ArunNetworkingPro
🕵️

Linux+ Break Room · Case 04

The stranger in the house

Someone is living here. They have the keys to every room. The owner can't even get in.

A name nobody recognises can use sudo for everything. Another account looks harmless, but Linux treats it exactly like root. The real keeper of the house can't log in, and even if they could, the lantern room is locked to them. And somewhere in the network config, a pretend network card is waiting to appear, if only someone could spell.

Case 04 of 10Services & usersSecurityNeeds sudo

⚠️ This case needs sudo

Get the case

Rule 4: read it before you run it, less breakroom-mission-04.sh. The top of the file lists everything it creates and how --clean removes it.

curl -O https://arunnetworkingpro.com/labs/breakroom-mission-04.sh
sudo bash breakroom-mission-04.sh

At any point, ask the house how many ghosts are left:

sudo bash breakroom-mission-04.sh --check

Part A: who's in the house?

A1

Count the roots

Linux decides who is root by UID, not by name. Find every account with UID 0.

Hint

Every account is one line in /etc/passwd, with fields split by :. The third field is the UID. awk -F: '$3 == 0' /etc/passwd.

A2

Evict the hidden root

Get rid of the extra UID-0 account. Careful: userdel won't do it, because it says the user is "currently used by process 1". Why would that be, and how else can you remove one line?

Hint

The account shares root's UID, so every root process looks like it belongs to it. Don't reach for userdel -r, -f or pkill: they'd hit root itself. sudo vipw edits /etc/passwd safely (then sudo vipw -s for /etc/shadow). Delete only the maintenance line.

A3

Who has the master key?

Find who can use sudo, and why. Then take the stranger's rights away.

Hint

sudo -l -U stranger shows what a user may run. The rule lives in /etc/sudoers.d/. Edit it with sudo visudo -f /etc/sudoers.d/breakroom-04.

Part B: let the keeper back in

B1

Locked out, twice

sudo su - keeper

It refuses. Fix every reason, one at a time, until you get a shell as keeper.

Hint

Read each error. "Account has expired": sudo chage -l keeper shows the dates, and chage -E -1 removes the expiry. "This account is currently not available": look at the last field of the keeper's /etc/passwd line, the login shell (usermod -s).

B2

The lantern room

sudo su - keeper -c 'cat /srv/breakroom-04/lantern.txt'

Permission denied. Let the keeper in without changing the file's permissions.

Hint

ls -l /srv/breakroom-04/lantern.txt: which group can read it? id keeper: is the keeper in it? usermod -aG adds a group. Never forget the -a, or you'll replace all their groups.

B3

Just enough power

The keeper needs to read the system logs with sudo journalctl, and nothing else. Write that rule.

Hint

In visudo -f /etc/sudoers.d/breakroom-04: keeper ALL=(root) /usr/bin/journalctl. Check with sudo -l -U keeper. Full paths only in sudoers.

Part C: something hiding in the network config

C1

The card that never appears

The caretaker left a draft network config, /srv/breakroom-04/90-breakroom-04.yaml, for a pretend card ghost4 at 10.66.6.4. It was never installed, which is lucky: one broken file in /etc/netplan can take the whole network down at the next boot. Test it somewhere safe first:

mkdir -p /tmp/np/etc/netplan
cp /srv/breakroom-04/90-breakroom-04.yaml /tmp/np/etc/netplan/
sudo netplan generate --root-dir /tmp/np

Fix it until netplan is happy, then install it (private, 600) and bring ghost4 up.

Hint

netplan names the file, line and column of the mistake: read the key it doesn't know very slowly. --root-dir checks a config without touching the real system. Install with sudo install -m 600 /tmp/np/etc/netplan/90-breakroom-04.yaml /etc/netplan/, then sudo netplan try (it rolls back by itself if you lose your connection; press Enter to keep it) or sudo netplan apply, and ip -br a show ghost4. Tidy up with sudo rm -rf /tmp/np. (No netplan, like on Debian? This part is skipped.)

✅ How you know you won

sudo bash breakroom-mission-04.sh --check says Verdict: 5/5. The only stranger was a config file. Case closed.

Answer key (no peeking until you've tried)

A1: root and maintenance both have UID 0. A2: sudo vipw and sudo vipw -s, delete the maintenance lines. A3: stranger ALL=(ALL) NOPASSWD: ALL in /etc/sudoers.d/breakroom-04; delete that line. B1: sudo chage -E -1 keeper, then sudo usermod -s /bin/bash keeper. B2: the file is root:lanterns 640; sudo usermod -aG lanterns keeper. B3: keeper ALL=(root) /usr/bin/journalctl. C1: adresses should be addresses; sudo install -m 600 it into /etc/netplan/; sudo netplan try or apply.

💥 Let it haunt you again

Run the script again. The haunting starts over, fresh:

sudo bash breakroom-mission-04.sh

Now do it without the hints. And when you're done for good: sudo bash breakroom-mission-04.sh --clean.

🧠 The ghost, explained

Verdict: not a ghost. The stranger was a sudoers line, the hidden root was a UID, and the locked-out keeper was an expiry date, a shell and a missing group.

Linux trusts numbers, not names. Permissions and root powers belong to UIDs and GIDs. A second account with UID 0 is root, whatever it's called. Auditing /etc/passwd for UID 0 is one of the first things security people check.

An account can be locked in many ways. Expired (chage), password locked (passwd -l), no login shell (/usr/sbin/nologin), or simply not in the right group. Each gives a different error, so read the error.

sudo is a list of promises. Each rule says who, on which host, as whom, may run what. Least privilege means naming the exact command (with its full path) instead of ALL. And NOPASSWD: ALL for an account nobody recognises is a flashing red light.

netplan writes the real config for you. On Ubuntu, YAML in /etc/netplan/ is turned into systemd-networkd or NetworkManager config by netplan generate, and netplan apply puts it live. netplan try rolls back automatically if you lose your connection. Red Hat uses NetworkManager (nmcli) directly, and Debian often uses /etc/network/interfaces.

← Case 03 · All cases · Case 05 → · Stuck, or found a better way? Email me

🎉 Got it, thank you!

Your comment just landed in my inbox. I read every one, and I'll reply by email.

🤔 That didn't go through

Something in the form looked off. Check your name, email and comment and try again, or just email me.

🐢 Whoa, slow down

That's a lot of comments in a short time, so the box is taking a breather. Try again later, or email me.

😴 The comment box is napping

My server is taking a quick break, so your comment couldn't be sent. Sorry! Please email me instead.

💬 Leave a comment

Stuck, found a better way, or just built it and want to brag? Tell me. It comes straight to my inbox (nothing is posted publicly), and I'll reply by email.

Your email is only used to reply to you. Never shared, never added to any list.