Back to lessonhackingpath / lab
Capture the FlagMedium

Own the Service

Lab for Writable Files & PATH Hijacking

Scenario

root trusts a lot of files. If one it runs is writable by you, you run code as root. List the systemd units, find the one with loose permissions, and read it, its ExecStart is your way in.

Objective

Find a root-run systemd service file you can write to, the privesc vector.

lab ~ own the servicenothing real runs
booting lab sandbox…

This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.