OTW: Bandit Writeup
Writeup on the Bandit challenges series by Over The Wire
Platform: Linux
Link: https://overthewire.org/wargames/bandit/ ↗

SSH Information
Host: bandit.labs.overthewire.org
Port: 2220
You start at Level 0 and try to “beat” or “finish” it. Finishing a level results in information on how to start the next level.
Username is the level that you are currently in. ie username for level 1 is bandit1
Level 0#
Hint: The password for the next level is stored in a file called readme located in the home directory.
ssh bandit0@bandit.labs.overthewire.org -p 2220 `
password: bandit0
bandit0@bandit:~$ ls
readme
bandit0@bandit:~$ pwd
/home/bandit0
bandit0@bandit:~$ cat readme
Congratulations on your first steps into the bandit game!!
Please make sure you have read the rules at https://overthewire.org/rules/
If you are following a course, workshop, walkthrough or other educational activity,
please inform the instructor about the rules as well and encourage them to
contribute to the OverTheWire community so we can keep these games free!
The password you are looking for is: ####REDACTED####plaintextLevel 1#
Hint: The password for the next level is stored in a file called - located in the home directory
ssh bandit1@bandit.labs.overthewire.org -p 2220
bandit1@bandit:~$ pwd
/home/bandit1
bandit1@bandit:~$ ls -la
total 24
-rw-r----- 1 bandit2 bandit1 33 Jun 24 14:59 -
drwxr-xr-x 2 root root 4096 Jun 24 14:59 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profile
bandit1@bandit:~$ file ./-
./-: ASCII text
bandit1@bandit:~$ cat ./-
####REDACTED####plaintextLevel 2#
Hint: The password for the next level is stored in a file called --spaces in this filename-- located in the home directory.
ssh bandit2@bandit.labs.overthewire.org -p 2220
bandit2@bandit:~$ pwd
/home/bandit2
bandit2@bandit:~$ ls -la
total 24
-rw-r----- 1 bandit3 bandit2 33 Jun 24 14:59 --spaces in this filename--
drwxr-xr-x 2 root root 4096 Jun 24 14:59 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profile
bandit2@bandit:~$ cat ./--spaces\ in\ this\ filename--
####REDACTED####plaintextLevel 3#
Hint: The password for the next level is stored in a hidden file in the inhere directory.
bandit3@bandit:~$ ls -la
total 24
drwxr-xr-x 3 root root 4096 Jun 24 14:59 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profile
drwxr-xr-x 2 root root 4096 Jun 24 14:59 inhere
bandit3@bandit:~$ cd inhere/
bandit3@bandit:~/inhere$ ls -la
total 12
drwxr-xr-x 2 root root 4096 Jun 24 14:59 .
drwxr-xr-x 3 root root 4096 Jun 24 14:59 ..
-rw-r----- 1 bandit4 bandit3 33 Jun 24 14:59 ...Hiding-From-You
bandit3@bandit:~/inhere$ cat ...Hiding-From-You
####REDACTED####plaintextLevel 4#
Hint: The password for the next level is stored in the only human-readable file in the inhere directory.
bandit4@bandit:~$ ls -la
total 24
drwxr-xr-x 3 root root 4096 Jun 24 14:59 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profile
drwxr-xr-x 2 root root 4096 Jun 24 14:59 inhere
bandit4@bandit:~$ cd inhere/
bandit4@bandit:~/inhere$ ls -la
total 48
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file00
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file01
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file02
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file03
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file04
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file05
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file06
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file07
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file08
-rw-r----- 1 bandit5 bandit4 33 Jun 24 14:59 -file09
drwxr-xr-x 2 root root 4096 Jun 24 14:59 .
drwxr-xr-x 3 root root 4096 Jun 24 14:59 ..plaintextThe command tail -n +1 outputs the entire contents of a file starting from the very first line
bandit4@bandit:~/inhere$ tail -n +1 ./*
==> ./-file00 <==
Y1[�b1���� ��ɂ�D¬1K0
3'���
==> ./-file01 <==
���kbj.j���W������ylbʒ���9az�
==> ./-file02 <==
���9����rf�VE�fQ�|��o��������
==> ./-file03 <==
o��{|���y�Ѭ���f��Y��D��x)O�zd�
==> ./-file04 <==
TAQ�c�a�u~�\��[���Z]���dS�� Nl��
==> ./-file05 <==
��;(1~5��Iv�L�;M�b{�#��LSv+��
==> ./-file06 <==
�Ğ
�ߴ���E'4���φ⠟�~)��`D
�
==> ./-file07 <==
====REDACTED====
==> ./-file08 <==
F$0����b�L������
�!�}�LWK�j�
==> ./-file09 <==
S0��!ž6���@�?H"�93j%A�,�8���z�plaintextThe command grep -I -H "" ./* will search for “everything” in a file with grep. -I tells grep to ignore binary files completely. -H forces it to print the filename.
bandit4@bandit:~/inhere$ grep -I -H "" ./*
./-file07:====REDACTED====plaintextLevel 5#
Hint: The password for the next level is stored in a file somewhere under the inhere directory and has all of the following properties:
- human-readable
- 1033 bytes in size
- not executable
bandit5@bandit:~$ ls
inhere
bandit5@bandit:~/inhere$ ls
maybehere00 maybehere02 maybehere04 maybehere06 maybehere08 maybehere10 maybehere12 maybehere14 maybehere16 maybehere18
maybehere01 maybehere03 maybehere05 maybehere07 maybehere09 maybehere11 maybehere13 maybehere15 maybehere17 maybehere19
bandit5@bandit:~/inhere$ ls maybehere00
-file1 -file2 -file3 spaces file1 spaces file2 spaces file3plaintextEach folder contains files like this.
We can use find command to find the file matching our criteria.
bandit5@bandit:~/inhere$ find . -type f -size 1033c ! -executable
./maybehere07/.file2
bandit5@bandit:~/inhere$ cat ./maybehere07/.file2
====REDACTED====plaintext-type f: Filters the search to regular files only,-size 1033c: Matches files that are exactly 1033 bytes in size (cstands for bytes).
