Capture the FlagMedium
Own the Service
Lab for Writable Files & PATH Hijacking
Scenario
root trusts a lot of files. If one it runs is writable by you, you run code as root. List the systemd units, find the one with loose permissions, and read it, its ExecStart is your way in.
Objective
Find a root-run systemd service file you can write to, the privesc vector.
lab ~ own the servicenothing real runs
booting lab sandbox…
This sandbox is fully emulated in your browser, nothing real runs and nothing leaves your machine. Type help to see the tools available.