Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
In this lab, you will explore a corporate Linux system with multiple users, discover which of them can escalate privileges, and access a hidden flag in the root directory. In this lab, you will learn:
rockyou.txt
) using HydraFollow these instructions to get started:
You are facing a corporate server with multiple users. Your task is to discover how to gain privileged access from an apparently limited environment.
Discover the IP address of the ELEVATION machine.
nmap
, netdiscover
, or arp-scan
to scan the network.Access the system via SSH with known users.
Pay attention to a user without a known password.
Perform a brute-force attack using Hydra.
Gain access and look for ways to escalate privileges.
Find and read the final flag.
Remember: sometimes power lies not in what is visible… but in what seems unprotected.
Happy hacking!
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures
Difficulty
intermediate
Average duration
2 hrs
Technologies
linux
cybersecurity
red team
owasp-a05-security-misconfiguration
ssh
hydra
suid
owasp-a07-identification-authentication-failures