October 1, 2026
Linux Capture The Flag Bandit Level 20
Netcat Listeners, Background Processes, and SetUID Binaries

By Red
2 min read
Bandit Level 20 builds on two concepts from previous levels โ SetUID binaries and Netcat โ and combines them into a challenge that requires two things to happen simultaneously on the same machine. It's a great exercise in understanding how processes and network connections work together in Linux.
If you'd like to follow what I did via video, feel free to check it out on YouTube below:
The Challenge
There's another SetUID binary in the home directory called suconnect. Here's what it does:
- It connects to localhost on a port you specify
- It reads a line of text from that connection
- It compares that text to the Level 20 password
- If it matches, it sends back the Level 21 password
In other words, you need to set up a listener on a port that has the Level 20 password ready to send, and then point suconnect at that port. The binary does the rest.
The Tools: Netcat and the & Operator
Netcat as a Listener
You've used Netcat before to connect to ports. This time you're using it in server mode โ having it listen for an incoming connection rather than initiate one. Two flags make this work:
-lโ listen for an incoming connection-pโ specify the port to listen on
This is exactly how Netcat is used in real penetration testing. When exploiting a vulnerable machine, a common technique is to set up a Netcat listener on your attack box, trigger an exploit on the target that sends a connection back to you, and catch a reverse shell when it arrives. The concept here is the same โ just on localhost.
The & Operator
Running two things at once from a single terminal requires one of them to run in the background. In Linux, appending & to a command does exactly that โ it starts the process and returns control of the terminal immediately, letting you run another command while the first one continues running behind the scenes.
The echo -n Command
The -n flag on echo suppresses the trailing newline that echo normally appends. This is important here because you want to send exactly the password and nothing extra โ an unexpected newline could cause the comparison to fail.
Solving the Challenge
First, confirm suconnect is in the home directory:
ls -lls -lRunning it without arguments shows the usage: suconnect <port>. It will connect to localhost on that port and handle the rest.
Now set up the Netcat listener with the Level 20 password piped in, running in the background. Choose any available port โ 1234 works fine:
echo -n '<Level 20 password>' | nc -l -p 1234 &echo -n '<Level 20 password>' | nc -l -p 1234 &Breaking this down:
echo -n '<password>'outputs the password without a trailing newline- | pipes that output into Netcat
nc -l -p 1234sets Netcat to listen on port 1234, ready to send the password to whatever connects- & runs the whole thing in the background
With the listener running, connect to it using suconnect:
./suconnect 1234./suconnect 1234suconnect connects to localhost on port 1234, receives the password from Netcat, compares it to the stored Level 20 password, finds a match, and prints the Level 21 password back to the terminal.
Key Commands Covered
nc -l -p <port>Start Netcat in listener mode on a specific portecho -n '<text>'Output text without a trailing newlinecommand &Run a command in the background./suconnect <port>Connect the SetUID binary to the listener on a given port
This level reinforces a few important ideas. First, Netcat is incredibly versatile โ it can initiate connections, listen for them, and pipe data in either direction. Second, the & operator is a fundamental part of working in Linux, particularly when you need processes to run concurrently. Third, understanding networking at the local level โ not just across machines, but on your own system โ is essential for both system administration and security work.
Feel free to check out my blog: coderedblog.io
Checkout my YouTube
Feel free to follow me on here and keep learning!