SSH Brute Force / PersistenceBeginnerFree, no sign-up
Foothold on the Web Server
A case from the Linux Terminal Lab
Briefing
An internet-facing Linux web server took hundreds of SSH login failures overnight, then one of them worked. You are dropped into a real browser terminal on the live box with a read-only shell. Use the commands a responder actually uses - grep the auth log, read the cron jobs, cat the dropped script, decode the base64 - to prove the break-in and find how the attacker is keeping their way back in. No console, no multiple choice fishing: a shell and the truth on disk.
3393 events6 log sourcesabout 35 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Working a live Linux host from a terminal: ls, cd, cat, grep, find, awk, stat, file
- Reading /var/log/auth.log to tell a brute force from a successful login
- Finding cron, dropped-file and config-based persistence
- Decoding a base64 stager and extracting indicators to block
Maps to these certifications
Security+GSECGCIHBTL1eJPT
Log sources in the corpus
auth.log · syslog · nginx access & error · bash_history · cron · sshd_config
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.