Linux+ Break Room · Case 04
The stranger in the house
Someone is living here. They have the keys to every room. The owner can't even get in.
A name nobody recognises can use sudo for everything. Another account looks harmless, but Linux treats it exactly like root. The real keeper of the house can't log in, and even if they could, the lantern room is locked to them. And somewhere in the network config, a pretend network card is waiting to appear, if only someone could spell.
⚠️ This case needs sudo
- Play it on a practice VM (a free Ubuntu VM, a spare Pi, a lab node), not a machine you care about.
- It creates users
stranger,maintenanceandkeeper, a grouplanterns,/etc/sudoers.d/breakroom-04, and (on Ubuntu) a netplan file for a pretend cardghost4. Your own user and the rest of sudoers are never changed.--cleanremoves it all. - Always edit sudoers with
visudo. A typo in a sudoers file can break sudo for everyone.visudochecks the file before saving. - Careful with the hidden root. It shares root's UID and home folder. Never
userdel -ror-fit (that deletes/root), and neverpkill -uit (that kills every root process).
Get the case
Rule 4: read it before you run it, less breakroom-mission-04.sh. The top of the file lists everything it creates and how --clean removes it.
curl -O https://arunnetworkingpro.com/labs/breakroom-mission-04.sh
sudo bash breakroom-mission-04.sh
At any point, ask the house how many ghosts are left:
sudo bash breakroom-mission-04.sh --check
Part A: who's in the house?
Count the roots
Linux decides who is root by UID, not by name. Find every account with UID 0.
Hint
Every account is one line in /etc/passwd, with fields split by :. The third field is the UID. awk -F: '$3 == 0' /etc/passwd.
Evict the hidden root
Get rid of the extra UID-0 account. Careful: userdel won't do it, because it says the user is "currently used by process 1". Why would that be, and how else can you remove one line?
Hint
The account shares root's UID, so every root process looks like it belongs to it. Don't reach for userdel -r, -f or pkill: they'd hit root itself. sudo vipw edits /etc/passwd safely (then sudo vipw -s for /etc/shadow). Delete only the maintenance line.
Who has the master key?
Find who can use sudo, and why. Then take the stranger's rights away.
Hint
sudo -l -U stranger shows what a user may run. The rule lives in /etc/sudoers.d/. Edit it with sudo visudo -f /etc/sudoers.d/breakroom-04.
Part B: let the keeper back in
Locked out, twice
sudo su - keeperIt refuses. Fix every reason, one at a time, until you get a shell as keeper.
Hint
Read each error. "Account has expired": sudo chage -l keeper shows the dates, and chage -E -1 removes the expiry. "This account is currently not available": look at the last field of the keeper's /etc/passwd line, the login shell (usermod -s).
The lantern room
sudo su - keeper -c 'cat /srv/breakroom-04/lantern.txt'Permission denied. Let the keeper in without changing the file's permissions.
Hint
ls -l /srv/breakroom-04/lantern.txt: which group can read it? id keeper: is the keeper in it? usermod -aG adds a group. Never forget the -a, or you'll replace all their groups.
Just enough power
The keeper needs to read the system logs with sudo journalctl, and nothing else. Write that rule.
Hint
In visudo -f /etc/sudoers.d/breakroom-04: keeper ALL=(root) /usr/bin/journalctl. Check with sudo -l -U keeper. Full paths only in sudoers.
Part C: something hiding in the network config
The card that never appears
The caretaker left a draft network config, /srv/breakroom-04/90-breakroom-04.yaml, for a pretend card ghost4 at 10.66.6.4. It was never installed, which is lucky: one broken file in /etc/netplan can take the whole network down at the next boot. Test it somewhere safe first:
mkdir -p /tmp/np/etc/netplan
cp /srv/breakroom-04/90-breakroom-04.yaml /tmp/np/etc/netplan/
sudo netplan generate --root-dir /tmp/npFix it until netplan is happy, then install it (private, 600) and bring ghost4 up.
Hint
netplan names the file, line and column of the mistake: read the key it doesn't know very slowly. --root-dir checks a config without touching the real system. Install with sudo install -m 600 /tmp/np/etc/netplan/90-breakroom-04.yaml /etc/netplan/, then sudo netplan try (it rolls back by itself if you lose your connection; press Enter to keep it) or sudo netplan apply, and ip -br a show ghost4. Tidy up with sudo rm -rf /tmp/np. (No netplan, like on Debian? This part is skipped.)
✅ How you know you won
sudo bash breakroom-mission-04.sh --check says Verdict: 5/5. The only stranger was a config file. Case closed.
Answer key (no peeking until you've tried)
A1: root and maintenance both have UID 0. A2: sudo vipw and sudo vipw -s, delete the maintenance lines. A3: stranger ALL=(ALL) NOPASSWD: ALL in /etc/sudoers.d/breakroom-04; delete that line. B1: sudo chage -E -1 keeper, then sudo usermod -s /bin/bash keeper. B2: the file is root:lanterns 640; sudo usermod -aG lanterns keeper. B3: keeper ALL=(root) /usr/bin/journalctl. C1: adresses should be addresses; sudo install -m 600 it into /etc/netplan/; sudo netplan try or apply.
💥 Let it haunt you again
Run the script again. The haunting starts over, fresh:
sudo bash breakroom-mission-04.shNow do it without the hints. And when you're done for good: sudo bash breakroom-mission-04.sh --clean.
🧠 The ghost, explained
Verdict: not a ghost. The stranger was a sudoers line, the hidden root was a UID, and the locked-out keeper was an expiry date, a shell and a missing group.
Linux trusts numbers, not names. Permissions and root powers belong to UIDs and GIDs. A second account with UID 0 is root, whatever it's called. Auditing /etc/passwd for UID 0 is one of the first things security people check.
An account can be locked in many ways. Expired (chage), password locked (passwd -l), no login shell (/usr/sbin/nologin), or simply not in the right group. Each gives a different error, so read the error.
sudo is a list of promises. Each rule says who, on which host, as whom, may run what. Least privilege means naming the exact command (with its full path) instead of ALL. And NOPASSWD: ALL for an account nobody recognises is a flashing red light.
netplan writes the real config for you. On Ubuntu, YAML in /etc/netplan/ is turned into systemd-networkd or NetworkManager config by netplan generate, and netplan apply puts it live. netplan try rolls back automatically if you lose your connection. Red Hat uses NetworkManager (nmcli) directly, and Debian often uses /etc/network/interfaces.
← Case 03 · All cases · Case 05 → · Stuck, or found a better way? Email me
🎉 Got it, thank you!
Your comment just landed in my inbox. I read every one, and I'll reply by email.
🤔 That didn't go through
Something in the form looked off. Check your name, email and comment and try again, or just email me.
🐢 Whoa, slow down
That's a lot of comments in a short time, so the box is taking a breather. Try again later, or email me.
😴 The comment box is napping
My server is taking a quick break, so your comment couldn't be sent. Sorry! Please email me instead.
💬 Leave a comment
Stuck, found a better way, or just built it and want to brag? Tell me. It comes straight to my inbox (nothing is posted publicly), and I'll reply by email.
Your email is only used to reply to you. Never shared, never added to any list.