Project Meridian
Five OSCP-prep machines inside SolarGate Energy's industrial network. Each one drills a core Linux privilege escalation technique — from SUID abuse to multi-vector chains.
The Machines
Five targets. One theme. Zero hand-holding.
A misconfigured SUID binary left behind after a failed patch window. Find it, understand why it's exploitable, and abuse it to get root.
The ops team sudoed a text-processing binary "for log analysis." One GTFOBins entry later, you're root. sudo -l is always step one.
The ops team gave themselves NOPASSWD sudo on programs they thought were safe. Spoiler: they weren't. Check GTFOBins.
No SUID. No sudo. But a binary with cap_setuid+ep set by a junior admin who thought "capabilities are safer than SUID."
SolarGate's flagship server runs a root cron job sourcing a world-writable cleanup script. Inject your payload, wait 60 seconds, collect root.
Ready to get root?
Five machines. Five techniques. Full OSCP prep in one series.
💡 Suggested by community member tumtum — awarded the Feature Favourite flair for this idea.