tmpfs.tech · all tracks · Offensive Lab

Writable-PATH binary hijack

Offensive Lab · medium · solved in-browser (no VM needed) · 3 tiered hints

Your own disposable practice box. A root cron job (or a SUID wrapper) runs the bare command backup instead of an absolute path, and /home/player appears in PATH ahead of /usr/bin. So a script you place at /home/player/backup runs as root when the job fires. Author the file /home/player/backup: a /bin/sh script (shebang on line one) whose body copies /root/flag.txt to /home/player/flag and makes that copy world-readable with chmod so you can read it afterwards. (Authored config, graded structurally — the engine isn't run here.)

▶ Start this challenge

Nobody has solved this one yet — be the first clear on the leaderboard.

How it works

Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.

More Offensive Lab challenges

Authorized local-privilege-escalation wargames on a disposable box you own.

See all Offensive Lab challenges →

FAQ

Is it free? Yes — play as a guest, no signup required to start.

Do I need to install anything? No. Everything runs in your browser.

How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.