## Level 0 The password for the next level is stored in a file called readme located in the home directory. Use this password to log into bandit1 using SSH. Whenever you find a password for a level, use SSH (on port 2220) to log into that level and continue the game. ```bash bandit1@bandit:~$ ls readme bandit1@bandit:~$ cat readme ``` ## Level 1 The password for the next level is stored in a file called - located in the home directory. ```bash bandit1@bandit:~$ ls -ltra total 24 -rw-r--r-- 1 root root 807 Jan 6 2022 .profile -rw-r--r-- 1 root root 3771 Jan 6 2022 .bashrc -rw-r--r-- 1 root root 220 Jan 6 2022 .bash_logout drwxr-xr-x 2 root root 4096 Oct 5 2023 . -rw-r----- 1 bandit2 bandit1 33 Oct 5 2023 - drwxr-xr-x 70 root root 4096 Oct 5 2023 .. ``` However, we can't simply read the file by saying `cat -`, since the `-` is read as the beginning of an argument. Hence we need to provide the full path to read the file. ```bash bandit1@bandit:~$ cat /home/bandit1/- rRGizSaX8Mk1RTb1CNQoXTcYZWU6lgzi ``` ## Level 2 The password for the next level is stored in a file called spaces in this filename located in the home directory ```bash bandit2@bandit:~$ ls -ltr total 4 -rw-r----- 1 bandit3 bandit2 33 Oct 5 2023 spaces in this filename bandit2@bandit:~$ cat spaces\ in\ this\ filename aBZ0W5EmUfAf7kHTQeOwd8bauFJ2lAiG ``` ## Level 3 The password for the next level is stored in a hidden file in the inhere directory. ```bash bandit3@bandit:~$ ls -ltr total 4 drwxr-xr-x 2 root root 4096 Oct 5 2023 inhere bandit3@bandit:~$ cd inhere/ bandit3@bandit:~/inhere$ ls bandit3@bandit:~/inhere$ ls -la total 12 drwxr-xr-x 2 root root 4096 Oct 5 2023 . drwxr-xr-x 3 root root 4096 Oct 5 2023 .. -rw-r----- 1 bandit4 bandit3 33 Oct 5 2023 .hidden bandit3@bandit:~/inhere$ cat .hidden 2EW7BBsr6aMMoJ2HjW067dm8EgX26xNe ``` ## Level 4 The password for the next level is stored in the only human-readable file in the inhere directory. Tip: if your terminal is messed up, try the “reset” command. When we move to the `inhere` directory, we see a bunch of files starting with `-file` ```bash bandit4@bandit:~$ ls -la total 24 drwxr-xr-x 3 root root 4096 Oct 5 2023 . drwxr-xr-x 70 root root 4096 Oct 5 2023 .. -rw-r--r-- 1 root root 220 Jan 6 2022 .bash_logout -rw-r--r-- 1 root root 3771 Jan 6 2022 .bashrc drwxr-xr-x 2 root root 4096 Oct 5 2023 inhere -rw-r--r-- 1 root root 807 Jan 6 2022 .profile bandit4@bandit:~$ cd inhere/ bandit4@bandit:~/inhere$ ls -la total 48 drwxr-xr-x 2 root root 4096 Oct 5 2023 . drwxr-xr-x 3 root root 4096 Oct 5 2023 .. -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file00 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file01 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file02 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file03 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file04 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file05 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file06 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file07 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file08 -rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file09 ``` We can use the `file` command to give us the type of data in the file. ```bash bandit4@bandit:~/inhere$ file ./* ./-file00: data ./-file01: data ./-file02: data ./-file03: data ./-file04: data ./-file05: data ./-file06: data ./-file07: ASCII text ./-file08: data ./-file09: data bandit4@bandit:~/inhere$ cat ./-file07 lrIWWI6bB37kxfiCQZqUdOIYfr6eEeqR ``` We see that `file07` contains ASCII data. By listing the file content we see the password for the next level. ## Level 5 The password for the next level is stored in a file somewhere under the inhere directory and has all of the following properties: - human-readable - 1033 bytes in size - not executable When we login to the server, we see there is a directory names `inhere`, and inside the directory we find multiple subfolders with multiple files. ```bash bandit5@bandit:~$ ls inhere bandit5@bandit:~$ cd inhere/ bandit5@bandit:~/inhere$ ls -la total 88 drwxr-x--- 22 root bandit5 4096 Oct 5 2023 . drwxr-xr-x 3 root root 4096 Oct 5 2023 .. drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere00 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere01 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere02 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere03 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere04 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere05 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere06 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere07 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere08 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere09 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere10 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere11 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere12 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere13 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere14 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere15 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere16 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere17 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere18 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere19 bandit5@bandit:~/inhere$ ls -la maybehere00 total 72 drwxr-x--- 2 root bandit5 4096 Oct 5 2023 . drwxr-x--- 22 root bandit5 4096 Oct 5 2023 .. -rwxr-x--- 1 root bandit5 1039 Oct 5 2023 -file1 -rwxr-x--- 1 root bandit5 551 Oct 5 2023 .file1 -rw-r----- 1 root bandit5 9388 Oct 5 2023 -file2 -rw-r----- 1 root bandit5 7836 Oct 5 2023 .file2 -rwxr-x--- 1 root bandit5 7378 Oct 5 2023 -file3 -rwxr-x--- 1 root bandit5 4802 Oct 5 2023 .file3 -rwxr-x--- 1 root bandit5 6118 Oct 5 2023 spaces file1 -rw-r----- 1 root bandit5 6850 Oct 5 2023 spaces file2 -rwxr-x--- 1 root bandit5 1915 Oct 5 2023 spaces file3 ``` We need a way to filter the output of a command. `file */*` would list all the file formats, however it will not list hidden files. Hence we need to use the command `file */{.,}*`. `{.,}` means match with files either starting with `.