Space Jam
Challenge
The webshell on 3000 (/?cmd=) exposed jordan’s easyaccess.py on 61432, where sudo find . -exec /bin/sh \; -quit gave root. bunny’s password was carrot123. /bin/cp had the SUID bit.
cp /root/root.txt /dev/stdout
Root flag 218f5ea7a4d711eef60171e5c92ba9e1. The king file had been set immutable with chattr removed, so I re-uploaded chattr.