OverTheWire Natas Level 5 Walkthrough

Today we're doing a walkthrough for level 5 of the Natas CTF wargame, hosted at:

http://natas5.natas.labs.overthewire.org

As usual, you will need to authenticate into the webpage using the current level of the game as the username (natas5) and the password we got from the previous level as the password.  Once authenticated, we see this webpage:


Whether or not a webpage user is logged in or not is usually indicated by session cookies, so let's take a look at what cookies we have for this webpage in our web browser settings.  Using Firefox, we click on the three-line menu button and select Developer Tools, then Storage Inspector

three-line menu ------->  Developer Tools ----------->  Storage Inspector


From there, we see that there's a loggedIn cookie associated with the Natas5 webpage, that is set to 0.


We can then set the value of the loggedIn cookie to 1, then refresh the page.

set loggedIn cookie Value to 1 --------> refresh Natas5 webpage


Summary

Natas5 did not count us as "logged in" after authenticating into the webpage, so we used our web browser settings to change the value of our Nata5 webpage cookie, which allowed us full access to the page and the password to Natas6.

Finish

















Comments

Popular posts from this blog

TryHackMe - Windows PrivEsc - Walkthrough

TryHackMe - Reversing Elf - Walkthrough

TryHackMe - XSS - Walkthrough