` or nothing. However, since we have the `*` after brackets, this means any file starting with `.` or anything else. Then we can use `grep` to filter out files of type `ASCII text` ```bash maybehere19/spaces file3: data bandit5@bandit:~/inhere$ file */{.,}* | grep "ASCII text" maybehere00/.file1: ASCII text, with very long lines (550) maybehere00/.file2: ASCII text, with very long lines (7835) maybehere01/.file2: ASCII text, with very long lines (3069) maybehere02/.file1: ASCII text, with very long lines (6350) maybehere02/.file2: ASCII text, with very long lines (2576) maybehere03/.file1: ASCII text, with very long lines (9768) maybehere03/.file2: ASCII text, with very long lines (8879) maybehere04/.file1: ASCII text, with very long lines (2439) maybehere04/.file2: ASCII text, with very long lines (6143) maybehere05/.file1: ASCII text, with very long lines (3200) maybehere05/.file2: ASCII text, with very long lines (5916) maybehere06/.file1: ASCII text, with very long lines (1270) maybehere06/.file2: ASCII text, with very long lines (8975) maybehere07/.file1: ASCII text, with very long lines (3064) maybehere07/.file2: ASCII text, with very long lines (1000) maybehere08/.file1: ASCII text, with very long lines (8168) maybehere08/.file2: ASCII text, with very long lines (746) maybehere09/.file1: ASCII text, with very long lines (6762) maybehere09/.file2: ASCII text, with very long lines (8516) maybehere10/.file1: ASCII text, with very long lines (7091) maybehere10/.file2: ASCII text maybehere11/.file1: ASCII text, with very long lines (451) maybehere11/.file2: ASCII text, with very long lines (2500) maybehere12/.file1: ASCII text, with very long lines (5814) maybehere12/.file2: ASCII text, with very long lines (8243) . ``` However, there are still many files that fit this criteria. From the previous exercise we know the file did not contain any very long lines. We can use `grep -v "very long lines"` to filter out these files. ```bash bandit5@bandit:~/inhere$ file */{.,}* | grep "ASCII text" | grep -v "very long lines" maybehere10/.file2: ASCII text maybehere15/.file2: ASCII text maybehere01/-file2: ASCII text maybehere08/spaces file1: ASCII text maybehere12/-file2: ASCII text maybehere15/spaces file2: ASCII text maybehere18/-file2: ASCII text ``` Since there are only a few, we can check them manually to find the file. However, the password is not in any. That means out presumption of not `"very long lines"` is incorrect. Instead of looking for the file type, we can use the file size to find the file. With the `ls` command we can use `-R` to recursively list the files and we can `grep` the file of size `1033`. ```bash bandit5@bandit:~/inhere$ ls -laR | grep 1033 -rw-r----- 1 root bandit5 1033 Oct 5 2023 .file2 ``` Another way is to use the `du` command. The `-a` command tells it to list all files instead of directories, and `-b` displays the file size in bytes instead of kilobytes. ```bash bandit5@bandit:~/inhere$ du -b -a | grep 1033 1033 ./maybehere07/.file2 ``` Finally listing out the data in the files gives us: ```bash bandit5@bandit:~/inhere$ cat ./maybehere07/.file2 P4L4vucdmLnm8I7Vl7jG1ApGSfjYKqJU ``` ## Level 6 The password for the next level is stored somewhere on the server and has all of the following properties: - owned by user bandit7 - owned by group bandit6 - 33 bytes in size Since the file can be anywhere in the machine, we can use the `find` command. ```bash bandit6@bandit:/$ find / -type f -user bandit7 -group bandit6 -size 33c 2>/dev/null /var/lib/dpkg/info/bandit7.password ``` The password in the file is, ```bash bandit6@bandit:/$ cat /var/lib/dpkg/info/bandit7.password z7WtoNQU2XfjmMtWA8u5rN4vzqu4v99S ``` ## Level 7 The password for the next level is stored in the file data.txt next to the word millionth. Since the file is in the directory when we log in, we just need to use `grep` to extract the data. ```bash bandit7@bandit:~$ ls data.txt bandit7@bandit:~$ grep millionth data.txt millionth TESKZC0XvTetK0S9xNwm25STk5iWrBvP ``` #### Level 8 The password for the next level is stored in the file data.txt and is the only line of text that occurs only once. We can use the `uniq` command to find the unique line in the file. However, the data should be sorted for `uniq` to work. Hence we can sort the lines using the `sort` command and pipe the output to `uniq`. Since we want a line that repeats only once, we can use the `-u` flag with `uniq`. ```bash bandit8@bandit:~$ sort data.txt | uniq -u EN632PlfYiZbn3PhVK3XOGSlNInNE00t ``` #### Level 9 The password for the next level is stored in the file data.txt in one of the few human-readable strings, preceded by several ‘=’ characters. We can use the `strings` command to list human readable strings in a file. Next we can use grep to filter out strings that contain several `=` signs. ```bash bandit9@bandit:~$ strings data.txt | grep == x]T========== theG)" ========== passwordk^ ========== is ========== G7w8LIi6J3kTb8A7j9LgrywtEUlyyp6s ``` #### Level 10 The password for the next level is stored in the file data.txt, which contains base64 encoded data. The `base64` command can be used to decode the data in the file. ```bash bandit10@bandit:~$ cat data.txt VGhlIHBhc3N3b3JkIGlzIDZ6UGV6aUxkUjJSS05kTllGTmI2blZDS3pwaGxYSEJNCg== bandit10@bandit:~$ base64 -d data.txt The password is 6zPeziLdR2RKNdNYFNb6nVCKzphlXHBM ```