Level 6#
Hint: The password for the next level is stored somewhere on the server and has all of the following properties:
- owned by user bandit7
- owned by group bandit6
- 33 bytes in size
bandit6@bandit:~$ ls -la
total 20
drwxr-xr-x 2 root root 4096 Jun 24 14:58 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profileplaintextThere’s nothing useful in the home folder.
Lets use the find command:
bandit6@bandit:~$ find / -type f -user bandit7 -group bandit6 -size 33c 2>/dev/null
/var/lib/dpkg/info/bandit7.password
cat /var/lib/dpkg/info/bandit7.password
====REDACTED====plaintext-userfilters by file owner and-groupfilter file group.2>/dev/nullis used to silence error messages by redirecting them to/dev/null.
Level 7#
Hint: The password for the next level is stored in the file data.txt next to the word millionth
bandit7@bandit:~$ ls
data.txt
bandit7@bandit:~$ grep "millionth" data.txt
millionth ====REDACTED====plaintextLevel 8#
Hint: The password for the next level is stored in the file data.txt and is the only line of text that occurs only once
bandit8@bandit:~$ ls
data.txt
bandit8@bandit:~$ sort data.txt | uniq -u
====REDACTED====plaintextsort: Rearranges the lines alphabetically. This is required because the next command (uniq) only compares consecutive lines.uniq -u: Filters the list and prints only the unique lines that appear exactly once in the file.-cwill display count of every line.
Level 9#
Hint: The password for the next level is stored in the file data.txt in one of the few human-readable strings, preceded by several ‘=’ characters.
bandit9@bandit:~$ strings data.txt | grep ====
cL0========== the
========== password
>========== is
R========== ====REDACTED====plaintext- strings - print the sequences of printable characters in files
Level 10#
Hint: The password for the next level is stored in the file data.txt, which contains base64 encoded data
bandit10@bandit:~$ ls
data.txt
bandit10@bandit:~$ base64 -d data.txt
The password is ====REDACTED====plaintextLevel 11#
Hint: The password for the next level is stored in the file data.txt, where all lowercase (a-z) and uppercase (A-Z) letters have been rotated by 13 positions
bandit11@bandit:~$ ls
data.txt
bandit11@bandit:~$ cat data.txt
Gur cnffjbeq vf TEBbmJCB8DlA0zTewHxVQ0JPLxMvDkeA
bandit11@bandit:~$ cat data.txt | tr 'A-Za-z' 'N-ZA-Mn-za-m'
The password is ====REDACTED====plaintexttr: Replaces characters from the first set with characters in the matching position of the second set.A-Za-z: Defines the source alphabet (uppercase A-Z, lowercase a-z).N-ZA-Mn-za-m: Defines the target alphabet shifted by 13 spaces (starting at N, wrapping around to A).
Level 12#
Hint: The password for the next level is stored in the file data.txt, which is a hexdump of a file that has been repeatedly compressed.
bandit12@bandit:~$ ls
data.txt
bandit12@bandit:~$ file data.txt
data.txt: ASCII text
bandit12@bandit:~$ cat data.txt
00000000: 1f8b 0808 b2f0 3b6a 0203 6461 7461 322e ......;j..data2.
00000010: 6269 6e00 0142 02bd fd42 5a68 3931 4159 bin..B...BZh91AY
00000020: 2653 59dc 0966 8300 001a ffff dff5 c5fe &SY..f..........
00000030: b8ef a7be bddb f8a7 febb ffc9 bfbf 9fbf ................
00000040: b77b bfff fbd9 7ffe 5fef efcf b001 3b19 .{......_.....;.
00000050: 9206 87a9 a068 0340 3400 341a 1a1a 0340 .....h.@4.4....@
00000060: 1a68 068d 1a00 0646 8000 0610 0d00 069a .h.....F........
00000070: 0640 683c a0d0 3d43 4d3d 4f51 b420 0680 .@h<..=CM=OQ. ..
00000080: d034 0000 0079 41a3 40d1 ea00 0f48 000d .4...yA.@....H..
00000090: 1a34 d1ea 7a83 d468 f441 a03d 469a 3400 .4..z..h.A.=F.4.
000000a0: 6400 00d0 f500 d019 01a0 6534 d0f2 8320 d.........e4...
000000b0: 7a8d 3200 0000 0034 1ea1 e900 d000 d006 z.2....4........
000000c0: 8000 681a 6834 001a 0000 0006 d400 f50f ..h.h4..........
000000d0: 507a 81fa a193 0142 1809 3e44 b214 426c Pz.....B..>D..Bl
000000e0: b74f a3a8 bbad 1594 edb6 f107 af89 5c5d .O............\]
000000f0: 4a31 234c c745 9085 a522 3fc7 8a68 2ae3 J1#L.E..."?..h*.
00000100: 7711 a0ea d795 527d c100 5da1 2783 2400 w.....R}..].'.$.
00000110: cbf5 1a40 2406 8e71 5365 27cb 01ed 5025 ...@$..qSe'...P%
00000120: 2623 64be 09cc 5f29 e33e ebaa cef0 a814 &#d..._).>......
00000130: a1d2 46b8 785c 5a2c a007 a388 d38b b49b ..F.x\Z,........
00000140: e734 d6e2 c9dc 2de3 7a0d 0792 6586 4748 .4....-.z...e.GH
00000150: e901 f017 5076 a0cc 6009 1e12 54a4 23dd ....Pv..`...T.#.
00000160: 1e33 d761 f76c f2a8 e56a d4e9 c80d 996e .3.a.l...j.....n
00000170: 6494 dfa7 5618 2f5c a486 0b53 eef5 4855 d...V./\...S..HU
00000180: 5f30 8da5 4e0a 123b c4f1 3209 b120 0bf2 _0..N..;..2.. ..
00000190: 9838 9754 2f21 ee96 1df2 9eb1 8682 1ae3 .8.T/!..........
000001a0: 7fd0 e58a 73c2 a955 c7ff 6ca2 349c ba62 ....s..U..l.4..b
000001b0: 7885 8425 4fdc 6346 43e6 f44e 84ad ef1c x..%O.cFC..N....
