RootMe writeup and attack path
RootMe is a easy Linux machine on TryHackMe that I solved myself. This page is my short attack path summary and the techniques it trains.
| Platform | TryHackMe |
|---|---|
| Operating system | Linux |
| Difficulty | Easy |
| Time to user | 18m |
| Time to root | 45m |
| User owned | 2026-08-15 |
| Root owned | 2026-08-15 |
| Relevant for | OSCP |
Attack path summary
Bypass PHP upload extension filter using .phtml on /panel, catch reverse shell, then escalate via /usr/bin/python SUID.
Techniques
File-Upload Bypass SUID-Python
Track RootMe in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.
RootMe belongs to TryHackMe. This page contains only my own notes.