## Level 0
The password for the next level is stored in a file called readme located in the home directory. Use this password to log into bandit1 using SSH. Whenever you find a password for a level, use SSH (on port 2220) to log into that level and continue the game.
```bash
bandit1@bandit:~$ ls
readme
bandit1@bandit:~$ cat readme
```
## Level 1
The password for the next level is stored in a file called - located in the home directory.
```bash
bandit1@bandit:~$ ls -ltra
total 24
-rw-r--r-- 1 root root 807 Jan 6 2022 .profile
-rw-r--r-- 1 root root 3771 Jan 6 2022 .bashrc
-rw-r--r-- 1 root root 220 Jan 6 2022 .bash_logout
drwxr-xr-x 2 root root 4096 Oct 5 2023 .
-rw-r----- 1 bandit2 bandit1 33 Oct 5 2023 -
drwxr-xr-x 70 root root 4096 Oct 5 2023 ..
```
However, we can't simply read the file by saying `cat -`, since the `-` is read as the beginning of an argument. Hence we need to provide the full path to read the file.
```bash
bandit1@bandit:~$ cat /home/bandit1/-
rRGizSaX8Mk1RTb1CNQoXTcYZWU6lgzi
```
## Level 2
The password for the next level is stored in a file called spaces in this filename located in the home directory
```bash
bandit2@bandit:~$ ls -ltr
total 4
-rw-r----- 1 bandit3 bandit2 33 Oct 5 2023 spaces in this filename
bandit2@bandit:~$ cat spaces\ in\ this\ filename
aBZ0W5EmUfAf7kHTQeOwd8bauFJ2lAiG
```
## Level 3
The password for the next level is stored in a hidden file in the inhere directory.
```bash
bandit3@bandit:~$ ls -ltr
total 4
drwxr-xr-x 2 root root 4096 Oct 5 2023 inhere
bandit3@bandit:~$ cd inhere/
bandit3@bandit:~/inhere$ ls
bandit3@bandit:~/inhere$ ls -la
total 12
drwxr-xr-x 2 root root 4096 Oct 5 2023 .
drwxr-xr-x 3 root root 4096 Oct 5 2023 ..
-rw-r----- 1 bandit4 bandit3 33 Oct 5 2023 .hidden
bandit3@bandit:~/inhere$ cat .hidden
2EW7BBsr6aMMoJ2HjW067dm8EgX26xNe
```
## Level 4
The password for the next level is stored in the only human-readable file in the inhere directory. Tip: if your terminal is messed up, try the “reset” command. When we move to the `inhere` directory, we see a bunch of files starting with `-file`
```bash
bandit4@bandit:~$ ls -la
total 24
drwxr-xr-x 3 root root 4096 Oct 5 2023 .
drwxr-xr-x 70 root root 4096 Oct 5 2023 ..
-rw-r--r-- 1 root root 220 Jan 6 2022 .bash_logout
-rw-r--r-- 1 root root 3771 Jan 6 2022 .bashrc
drwxr-xr-x 2 root root 4096 Oct 5 2023 inhere
-rw-r--r-- 1 root root 807 Jan 6 2022 .profile
bandit4@bandit:~$ cd inhere/
bandit4@bandit:~/inhere$ ls -la
total 48
drwxr-xr-x 2 root root 4096 Oct 5 2023 .
drwxr-xr-x 3 root root 4096 Oct 5 2023 ..
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file00
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file01
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file02
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file03
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file04
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file05
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file06
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file07
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file08
-rw-r----- 1 bandit5 bandit4 33 Oct 5 2023 -file09
```
We can use the `file` command to give us the type of data in the file.
```bash
bandit4@bandit:~/inhere$ file ./*
./-file00: data
./-file01: data
./-file02: data
./-file03: data
./-file04: data
./-file05: data
./-file06: data
./-file07: ASCII text
./-file08: data
./-file09: data
bandit4@bandit:~/inhere$ cat ./-file07
lrIWWI6bB37kxfiCQZqUdOIYfr6eEeqR
```
We see that `file07` contains ASCII data. By listing the file content we see the password for the next level.
