suuqeasy
suuq is a small neighbourhood shop that put its website online before it was finished. Somewhere on that unfinished site a developer left a file they meant to delete — and that one forgotten file is the whole way in. This is an EASY Linux box and your first walk through the classic chain every engagement follows: scan the box to see what is exposed, enumerate the web server to find what was left behind, use it to land a foothold as an ordinary user, then hunt for the one misconfiguration that turns that foothold into full root. Along the way you will practise the staples — port scanning, directory enumeration, spotting reused credentials, and the single most important habit on any Linux box: asking what you are allowed to run as root. Capture the user flag first, then escalate and capture the root flag. If you get stuck, reveal a hint; if you are still stuck, the walkthrough is free on this box.
Linux20 + 20 pts0 solves#web#enumeration#credential-reuse