[ Donate ]

Level 11 → Level 12

Schedule Hijack · 660 pts · +50 first-blood bonus

First Blood Available

Mission

This challenge contains a scheduled task that executes a script referring to a command by its short name. The current search order for command lookup can be influenced by a user with write access to a specific directory. To solve the challenge, read /flag.

Starting toolkit (you may need more)

crontablscat

Why this matters in 2026

Scheduled tasks that use relative command names are legacy bugs that never die. Every DFIR engineer has found one within five minutes of landing on a compromised server, and every attacker who knows to look gets easy persistence from them.

Mitigation era: 2026-04 · rotation policy: levels may be refreshed as CVEs are patched out of distro defaults.

How to reach this level

Use the password for phantom11 that you captured on the previous level, then:

ssh phantom11@phantom.breachlab.org -p 2223

SSH endpoint is being provisioned. Follow @BreachLab for launch announcement.

Log in to submit flags and track progress.