Skip to content

Conversation

@girlier
Copy link

@girlier girlier commented Nov 10, 2025

Access can roll

Flag 1/2 Commands

ln /home/[access_my_flag user]/access_my_flag ./access_my_flag
ln /home/[access_my_flag user]/flag1 ./flag1
./access_my_flag
rm flag1
ln /home/[access_my_flag user]/flag2 ./flag1
./access_my_flag
Pasted image 20251109122543

Flag 3 Commands

./home/[no flag.txt shell user]/shell /home/[flag.txt user]/shell cat /home/[flag.txt user]
Pasted image 20251109122349

Scenario Changes - scenarios/ctc/Access_can_roll

  • removed hackerbot tag (no hackerbot config/ server)
  • removed IceWeasel (only opened deadlink)
  • removed Pidgin (no hackerbot config)
  • removed SSH vulnerability (SecGen error/ not needed)
  • added gcc module to the server (needed for compiling shell.c for the lab)

Module Changes - vulnerabilities/unix/ctf/pwn/relative_path_suid_hardlinks

  • changed symlink, regular protection, and fifos protection = 0
  • without these the user cannot read the file from access_my_flag in the users home area

Rosie added 2 commits November 10, 2025 18:23
…ns for Debian 12

- changed fs.protected_regular = 0

changed fs.protected_fifos = 0
removed hackerbot tag (no hackerbot config/ server section)

removed Iceweasel module (opened deadlink)

removed Pidgin module (no hackerbot)

removed SSH vulnerability (secgen erorr/ not needed for this lab)

added gcc module to server (needed for setting up lab)
@cliffe cliffe merged commit a3e70fe into cliffe:master Dec 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants