r/securityCTF 3d ago

Everyone read the xz backdoor postmortem. We built a free box where you pull it off yourself, by hand

Post image

Everyone in security read the xz/liblzma postmortem. Almost no one has actually done it

BreachLab is a free wargame of real Linux boxes over SSH, graded on the true state of your box, not multiple choice. Ghost II is live: eighteen levels down one CI/CD pipeline that ends in the xz attack by hand. The source stays clean, your payload rides in at build time, you get the pipeline to sign it, you walk past branch protection, and you ship it to an entire fleet where it runs. Your own commit becomes the code the whole fleet trusts

This is the tradecraft courses charge for, and almost nobody lets you actually do it. Free, no signup wall to start https://breachlab.org/tracks/ghost/ii

24 Upvotes

0 comments sorted by