Offensive Lab · pro · solved in-browser (no VM needed) · 3 tiered hints
Your own disposable practice box. sudo -l shows a NOPASSWD rule for /usr/bin/make. make runs the shell commands inside a recipe as root, and you can feed it a makefile from standard input (-f /dev/stdin) or an inline recipe. Write /home/player/ans.txt with a single command that runs make through sudo and supplies a recipe (via -f /dev/stdin with a here-string/heredoc, or --eval) whose command copies /root/flag.txt to /home/player/flag. (Authored config, graded structurally — the engine isn't run here.)
▶ Start this challengeNobody has solved this one yet — be the first clear on the leaderboard.
Open the challenge and an in-page editor appears — write your answer and tmpfs.tech grades it server-side against the same checks a real box would run. No VM, no install, no signup needed to try.
Authorized local-privilege-escalation wargames on a disposable box you own.
See all Offensive Lab challenges →
Is it free? Yes — play as a guest, no signup required to start.
Do I need to install anything? No. Everything runs in your browser.
How is it graded? Automatically and deterministically — your work is checked against the exact rules the live box would apply.