Mission
This challenge contains a scheduled task that executes a script referring to a command by its short name. The current search order for command lookup can be influenced by a user with write access to a specific directory. To solve the challenge, read /flag.
Starting toolkit (you may need more)
crontablscatWhy this matters in 2026
Scheduled tasks that use relative command names are legacy bugs that never die. Every DFIR engineer has found one within five minutes of landing on a compromised server, and every attacker who knows to look gets easy persistence from them.
Mitigation era: 2026-04 · rotation policy: levels may be refreshed as CVEs are patched out of distro defaults.
How to reach this level
Use the password for phantom11 that you captured on the previous level, then:
ssh phantom11@phantom.breachlab.org -p 2223
SSH endpoint is being provisioned. Follow @BreachLab for launch announcement.
Log in to submit flags and track progress.