
This is an exercise built around CVE-2021-3560
This repository contains materials for a hands-on cybersecurity exercise centered on CVE-2021-3560, a privilege escalation vulnerability in polkit.
Discovered by GitHub Security Lab in 2021, this flaw allowed unprivileged Linux users to gain root access by exploiting a race condition in user credential handling.
The vulnerability affected multiple Linux distributions and was patched in mid-2021.
You are Sidewinder Swifty — a sly cyber-infiltrator known for slipping past digital defenses. You've gained low-level access to a target Ubuntu 20.04 machine. Your mission:
⚠️ Precision and timing are key. Success depends on your ability to emulate real-world attacker tradecraft.
This exercise will guide you through practical offensive security concepts, including:
scp and netcattarBy completing this challenge, you will:
This project is intended for educational and ethical research purposes only.
Do not use these techniques on systems you do not own or have explicit permission to test.
Do not use these techniques on any system you do not own or have explicit permission to test. Unauthorized access is illegal and unethical.