000001c0: 981f 6080 aa78 3467 401f 3e9e b6d3 dda9 ..`..x4g@.>.....
000001d0: 669a 3a81 0332 6d67 5800 f837 683f 04a6 f.:..2mgX..7h?..
000001e0: 0871 f24f 6c87 3b10 03c0 fa0c ced1 7bbc .q.Ol.;.......{.
000001f0: 7f4d 7906 abf6 91fc 403d a92c c863 8966 .My.....@=.,.c.f
00000200: 4cc6 2b9b c8b2 2058 36a0 b385 347b 299a L.+... X6...4{).
00000210: 51f2 1fa0 e32b 9669 bc78 8209 923b 0fca Q....+.i.x...;..
00000220: c29e 30a2 aacf 65b5 696e f7cb a5af 9b6c ..0...e.in.....l
00000230: e6cd 4413 f7f0 6200 1c3c 67d9 d917 ddff ..D...b..<g.....
00000240: 9c50 2d14 54ca 1c86 6835 2418 cb8b 2e42 .P-.T...h5$....B
00000250: bc5d c914 e142 4370 259a 0c7f 1988 6542 .]...BCp%.....eB
00000260: 0200 00 ...plaintextbandit12@bandit:~$ mktemp -d
/tmp/tmp.iyflICIAxQ
bandit12@bandit:~$ cp data.txt /tmp/tmp.iyflICIAxQ
bandit12@bandit:~$ cd /tmp/tmp.iyflICIAxQ
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ ls
data.txtplaintext- The
xxdcommand converts binary files into hexadecimal dumps for inspection and debugging. We can also converts hexadecimal dumps back into the original binary files by usingxxd -r
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ mv data.txt hex.txt
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ xxd -r hex.txt > comp_bin
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file comp_bin
comp_bin: gzip compressed data, was "data2.bin", last modified: Wed Jun 24 14:58:58 2026, max compression, from Unix, original size modulo 2^32 578plaintextWe get a gzip file.
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ gunzip -c comp_bin > data1
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data1
data1: bzip2 compressed data, block size = 900kplaintextWe get a bzip file.
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ bunzip2 -c data1 > data2
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data2
data2: gzip compressed data, was "data4.bin", last modified: Wed Jun 24 14:58:58 2026, max compression, from Unix, original size modulo 2^32 20480plaintextWe get a gzip file.
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ gunzip -c data2 > data3
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data3
data3: POSIX tar archive (GNU)plaintextWe get a tar file.
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ tar -xf data3
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ ls
comp_bin data1 data2 data3 data5.bin hex.txt
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data5.bin
data5.bin: POSIX tar archive (GNU)plaintextAgain a tar file
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ tar -xf data5.bin
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ ls
comp_bin data1 data2 data3 data5.bin data6.bin hex.txt
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data6.bin
data6.bin: bzip2 compressed data, block size = 900kplaintextA bzip file
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ bunzip2 -c data6.bin > data7.bin
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data7.bin
data7.bin: POSIX tar archive (GNU)plaintextA tar file
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ tar -xf data7.bin
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ ls
comp_bin data1 data2 data3 data5.bin data6.bin data7.bin data8.bin hex.txt
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data8.bin
data8.bin: gzip compressed data, was "data9.bin", last modified: Wed Jun 24 14:58:58 2026, max compression, from Unix, original size modulo 2^32 49plaintextA gzip file
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ gunzip -c data8.bin > data9.bin
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ file data9.bin
data9.bin: ASCII textplaintextFinally a text file!!!
bandit12@bandit:/tmp/tmp.iyflICIAxQ$ cat data9.bin
The password is ====REDACTED====plaintextLevel 13#
Hint: The password for the next level is stored in /etc/bandit_pass/bandit14 and can only be read by user bandit14. For this level, you don’t get the next password, but you get a private SSH key that can be used to log into the next level. Look at the commands that logged you into previous bandit levels, and find out how to use the key for this level.
If you need help with this level: a hint file can be found in the home directory.
Make sure to read the error messages as they are informative.
bandit13@bandit:~$ ls
HINT sshkey.private
bandit13@bandit:~$ ls -la /etc/bandit_pass/bandit14
-r-------- 1 bandit14 bandit14 33 Jun 24 14:58 /etc/bandit_pass/bandit14
bandit13@bandit:~$ cat /etc/bandit_pass/bandit14
cat: /etc/bandit_pass/bandit14: Permission deniedplaintextOn local machine:
> scp -P 2220 bandit13@bandit.labs.overthewire.org:sshkey.private .
> ls -la
.rw-r-----@ 2.6k neo neo 26 Jul 18:47 sshkey.private
> chmod 600 sshkey.private
> ssh bandit14@bandit.labs.overthewire.org -p 2220 -i sshkey.privateplaintextNow you are in bandit14.
bandit14@bandit:~$ cat /etc/bandit_pass/bandit14
====REDACTED====plaintextLevel 14#
Hint: The password for the next level can be retrieved by submitting the password of the current level to port 30000 on localhost.
bandit14@bandit:~$ telnet localhost 30000
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
====REDACTED==== # Enter password of current level here.
Correct!
====REDACTED====
Connection closed by foreign host.plaintextWe can also use netcat:
bandit14@bandit:~$ netcat localhost 30000
====REDACTED====
Correct!
====REDACTED====plaintextLevel 15#
Hint: The password for the next level can be retrieved by submitting the password of the current level to port 30001 on localhost using SSL/TLS encryption.
ncat is an alternative implementation of netcat/nc by nmap.
bandit15@bandit:~$ ncat localhost 30001 --ssl
====REDACTED==== # Enter password of current level here.
Correct!
====REDACTED====plaintextWe can also use the openssl tool.
bandit15@bandit:~$ openssl s_client -connect localhost:30001
Connecting to 127.0.0.1
CONNECTED(00000003)
Can't use SSL_get_servername
depth=0 CN=SnakeOil
verify error:num=18:self-signed certificate
verify return:1
depth=0 CN=SnakeOil
verify return:1
---
Certificate chain
0 s:CN=SnakeOil
i:CN=SnakeOil
a:PKEY: RSA, 4096 (bit); sigalg: sha256WithRSAEncryption
v:NotBefore: Jun 10 03:59:50 2024 GMT; NotAfter: Jun 8 03:59:50 2034 GMT
...
