Sign in to challenge friends to a staged breach and take on their challenges.
Back to matchesForfeit
Mission Briefing
Next breach in00:00:00
Breach fromBack to today
A nightly backup job at SecureArc Technologies archives admin credentials to an encrypted file. Find this week's backup key, decrypt the archive, and use what's inside to read the file in /root.
Shelluser@boosterbox:$0 commands
$
Breach complete! Solved in 0 commands.
View Stats
Reveal this day's solution
Past Breaches
SunMonTueWedThuFriSat
Pick a day to play its system. Days you've solved show your command count.
Back to gameInteractive Tutorial
How to Play Shell Breach
No account required to play
A new fake system every day, shared by everyone
Daily leaderboard ranked by fewest commands
Your progress is saved automatically
Goal
Read the mission briefing, explore the filesystem, and either submit the flag or cat the file it asks for - in as few commands as possible.
Commands
The grammar is plain and whitespace-split - no pipes, flags or wildcards.
ls [path]
List the contents of the current or a given directory.
cd <path>
Change directory. Supports .., ~, and relative or absolute paths.
pwd
Print the current directory.
cat <file>
Print a file's contents, or "Permission denied" if it's locked.
whoami
Print the current user.
su <user> <password>
Switch user, if the password matches.
ssh <ip> <user> <password>
Connect to a remote host, if the address and login both match.
decrypt <file> <key>
Unlock a file that needs a decryption key instead of a login.
submit <flag>
Submit the flag to solve the system.
clear
Clear the screen. Free - never sent to the server.
history
Show the commands you've typed this session. Also free.
A few extra commands exist just for atmosphere - they never count toward your score, so poke around freely:
ipconfig
Show this machine's fake network interfaces and IP address.
hostname
Print this machine's hostname.
uname
Print system information.
date
Print the current date and time.
uptime
Print how long this machine has been running.
ps
Print a list of running processes.
neofetch
Print a system summary.
ping
Ping this machine's own address.
id
Show your user and group IDs.
sudo
Try to run something as root. It won't go well.
cowsay
Get some wisdom from a cow.
matrix
Wake up...
Scoring
Fewest commands wins, not fastest time. An empty line, a typo, or an unrecognized command never counts against you and can be retried for free - and neither do any of the "just for fun" commands above. Every other command the engine actually attempts - even a wrong password or a guess at the wrong file - counts toward your total, whether it works or not.
A Full Walkthrough
Every day's system is different, but the shape of a solve is the same: look around, follow the clues, escalate if you need to, then finish the goal.
$ ls
notes.txt
$ cat notes.txt
Admin password is taped under the keyboard. Check /etc/motd.
$ cat /root/secret.txt
Permission denied.
$ cat /etc/motd
This week's password: Sunrise88!
$ su admin Sunrise88!
Switched to admin.
$ cat /root/secret.txt
CONFIDENTIAL - FLAG-7X2K9
$ submit FLAG-7X2K9
Correct! Breach complete in 6 commands.
What the Shell Looks Like
The whole game lives in this one dark screen - the mission briefing above it, then your commands and their output scrolling down as you type.
DesktopPhone
Strategy
ls and cat everything you can reach before trying to escalate - the clue you need is almost always sitting in a file you already have permission to read. If a file is locked, look for a password or key mentioned somewhere you've already read rather than guessing.
Replaying Past Days
The calendar below the terminal reaches back 30 days. Pick any past day to play it fresh in one sitting - there's no partial credit for stopping partway through and coming back later. If you get stuck, you can reveal that day's solution, but that marks it as given up rather than solved and keeps it off that day's leaderboard.
Challenge
Signed-in players can challenge each other. Pick an opponent, line up 1 to 5 systems, and set a command limit. You can also pick each system's passwords and decrypt keys yourself - your opponent still finds them in the system's files, so it's a way to leave a message rather than make it harder. Your opponent breaches the systems in order - submitting one flag connects them to the next machine - and the command count carries across every stage.
If they clear the last system within the limit, they win. If they run out of commands first, or forfeit, you win. The same scoring rules apply: typos and the just-for-fun commands are free. Unanswered and unfinished challenges expire after 7 days of no activity.
Want to try a lineup first? Tick Just me when setting up a challenge to start a solo run with the same stages and command limit - no opponent, and it never counts as a win or loss against anyone.
Back to game
Shell Breach Leaderboard
Break into a new fake system every day - fewest commands wins.How to play
About Shell Breach
Shell Breach
is a free online hacking puzzle - break into a fake computer by typing real
shell-style commands, no downloads and no account required to play.
Every day, everyone gets the exact same simulated system - the same files, the same fake user
accounts, the same hidden flag - and you explore it by typing commands like ls,
cd, cat, su, ssh, decrypt and submit.
The filesystem lives entirely on the server, so there's nothing to inspect in the browser's
network tab - every command is a real round trip, the same as being logged into an actual box.
Scoring is by fewest commands, not speed. A typo or an unrecognized command is
always free to retry, but any command the engine actually attempts counts, win or lose - so a
wrong password or a dead end costs you. Solve the day's system in as few commands as possible to
climb the leaderboard.
$ ls
notes.txt
$ cat notes.txt
Admin password is taped under the keyboard. Check /etc/motd.
$ su admin Sunrise88!
Switched to admin.
$ submit FLAG-7X2K9
Correct! Breach complete in 4 commands.
Four commands from a blank prompt to a solved system - reading a clue, escalating privileges, and
submitting the flag.
Want to test a friend? Sign in and send a challenge: line up one to five systems,
set a command limit, and even pick the passwords and decrypt keys they'll have to find. They breach
the systems one after another - submitting a flag connects them to the next machine - and win only
if they clear the last one before the limit runs out. Every finished challenge counts toward the
challenge leaderboard, and a solo run lets you try a lineup yourself first.
Missed a day? The replay calendar reaches back 30 days, so you can play any past system in one
sitting, or reveal its solution if you get stuck - a revealed day is marked honestly and never
counts toward that day's leaderboard.
Sign in to save your progress and keep your place on the leaderboard - or just start typing as a
guest.