Phantom Track

Level 4 → Level 5

Misplaced Power
ACT I380 pts+50 first-blood bonus
First Blood: @voxfox

Mission

Find a Linux capability granted to a scripting-language interpreter and abuse it to become root.

Why this matters in 2026

Capabilities replace SUID but are rarely audited. One misplaced privilege on an interpreter binary = full root.

Mitigation era: 2026-04 · rotation policy: levels may be refreshed as CVEs are patched out of distro defaults.

Connection Terminal

Use the password for phantom4 that you captured on the previous level, then:
ssh [email protected] -p 2223
SSH command copied to clipboard!

Flag Submission

Log in to submit flags and track progress.
🩸
First Blood captured by
ACTIVE RECORD