## Level 5
The password for the next level is stored in a file somewhere under the inhere directory and has all of the following properties:
- human-readable
- 1033 bytes in size
- not executable
When we login to the server, we see there is a directory names `inhere`, and inside the directory we find multiple subfolders with multiple files.
```bash
bandit5@bandit:~$ ls
inhere
bandit5@bandit:~$ cd inhere/
bandit5@bandit:~/inhere$ ls -la
total 88
drwxr-x--- 22 root bandit5 4096 Oct 5 2023 .
drwxr-xr-x 3 root root 4096 Oct 5 2023 ..
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere00
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere01
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere02
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere03
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere04
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere05
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere06
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere07
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere08
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere09
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere10
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere11
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere12
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere13
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere14
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere15
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere16
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere17
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere18
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 maybehere19
bandit5@bandit:~/inhere$ ls -la maybehere00
total 72
drwxr-x--- 2 root bandit5 4096 Oct 5 2023 .
drwxr-x--- 22 root bandit5 4096 Oct 5 2023 ..
-rwxr-x--- 1 root bandit5 1039 Oct 5 2023 -file1
-rwxr-x--- 1 root bandit5 551 Oct 5 2023 .file1
-rw-r----- 1 root bandit5 9388 Oct 5 2023 -file2
-rw-r----- 1 root bandit5 7836 Oct 5 2023 .file2
-rwxr-x--- 1 root bandit5 7378 Oct 5 2023 -file3
-rwxr-x--- 1 root bandit5 4802 Oct 5 2023 .file3
-rwxr-x--- 1 root bandit5 6118 Oct 5 2023 spaces file1
-rw-r----- 1 root bandit5 6850 Oct 5 2023 spaces file2
-rwxr-x--- 1 root bandit5 1915 Oct 5 2023 spaces file3
```
We need a way to filter the output of a command. `file */*` would list all the file formats, however it will not list hidden files.
Hence we need to use the command `file */{.,}*`. `{.,}` means match with files either starting with `.` or nothing. However, since we have the `*` after brackets, this means any file starting with `.` or anything else. Then we can use `grep` to filter out files of type `ASCII text`
```bash
maybehere19/spaces file3: data
bandit5@bandit:~/inhere$ file */{.,}* | grep "ASCII text"
maybehere00/.file1: ASCII text, with very long lines (550)
maybehere00/.file2: ASCII text, with very long lines (7835)
maybehere01/.file2: ASCII text, with very long lines (3069)
maybehere02/.file1: ASCII text, with very long lines (6350)
maybehere02/.file2: ASCII text, with very long lines (2576)
maybehere03/.file1: ASCII text, with very long lines (9768)
maybehere03/.file2: ASCII text, with very long lines (8879)
maybehere04/.file1: ASCII text, with very long lines (2439)
maybehere04/.file2: ASCII text, with very long lines (6143)
maybehere05/.file1: ASCII text, with very long lines (3200)
maybehere05/.file2: ASCII text, with very long lines (5916)
maybehere06/.file1: ASCII text, with very long lines (1270)
maybehere06/.file2: ASCII text, with very long lines (8975)
maybehere07/.file1: ASCII text, with very long lines (3064)
maybehere07/.file2: ASCII text, with very long lines (1000)
maybehere08/.file1: ASCII text, with very long lines (8168)
maybehere08/.file2: ASCII text, with very long lines (746)
maybehere09/.file1: ASCII text, with very long lines (6762)
maybehere09/.file2: ASCII text, with very long lines (8516)
maybehere10/.file1: ASCII text, with very long lines (7091)
maybehere10/.file2: ASCII text
maybehere11/.file1: ASCII text, with very long lines (451)
maybehere11/.file2: ASCII text, with very long lines (2500)
maybehere12/.file1: ASCII text, with very long lines (5814)
maybehere12/.file2: ASCII text, with very long lines (8243)
.