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: rsa_pss_rsae_sha256
Negotiated TLS1.3 group: X25519MLKEM768
---
SSL handshake has read 3191 bytes and written 1613 bytes
Verification error: self-signed certificate
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Protocol: TLSv1.3
Server public key is 4096 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 18 (self-signed certificate)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: C03D963116A90BA69665CDC60C931A69186603DA2AFB09E6D4423FFCEFBB095E
...
---
read R BLOCK
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_AES_256_GCM_SHA384
Session-ID: 39CAD34C90D89C48EEB49C8544B2DB9649C993CAC2795A1EFDD903F9AD776C2A
...
---
read R BLOCK
====REDACTED====
Correct!
====REDACTED====
closedplaintextLevel 16#
Hint: The credentials for the next level can be retrieved by submitting the password of the current level to a port on localhost in the range 31000 to 32000. First find out which of these ports have a server listening on them. Then find out which of those speak SSL/TLS and which don’t. There is only 1 server that will give the next credentials, the others will simply send back to you whatever you send to it.
bandit16@bandit:~$ nmap localhost -p 31000-32000 -sV
Starting Nmap 7.98 ( https://nmap.org ) at 2026-07-26 17:00 +0000
Nmap scan report for localhost (127.0.0.1)
Host is up (0.00015s latency).
Other addresses for localhost (not scanned): ::1
Not shown: 996 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
31046/tcp open echo
31518/tcp open ssl/echo
31691/tcp open echo
31790/tcp open ssl/unknown
31960/tcp open echo
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port31790-TCP:V=7.98%T=SSL%I=7%D=7/26%Time=6A663D4C%P=x86_64-pc-linux-g
SF:nu%r(GenericLines,32,"Wrong!\x20Please\x20enter\x20the\x20correct\x20cu
SF:rrent\x20password\.\n")%r(GetRequest,32,"Wrong!\x20Please\x20enter\x20t
SF:he\x20correct\x20current\x20password\.\n")%r(HTTPOptions,32,"Wrong!\x20
SF:Please\x20enter\x20the\x20correct\x20current\x20password\.\n")%r(RTSPRe
SF:quest,32,"Wrong!\x20Please\x20enter\x20the\x20correct\x20current\x20pas
SF:sword\.\n")%r(Help,32,"Wrong!\x20Please\x20enter\x20the\x20correct\x20c
SF:urrent\x20password\.\n")%r(FourOhFourRequest,32,"Wrong!\x20Please\x20en
SF:ter\x20the\x20correct\x20current\x20password\.\n")%r(LPDString,32,"Wron
SF:g!\x20Please\x20enter\x20the\x20correct\x20current\x20password\.\n")%r(
SF:SIPOptions,32,"Wrong!\x20Please\x20enter\x20the\x20correct\x20current\x
SF:20password\.\n");
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 122.89 secondsplaintextConnecting to port 31790
bandit16@bandit:~$ ncat localhost 31790 --ssl
kS0Hf0u5HiXFwKMKFqXvPdOTNGGa0X8V
Correct!
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
====REDACTED_FOR_BREVITY====
Pfos/2C+rbNuHjAAAADnJ1ZHlAbG9jYWxob3N0AQIDBA==
-----END OPENSSH PRIVATE KEY-----plaintextLevel 17#
Hint: There are 2 files in the homedirectory: passwords.old and passwords.new. The password for the next level is in passwords.new and is the only line that has been changed between passwords.old and passwords.new
Copy the ssh key from the previous level.
nano sshkey.private.17
chmod 600 sshkey.private.17 ssh bandit17@bandit.labs.overthewire.org -p 2220 -i sshkey.private.17plaintextLogged into bandit17
bandit17@bandit:~$ ls
passwords.new passwords.old
bandit17@bandit:~$ diff passwords.old passwords.new
42c42
< icUh23IUytZLIYhcCaXL18agiSIqymBc
---
> OQxXZjELndr====REDACTED====plaintextLevel 18#
Hint: The password for the next level is stored in a file readme in the homedirectory. Unfortunately, someone has modified .bashrc to log you out when you log in with SSH.
We can use scp
scp -P 2220 bandit18@bandit.labs.overthewire.org:readme .
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit18@bandit.labs.overthewire.org's password:
readme
cat readme
KpsOfPkcP7i1====REDACTED====plaintextLevel 19#
Hint: To gain access to the next level, you should use the setuid binary in the homedirectory. Execute it without arguments to find out how to use it. The password for this level can be found in the usual place (/etc/bandit_pass), after you have used the setuid binary.
bandit19@bandit:~$ ls -l
total 16
-rwsr-x--- 1 bandit20 bandit19 14880 Jun 24 14:59 bandit20-doplaintextWe can see that the file is called bandit20-do and when we list the details of the file we can see that the binary file can be executed by the current user (bandit19) and it is owned by bandit20.
bandit19@bandit:~$ ./bandit20-do
Run a command as another user.
Example: ./bandit20-do whoami
bandit19@bandit:~$ ./bandit20-do whoami
bandit20plaintextWe observe that when we use the binary file we are assigned the uid for bandit20 as well which means we can run commands as if we are bandit20
bandit19@bandit:~$ ./bandit20-do cat /etc/bandit_pass/bandit20
4pIjcu====REDACTED====plaintextLevel 20#
Hint: There is a setuid binary in the homedirectory that does the following: it makes a connection to localhost on the port you specify as a commandline argument. It then reads a line of text from the connection and compares it to the password in the previous level (bandit20). If the password is correct, it will transmit the password for the next level (bandit21).
bandit20@bandit:~$ ls -l
total 16
-rwsr-x--- 1 bandit21 bandit20 15604 Jun 24 14:59 suconnect
bandit20@bandit:~$ ./suconnect
Usage: ./suconnect <portnumber>
This program will connect to the given port on localhost using TCP. If it receives the correct password from the other side, the next password is transmitted back.plaintextSo we need to set up a listener that will return the previous level password if we connect to it.
