ~ creds in plain sightnothing real runs
booting lab sandbox…

This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.