Linux Privesc: cron, PATH & Capabilities

intermediate Hands-on lab 40 min 3 tasksSubscription

Escalate to root three ways: hijack a writable root cron script, abuse a relative-PATH lookup in a privileged binary, and exploit a file with cap_setuid set.

This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.

Part of these paths

Unlock this lab

Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.

Updated 2026-06-15