bandit20@bandit:~$ echo 4pIjcunZ0====REDACTED==== | nc -lp 1234 &
[1] 186plaintextWe use & at the end of the command to run it in the background.
bandit20@bandit:~$ jobs
[1]+ Running echo 4pIjcunZ0f====REDACTED==== | nc -lp 1234 &plaintextConnecting to it using the given binary.
bandit20@bandit:~$ ./suconnect 1234
Read: 4pIjcunZ0fK2====REDACTED====
Password matches, sending next password
bW9kBv5WC3====REDACTED====
[1]+ Done echo 4pIjcunZ0fK2====REDACTED==== | nc -lp 1234plaintextLevel 21#
Hint: A program is running automatically at regular intervals from cron, the time-based job scheduler. Look in /etc/cron.d/ for the configuration and see what command is being executed.
bandit21@bandit:~$ ls -l /etc/cron.d/
total 36
-r--r----- 1 root root 47 Jun 24 14:59 behemoth4_cleanup
-rw-r--r-- 1 root root 127 Jul 3 16:19 clean_tmp
-rw-r--r-- 1 root root 120 Jun 24 14:59 cronjob_bandit22
-rw-r--r-- 1 root root 122 Jun 24 14:59 cronjob_bandit23
-rw-r--r-- 1 root root 120 Jun 24 14:59 cronjob_bandit24
-rw-r--r-- 1 root root 188 Feb 13 12:17 e2scrub_all
-r--r----- 1 root root 48 Jun 24 15:01 leviathan5_cleanup
-rw------- 1 root root 138 Jun 24 15:01 manpage3_resetpw_job
-rwx------ 1 root root 52 Jun 24 15:03 otw-tmp-dir
bandit21@bandit:~$ cat /etc/cron.d/cronjob_bandit22
@reboot bandit22 /usr/bin/cronjob_bandit22.sh &> /dev/null
* * * * * bandit22 /usr/bin/cronjob_bandit22.sh &> /dev/null
bandit21@bandit:~$ ls -l /usr/bin/cronjob_bandit22.sh
-rwxr-x--- 1 bandit22 bandit21 130 Jun 24 14:59 /usr/bin/cronjob_bandit22.sh
bandit21@bandit:~$ cat /usr/bin/cronjob_bandit22.sh
#!/bin/bash
chmod 644 /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgv
cat /etc/bandit_pass/bandit22 > /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgvplaintextWe can see it copies the password to a file at /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgv
bandit21@bandit:~$ ls -l /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgv
-rw-r--r-- 1 bandit22 bandit22 33 Jul 26 17:51 /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgv
bandit21@bandit:~$ cat /tmp/t7O6lds9S0RqQh9aMcz6ShpAoZKF7fgv
RYVux2rHEm9tiXHmLFzuR7Vhx6AZQMEzplaintextLevel 22#
Hint: A program is running automatically at regular intervals from cron, the time-based job scheduler. Look in /etc/cron.d/ for the configuration and see what command is being executed.
bandit22@bandit:~$ ls /etc/cron.d
behemoth4_cleanup clean_tmp cronjob_bandit22 cronjob_bandit23 cronjob_bandit24 e2scrub_all leviathan5_cleanup manpage3_resetpw_job otw-tmp-dir
bandit22@bandit:~$ cat /etc/cron.d/cronjob_bandit23
@reboot bandit23 /usr/bin/cronjob_bandit23.sh &> /dev/null
* * * * * bandit23 /usr/bin/cronjob_bandit23.sh &> /dev/nullplaintextWe can see a script
bandit22@bandit:~$ ls -l /usr/bin/cronjob_bandit23.sh
-rwxr-x--- 1 bandit23 bandit22 211 Jun 24 14:59 /usr/bin/cronjob_bandit23.sh
bandit22@bandit:~$ cat /usr/bin/cronjob_bandit23.sh
#!/bin/bash
myname=$(whoami)
mytarget=$(echo I am user $myname | md5sum | cut -d ' ' -f 1)
echo "Copying passwordfile /etc/bandit_pass/$myname to /tmp/$mytarget"
cat /etc/bandit_pass/$myname > /tmp/$mytargetplaintextIt copies the password to file in /tmp. To get file name, we have to know the $mytarget which is the value of $(echo I am user $myname | md5sum | cut -d ' ' -f 1) where $myname is the output of $whoami which will be bandit23 since the file is owned by user bandit23.
bandit22@bandit:~$ echo I am user bandit23 | md5sum | cut -d ' ' -f 1
8ca319486bfbbc3663ea0fbe81326349
bandit22@bandit:~$ cat /tmp/8ca319486bfbbc3663ea0fbe81326349
gKXDTA====REDACTED====plaintextLevel 23#
Hint: A program is running automatically at regular intervals from cron, the time-based job scheduler. Look in /etc/cron.d/ for the configuration and see what command is being executed.
NOTE: This level requires you to create your own first shell-script.
bandit23@bandit:~$ ls /etc/cron.d/
behemoth4_cleanup clean_tmp cronjob_bandit22 cronjob_bandit23 cronjob_bandit24 e2scrub_all leviathan5_cleanup manpage3_resetpw_job otw-tmp-dir
bandit23@bandit:~$ cat /etc/cron.d/cronjob_bandit24
@reboot bandit24 /usr/bin/cronjob_bandit24.sh &> /dev/null
* * * * * bandit24 /usr/bin/cronjob_bandit24.sh &> /dev/null
bandit23@bandit:~$ ls -l /usr/bin/cronjob_bandit24.sh
-rwxr-x--- 1 bandit24 bandit23 438 Jun 24 14:59 /usr/bin/cronjob_bandit24.shplaintextbandit23@bandit:~$ cat /usr/bin/cronjob_bandit24.sh
#!/bin/bash
shopt -s nullglob
myname=$(whoami)
cd /var/spool/"$myname"/foo || exit
echo "Executing and deleting all scripts in /var/spool/$myname/foo:"
for i in * .*;
do
if [ "$i" != "." ] && [ "$i" != ".." ];
then
echo "Handling $i"
owner="$(stat --format "%U" "./$i")"
if [ "${owner}" = "bandit23" ] && [ -f "$i" ]; then
timeout -s 9 60 "./$i"
fi
rm -rf "./$i"
fiplaintextAny script we write in /var/spool/bandit24/foo will be run by the cronjob script as the bandit24 user.
