Operation Broken Chain

LONG · LINUX · difficulty 5 · ~80 min · 29 steps

Nothing was exploited. Every component did exactly what it was documented to do, and the data left anyway.

Briefing

09:04. Your object-storage bill has a spike in it: 4.1 terabytes of egress from a bucket that normally serves nothing, over eleven hours overnight. The bucket is fine. The permissions are fine. The role that read it is one of yours, it was assumed legitimately, and the cloud provider's logs will show a completely ordinary sequence of API calls. This is going to take you backwards through six systems that no single team owns, and at every hop the previous hop will look legitimate. Nothing here is an exploit. Follow the chain to the beginning and find the default nobody chose.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$