ZeroBox

RootMe writeup and attack path

RootMe is a easy Linux machine on TryHackMe that I solved myself. This page is my short attack path summary and the techniques it trains.

PlatformTryHackMe
Operating systemLinux
DifficultyEasy
Time to user18m
Time to root45m
User owned2026-08-15
Root owned2026-08-15
Relevant forOSCP

Attack path summary

Bypass PHP upload extension filter using .phtml on /panel, catch reverse shell, then escalate via /usr/bin/python SUID.

Techniques

File-Upload Bypass SUID-Python

Track RootMe in ZeroBox. Log your progress, notes and flags offline in your browser, and follow the pentest methodology checklist.

Open ZeroBox

RootMe belongs to TryHackMe. This page contains only my own notes.