save the following script at /var/spool/bandit24/foo/script.sh
#!/bin/bash
myname=$(whoami)
cat /etc/bandit_pass/$myname > /tmp/bandit_24_temp_passbashbandit23@bandit:~$ nano /var/spool/bandit24/foo/script.sh
Unable to create directory /home/bandit23/.local/share/nano/: No such file or directory
It is required for saving/loading search history or cursor positions.
bandit23@bandit:~$ chmod +x /var/spool/bandit24/foo/script.sh
bandit23@bandit:~$ ls -l /var/spool/bandit24/foo/script.sh
-rwxrwxr-x 1 bandit23 bandit23 73 Jul 26 18:18 /var/spool/bandit24/foo/script.shplaintextNow when the cronjob runs, the script will get executed and the passwrod will be written to the /tmp/bandit_24_temp_pass file.
bandit23@bandit:~$ cat /tmp/bandit_24_temp_pass
hVQMk3lJNs====REDACTED====plaintextLevel 24#
Hint: A daemon is listening on port 30002 and will give you the password for bandit25 if given the password for bandit24 and a secret numeric 4-digit pincode. There is no way to retrieve the pincode except by going through all of the 10000 combinations, called brute-forcing.
You do not need to create new connections each time
bandit24@bandit:~$ netcat localhost 30002
I am the pincode checker for user bandit25. Please enter the password for user bandit24 and the secret pincode on a single line, separated by a space.
hVQMk3lJNsmQ7VF3ubyrNNBom7BOgVXv 1234
Wrong! Please enter the correct current password and pincode. Try again.
^CplaintextWe need to bruteforce the pin by looping from 0000 to 9999. We can use the following command:
for i in {0000..9999}; do echo "hVQMk3lJNsmQ7VF3ubyrNNBom7BOgVXv $i"; done | nc localhost 30002bashbandit24@bandit:~$ for i in {0000..9999}; do echo "hVQMk3lJNsmQ7VF3ubyrNNBom7BOgVXv $i"; done | nc localhost 30002
I am the pincode checker for user bandit25. Please enter the password for user bandit24 and the secret pincode on a single line, separated by a space.
Wrong! Please enter the correct current password and pincode. Try again.
Wrong! Please enter the correct current password and pincode. Try again.
Wrong! Please enter the correct current password and pincode. Try again.
Wrong! Please enter the correct current password and pincode. Try again.
...
Wrong! Please enter the correct current password and pincode. Try again.
Correct!
The password of user bandit25 is SoHfqMOEqI====REDACTED====plaintextLevel 25#
Hint: Logging in to bandit26 from bandit25 should be fairly easy… The shell for user bandit26 is not /bin/bash, but something else. Find out what it is, how it works and how to break out of it.
bandit25@bandit:~$ ls
bandit26.sshkeyplaintextWe can see an ssh key for bandit26 in home.
To know what shell bandit26 is using we can check the /etc/passwd file.
bandit25@bandit:~$ cat /etc/passwd | grep bandit26
bandit26:x:11026:11026:bandit level 26:/home/bandit26:/usr/bin/showtextplaintextInspecting /usr/bin/showtext
bandit25@bandit:~$ cat /usr/bin/showtext
#!/bin/sh
export TERM=linux
exec more ~/text.txt
exit 0plaintextWe can see showtext is a script that opens a file called ’text.txt’ with the more program.
Let’s try logging into bandit26:
scp -P 2220 bandit25@bandit.labs.overthewire.org:bandit26.sshkey .
chmod 600 bandit26.sshkey
ssh bandit26@bandit.labs.overthewire.org -p 2220 -i bandit26.sshkey
...
_ _ _ _ ___ __
| | | (_) | |__ \ / /
| |__ __ _ _ __ __| |_| |_ ) / /_
| '_ \ / _` | '_ \ / _` | | __| / / '_ \
| |_) | (_| | | | | (_| | | |_ / /| (_) |
|_.__/ \__,_|_| |_|\__,_|_|\__|____\___/
Connection to bandit.labs.overthewire.org closed.plaintextWhen trying to log in, we see that the connection is closed because ‘/usr/bin/showtext’ is executed.
The text in ’text.txt’ is very short, meaning the whole text can immediately be displayed. more does not need to go into command/interactive mode. If we make the terminal window smaller, more will go into command mode. We can then use v to go into vim.
Now rescale the terminal window and try connecting.
Vim is now opened as bandit26 and we can do different things to retrieve the password.
With :e /etc/bandit\_pass/bandit26 we can open the password file and read the password.
If we want a shell, we can use the :shell command that vim offers. This command, however, uses the user’s default shell. What we need to do instead is to set the default shell of the user in vim to a useful shell, like \bin\bash by running :set shell=/bin/bash and then use :shell. We have a bash shell as bandit26.
bandit26@bandit:~$ whoami
bandit26
bandit26@bandit:~$ cat /etc/bandit_pass/bandit26
jHdv2ELQh====REDACTED====plaintextTo exit from the shell, type exit first to exit from bash and then you will reach vim, press esc and then type :q! to exit, if still in more, press the spacebar.
Level 26#
Hint: Good job getting a shell! Now hurry and grab the password for bandit27!
Use the shell from the previous level to continue.
bandit26@bandit:~$ ls -l
total 20
-rwsr-x--- 1 bandit27 bandit26 14880 Jun 24 14:59 bandit27-do
-rw-r----- 1 bandit26 bandit26 258 Jun 24 14:59 text.txt
bandit26@bandit:~$ cat text.txt
_ _ _ _ ___ __
| | | (_) | |__ \ / /
| |__ __ _ _ __ __| |_| |_ ) / /_
| '_ \ / _` | '_ \ / _` | | __| / / '_ \
| |_) | (_| | | | | (_| | | |_ / /| (_) |
|_.__/ \__,_|_| |_|\__,_|_|\__|____\___/
bandit26@bandit:~$ ./bandit27-do
Run a command as another user.
