Lab Environment

All CS487 labs are developed and graded on the SEED Ubuntu 20.04 VM. Using the same image as the graders removes an entire class of “it worked on my machine” problems: several labs depend on the exact shell that /bin/sh points to, on specific glibc behavior, and on kernel hardening settings that differ across distributions.

Getting the VM

  1. Download the pre-built SEED Ubuntu 20.04 image from the SEED website: https://seedsecuritylabs.org/labsetup.html
  2. Install a hypervisor:
    • Intel/AMD machines: VirtualBox (free) or VMware Workstation/Fusion.
    • Apple Silicon Macs: VirtualBox does not run the x86 image well. Use UTM or VMware Fusion with an ARM Ubuntu 20.04 image, or use the cloud option below.
  3. Follow SEED’s VM setup manual for your hypervisor (linked from the same page).

The default account is seed with password dees.

Other option

If your laptop cannot run the image, contact the instructor on Piazza to get a department Ubuntu VM.

Sanity check

Before you start Lab 1, confirm your VM behaves as expected:

$ lsb_release -d
Description:	Ubuntu 20.04.x LTS

$ ls -l /bin/sh
lrwxrwxrwx 1 root root 4 ... /bin/sh -> dash

$ which gcc zsh
/usr/bin/gcc
/usr/bin/zsh

$ id
uid=1000(seed) gid=1000(seed) groups=1000(seed),...

If zsh is missing, install it — Lab 1 needs it:

sudo apt-get update && sudo apt-get install -y zsh

Working habits that will save you time

  • Snapshot your VM before each lab. Several labs ask you to relink /bin/sh, create root-owned Set-UID binaries, or modify files under /etc. A snapshot turns “I broke my VM” into a two-minute rollback.

  • Undo global changes when the lab is done. In particular, if a lab has you point /bin/sh at zsh, put it back:

    sudo ln -sf /bin/dash /bin/sh
    
  • Take screenshots as you go, not at the end. Reproducing a transient observation for the report is far more painful than capturing it the first time.

  • Keep a scratch directory per lab, e.g. ~/cs487/lab1/, and keep every source file you write. You will be asked to include code in the report.