Week Overview Mon – Fri · 10 hours total

Accounts, groups, and the Linux security model

Students who know Windows NTFS permissions will find a familiar mental model here — read, write, execute mapped to owner, group, and others — but implemented very differently. By Friday every student has created multiple users, assigned group-based file access, and understands how octal notation translates to rwx. Special permissions (SUID, SGID, sticky bit) close the week with real-world context.

Week at a glance

Monday
User Accounts

useradd, passwd, su, sudo, /etc/passwd and /etc/shadow explained

Tuesday
Permission Bits

chmod, octal notation, permission matrix lab — rwx vs. other

Wednesday
Groups & Ownership

groupadd, chown, chgrp, umask, group-based file access

Thursday
Special Permissions

SUID, SGID, sticky bit — /tmp, passwd, shared directories

Friday
Mini-Assessment 2

Written: permission theory, octal. Practical: multi-user access scenario.

⭐ OverTheWire Bandit Standing challenge — not assessed

Week 2 target: Levels 3–6

This week's Bandit levels are a perfect match for the lab content. Level 3 hides a password in a hidden file (ls -a). Level 4 requires finding the only human-readable file in a directory. Level 5 uses find with size and permission flags. Level 6 searches the whole system by owner and group — exactly what students practise in Lab 3 this week.

Bandit connection reminder
  • ssh bandit0@bandit.labs.overthewire.org -p 2220 — password: bandit0
  • Each level's password unlocks the next username (bandit1, bandit2, etc.)
  • Hints are on the website — commands only, no shared answers
Learning Outcomes By end of Week 2, students can…
Create & manage usersAdd users with useradd, set passwords, lock/unlock accounts, and explain /etc/passwd and /etc/shadow fields
Elevate privileges correctlyExplain the difference between su and sudo, enable root appropriately, and use sudo for admin tasks
Read & set permissionsInterpret rwx notation and octal values, use chmod in both symbolic and octal form
Manage groups & ownershipCreate groups, assign users, use chown and chgrp to change file ownership
Explain umaskDescribe how umask determines default permissions for new files and directories
Identify special permissionsExplain SUID, SGID, and sticky bit with real examples from the system
Monday Lecture + Lab 3 Part 1 · 2 hrs

User accounts — useradd, passwd, su, sudo, and the shadow file

0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:50
Lab 3 Pt 1
1:50–2:00
Debrief
Instructor note: The su vs. sudo distinction matters. Students often just sudo everything. Spend time on why sudo is preferred — it logs commands, limits blast radius, and doesn't require knowing the root password.
Tuesday Lecture + Lab 3 Part 2 · 2 hrs

Permission bits — chmod, octal notation, and the permission matrix

0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:50
Lab 3 Pt 2
1:50–2:00
Debrief
Key insight to drive home: Execute on a directory means traverse — without it, you cannot cd into it or access anything inside, even if you have read. This surprises students every time and is worth demonstrating live.
Wednesday Lecture + Lab 3 Part 3 · 2 hrs

Groups, chown, chgrp, and umask

0:00–0:10
Recap
0:10–0:35
Lecture
0:35–1:50
Lab 3 Pt 3
1:50–2:00
Debrief
Lab design note: The King's Landing scenario from the lab notes is intentionally flavourful — it makes the permission assignments memorable. Lean into it. Students remember "Tyrion gets full rights" better than "user A gets 7".
Thursday Lecture + guided exploration · 2 hrs

Special permissions — SUID, SGID, and the sticky bit

0:00–0:10
Recap
0:10–0:40
Lecture
0:40–1:45
Guided lab
1:45–1:55
Bonus
1:55–2:00
Wrap
Preview Friday: The assessment practical will present a scenario similar to today's lab — a set of users and files needing specific access. Students should be comfortable designing group structure and setting permissions without looking anything up.
Friday Mini-Assessment 2 · 2 hrs

Mini-Assessment 2 — Users & Permissions

0:00–0:25
Written
0:25–1:50
Practical
1:50–2:00
Review

Mini-Assessment 2 — Topic Coverage

TopicWeightFormat
Permission string interpretation (symbolic)15%Written
Octal conversion (both directions)15%Written
SUID / SGID / sticky bit — definitions and examples15%Written
su vs. sudo explanation5%Written
Create users, groups, directory structure20%Practical
Set correct permissions per specification20%Practical
Verify access by testing as correct users10%Practical

What you need ready before Monday

Lab 3 handout printed Both VMs running from Week 1 Mini-Assessment 2 printed (Friday) OverTheWire Bandit Level 3 link shared
← Week 1 Day 1 Lesson Plan → Week 3 → Course Outline