Example: ./bandit27-do id
bandit26@bandit:~$ ./bandit27-do id
uid=11026(bandit26) gid=11026(bandit26) euid=11027(bandit27) groups=11026(bandit26)
bandit26@bandit:~$ ./bandit27-do cat /etc/bandit_pass/bandit27
STJLJBRR====REDACTED====plaintextLevel 27#
Hint: There is a git repository at ssh://bandit27-git@bandit.labs.overthewire.org/home/bandit27-git/repo via the port 2220. The password for the user bandit27-git is the same as for the user bandit27.
From your local machine (not the OverTheWire machine!), clone the repository and find the password for the next level. This needs git installed locally on your machine.
git clone ssh://bandit27-git@bandit.labs.overthewire.org:2220/home/bandit27-git/repo
Cloning into 'repo'...
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit27-git@bandit.labs.overthewire.org's password:
remote: Enumerating objects: 3, done.
remote: Counting objects: 100% (3/3), done.
remote: Compressing objects: 100% (2/2), done.
remote: Total 3 (delta 0), reused 0 (delta 0), pack-reused 0 (from 0)
Receiving objects: 100% (3/3), done.plaintext❯ cd repo
❯ ls -la
drwxr-xr-x@ - neo 27 Jul 00:44 .git/
.rw-r--r--@ 68 neo 27 Jul 00:44 README
❯ cat README
The password to the next level is: y8Yd2ssKc====REDACTED====plaintextLevel 28#
Hint: There is a git repository at ssh://bandit28-git@bandit.labs.overthewire.org/home/bandit28-git/repo via the port 2220. The password for the user bandit28-git is the same as for the user bandit28.
From your local machine (not the OverTheWire machine!), clone the repository and find the password for the next level. This needs git installed locally on your machine.
❯ git clone ssh://bandit28-git@bandit.labs.overthewire.org:2220/home/bandit28-git/repo bandit28_repo
Cloning into 'bandit28_repo'...
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit28-git@bandit.labs.overthewire.org's password:
remote: Enumerating objects: 9, done.
remote: Counting objects: 100% (9/9), done.
remote: Compressing objects: 100% (6/6), done.
remote: Total 9 (delta 2), reused 0 (delta 0), pack-reused 0 (from 0)
Receiving objects: 100% (9/9), done.
Resolving deltas: 100% (2/2), done.
❯ cd bandit28_repo
❯ ls
README.md
❯ cat README.md
# Bandit Notes
Some notes for level29 of bandit.
## credentials
- username: bandit29
- password: xxxxxxxxxxplaintextChecking git logs
❯ git log
commit e2e1de5396037bafb23e9bb37c12ebea9b911cfd (HEAD -> master, origin/master, origin/HEAD)
Author: Morla Porla <morla@overthewire.org>
Date: Wed Jun 24 14:59:20 2026 +0000
fix info leak
commit 2678cfadd8f2a347bc23e1ea491f702e5b184709
Author: Morla Porla <morla@overthewire.org>
Date: Wed Jun 24 14:59:20 2026 +0000
add missing data
commit 9530d526c22b9e6e6ae11070ef8ff8ee21eb2e02
Author: Ben Dover <noone@overthewire.org>
Date: Wed Jun 24 14:59:20 2026 +0000
initial commit of README.mdplaintextChecking out to prev commit
❯ git checkout 2678cfadd8f2a347bc23e1ea491f702e5b184709
❯ git status
HEAD detached at 2678cfa
nothing to commit, working tree clean
❯ cat README.md
# Bandit Notes
Some notes for level29 of bandit.
## credentials
- username: bandit29
- password: Em7eGtqaMyS====REDACTED====plaintextLevel 29#
Hint: There is a git repository at ssh://bandit29-git@bandit.labs.overthewire.org/home/bandit29-git/repo via the port 2220. The password for the user bandit29-git is the same as for the user bandit29.
From your local machine (not the OverTheWire machine!), clone the repository and find the password for the next level. This needs git installed locally on your machine.
❯ git clone ssh://bandit29-git@bandit.labs.overthewire.org:2220/home/bandit29-git/repo bandit29_repo
Cloning into 'bandit29_repo'...
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit29-git@bandit.labs.overthewire.org's password:
remote: Enumerating objects: 16, done.
remote: Counting objects: 100% (16/16), done.
remote: Compressing objects: 100% (11/11), done.
remote: Total 16 (delta 2), reused 0 (delta 0), pack-reused 0 (from 0)
Receiving objects: 100% (16/16), done.
Resolving deltas: 100% (2/2), done.
❯ cd bandit29_repo
❯ ls
README.md
❯ cat README.md
# Bandit Notes
Some notes for bandit30 of bandit.
## credentials
- username: bandit30
- password: <no passwords in production!>plaintextLet’s check git properties
❯ git log --oneline
b607fba (HEAD -> master, origin/master, origin/HEAD) fix username
84c16f8 initial commit of README.md
❯ git branch -a
* master
remotes/origin/HEAD -> origin/master
remotes/origin/dev
remotes/origin/master
remotes/origin/sploits-devplaintextThere’s a dev branch. Let’s check it out:
❯ git checkout remotes/origin/dev
❯ git status
HEAD detached at origin/dev
nothing to commit, working tree clean
❯ git log --oneline
0bf8160 (HEAD, origin/dev) add data needed for development
1b95ced add gif2ascii
b607fba (origin/master, origin/HEAD, master) fix username
84c16f8 initial commit of README.md
❯ cat README.md
# Bandit Notes
Some notes for bandit30 of bandit.
## credentials
- username: bandit30
- password: jq9Dfg2rXsfY====REDACTED====plaintextLevel 30#
Hint: There is a git repository at ssh://bandit30-git@bandit.labs.overthewire.org/home/bandit30-git/repo via the port 2220. The password for the user bandit30-git is the same as for the user bandit30.
