Operation Broken Key

LOCKOUT · LINUX · difficulty 2 · ~20 min · 15 steps

Locked out of your own database server. Boot it back into your hands.

Briefing

01:40. You can no longer log into prod-db-01. Your SSH key is rejected, the root password you set is wrong, and your sudo rights are gone. The attacker changed the locks from the inside while they still had access. What they cannot change is how the machine boots. You have the console through the hypervisor. That console, plus the boot process, is the way back in — no exploit required, just an understanding of how Linux starts.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$