```
However, there are still many files that fit this criteria. From the previous exercise we know the file did not contain any very long lines. We can use `grep -v "very long lines"` to filter out these files.
```bash
bandit5@bandit:~/inhere$ file */{.,}* | grep "ASCII text" | grep -v "very long lines"
maybehere10/.file2: ASCII text
maybehere15/.file2: ASCII text
maybehere01/-file2: ASCII text
maybehere08/spaces file1: ASCII text
maybehere12/-file2: ASCII text
maybehere15/spaces file2: ASCII text
maybehere18/-file2: ASCII text
```
Since there are only a few, we can check them manually to find the file. However, the password is not in any. That means out presumption of not `"very long lines"` is incorrect.
Instead of looking for the file type, we can use the file size to find the file. With the `ls` command we can use `-R` to recursively list the files and we can `grep` the file of size `1033`.
```bash
bandit5@bandit:~/inhere$ ls -laR | grep 1033
-rw-r----- 1 root bandit5 1033 Oct 5 2023 .file2
```
Another way is to use the `du` command. The `-a` command tells it to list all files instead of directories, and `-b` displays the file size in bytes instead of kilobytes.
```bash
bandit5@bandit:~/inhere$ du -b -a | grep 1033
1033 ./maybehere07/.file2
```
Finally listing out the data in the files gives us:
```bash
bandit5@bandit:~/inhere$ cat ./maybehere07/.file2
P4L4vucdmLnm8I7Vl7jG1ApGSfjYKqJU
```
## Level 6
The password for the next level is stored somewhere on the server and has all of the following properties:
- owned by user bandit7
- owned by group bandit6
- 33 bytes in size
Since the file can be anywhere in the machine, we can use the `find` command.
```bash
bandit6@bandit:/$ find / -type f -user bandit7 -group bandit6 -size 33c 2>/dev/null
/var/lib/dpkg/info/bandit7.password
```
The password in the file is,
```bash
bandit6@bandit:/$ cat /var/lib/dpkg/info/bandit7.password
z7WtoNQU2XfjmMtWA8u5rN4vzqu4v99S
```
## Level 7
The password for the next level is stored in the file data.txt next to the word millionth.
Since the file is in the directory when we log in, we just need to use `grep` to extract the data.
```bash
bandit7@bandit:~$ ls
data.txt
bandit7@bandit:~$ grep millionth data.txt
millionth TESKZC0XvTetK0S9xNwm25STk5iWrBvP
```
#### Level 8
The password for the next level is stored in the file data.txt and is the only line of text that occurs only once.
We can use the `uniq` command to find the unique line in the file. However, the data should be sorted for `uniq` to work. Hence we can sort the lines using the `sort` command and pipe the output to `uniq`. Since we want a line that repeats only once, we can use the `-u` flag with `uniq`.
```bash
bandit8@bandit:~$ sort data.txt | uniq -u
EN632PlfYiZbn3PhVK3XOGSlNInNE00t
```
#### Level 9
The password for the next level is stored in the file data.txt in one of the few human-readable strings, preceded by several ‘=’ characters.
We can use the `strings` command to list human readable strings in a file. Next we can use grep to filter out strings that contain several `=` signs.
```bash
bandit9@bandit:~$ strings data.txt | grep ==
x]T========== theG)"
========== passwordk^
========== is
========== G7w8LIi6J3kTb8A7j9LgrywtEUlyyp6s
```
#### Level 10
The password for the next level is stored in the file data.txt, which contains base64 encoded data.
The `base64` command can be used to decode the data in the file.
```bash
bandit10@bandit:~$ cat data.txt
VGhlIHBhc3N3b3JkIGlzIDZ6UGV6aUxkUjJSS05kTllGTmI2blZDS3pwaGxYSEJNCg==
bandit10@bandit:~$ base64 -d data.txt
The password is 6zPeziLdR2RKNdNYFNb6nVCKzphlXHBM
```