From your local machine (not the OverTheWire machine!), clone the repository and find the password for the next level. This needs git installed locally on your machine.
❯ git clone ssh://bandit30-git@bandit.labs.overthewire.org:2220/home/bandit30-git/repo bandit30_repo
Cloning into 'bandit30_repo'...
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit30-git@bandit.labs.overthewire.org's password:
remote: Enumerating objects: 4, done.
remote: Counting objects: 100% (4/4), done.
remote: Total 4 (delta 0), reused 0 (delta 0), pack-reused 0 (from 0)
Receiving objects: 100% (4/4), done.plaintext❯ cd bandit30_repo
❯ ls
README.md
❯ cat README.md
just an epmty file... muahaha
❯ git log --oneline
929c564 (HEAD -> master, origin/master, origin/HEAD) initial commit of README.md
❯ git branch -a
* master
remotes/origin/HEAD -> origin/master
remotes/origin/master
❯ git tag
secret
❯ git show secret
82NkymblpG====REDACTED====plaintextLevel 31#
Hint: There is a git repository at ssh://bandit31-git@bandit.labs.overthewire.org/home/bandit31-git/repo via the port 2220. The password for the user bandit31-git is the same as for the user bandit31.
From your local machine (not the OverTheWire machine!), clone the repository and find the password for the next level. This needs git installed locally on your machine.
❯ git clone ssh://bandit31-git@bandit.labs.overthewire.org:2220/home/bandit31-git/repo bandit31_repo
Cloning into 'bandit31_repo'...
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit31-git@bandit.labs.overthewire.org's password:
remote: Enumerating objects: 4, done.
remote: Counting objects: 100% (4/4), done.
remote: Compressing objects: 100% (3/3), done.
remote: Total 4 (delta 0), reused 0 (delta 0), pack-reused 0 (from 0)
Receiving objects: 100% (4/4), done.
❯ ls -la
total 8
drwxr-xr-x. 1 neo neo 46 Jul 27 01:28 .
drwxr-xr-x. 1 neo neo 228 Jul 27 01:27 ..
drwxr-xr-x. 1 neo neo 122 Jul 27 01:28 .git
-rw-r--r--. 1 neo neo 6 Jul 27 01:28 .gitignore
-rw-r--r--. 1 neo neo 147 Jul 27 01:28 README.md
❯ cat README.md
This time your task is to push a file to the remote repository.
Details:
File name: key.txt
Content: 'May I come in?'
Branch: master
❯ cat .gitignore
*.txtplaintextEdit the .gitignore file and remove the *.txt line. Create a new file named key.txt and add the text May I come in?.
❯ git add .
❯ git commit -m "check"
[master 05ce83c] check
2 files changed, 1 insertion(+), 1 deletion(-)
create mode 100644 key.txt
❯ git push
_ _ _ _
| |__ __ _ _ __ __| (_) |_
| '_ \ / _` | '_ \ / _` | | __|
| |_) | (_| | | | | (_| | | |_
|_.__/ \__,_|_| |_|\__,_|_|\__|
This is an OverTheWire game server.
More information on http://www.overthewire.org/wargames
backend: gibson-0
bandit31-git@bandit.labs.overthewire.org's password:
Enumerating objects: 6, done.
Counting objects: 100% (6/6), done.
Delta compression using up to 8 threads
Compressing objects: 100% (2/2), done.
Writing objects: 100% (4/4), 343 bytes | 343.00 KiB/s, done.
Total 4 (delta 0), reused 0 (delta 0), pack-reused 0 (from 0)
remote: ### Attempting to validate files... ####
remote:
remote: .oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.
remote:
remote: Well done! Here is the password for the next level:
remote: pWuj5jBQ6I====REDACTED====
remote:
remote: .oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.oOo.
remote:
To ssh://bandit.labs.overthewire.org:2220/home/bandit31-git/repo
! [remote rejected] master -> master (pre-receive hook declined)
error: failed to push some refs to 'ssh://bandit.labs.overthewire.org:2220/home/bandit31-git/repo'plaintextWe get the key in the push error message.
Level 32#
Hint: After all this git stuff, it’s time for another escape. Good luck!
❯ ssh bandit32@bandit.labs.overthewire.org -p 2220
...
WELCOME TO THE UPPERCASE SHELL
>> ls
sh: 1: LS: Permission deniedplaintextWhen using ssh to get access to the machine, we are greeted with a slightly different shell. So every command we type seems to be made uppercase and executed and thus is not working.
The one thing in Linux that is uppercase is variables. Specifically, the variable $0 has a reference to a shell.
Let’s use it to break out of the uppercase shell:
>> $0
$ whoami
bandit33
$ pwd
/home/bandit32
$ ls -la
total 36
drwxr-xr-x 2 root root 4096 Jun 24 14:59 .
drwxr-xr-x 150 root root 4096 Jun 24 15:02 ..
-rw-r--r-- 1 root root 220 Feb 13 12:16 .bash_logout
-rw-r--r-- 1 root root 3851 Jun 24 14:50 .bashrc
-rw-r--r-- 1 root root 807 Feb 13 12:16 .profile
-rwsr-x--- 1 bandit33 bandit32 15136 Jun 24 14:59 uppershell
$ cat /etc/bandit_pass/bandit33
u4P2CyPOwPGLe====REDACTED====plaintextLevel 33#
Hint: At this moment, level 34 does not exist yet.
❯ ssh bandit33@bandit.labs.overthewire.org -p 2220
bandit33@bandit.labs.overthewire.org's password:
Welcome to OverTheWire!
...
Enjoy your stay!plaintextThis is the last level.
bandit33@bandit:~$ ls
README.txt
bandit33@bandit:~$ cat README.txt
Congratulations on solving the last level of this game!
At this moment, there are no more levels to play in this game. However, we are constantly working
on new levels and will most likely expand this game with more levels soon.
Keep an eye out for an announcement on our usual communication channels!
In the meantime, you could play some of our other wargames.
If you have an idea for an awesome new level, please let us know!plaintextCongratulations!! We have completed the Bandit Challenge. 🎉