OverTheWire Natas Level 7 Walkthrough
Today we're doing a walkthrough for level 7 of the Natas CTF wargame series located at:
http://natas7.natas.labs.overthewire.org
As usual, the webpage requires us to authenticate in order to load the page, using the name of the current level (natas7) as the user name, and the password gained from previous level as the password. One authenticated in, we see this:
Not much to go on here, so we take a look at the source for the webpage.
view-source:http://natas7.natas.labs.overthewire.org/
So we're essentially given the location where we can get the password for the next level, but navigating to http://natas7/natas.labs.overthewire.org/etc/natas_webpass/natas8 doesn't get us anywhere.
Instead, we take a look at the "About" link located at the first webpage we landed on.
http://natas7.natas.labs.overthewire.org/index.php?page=about
If we look at the address bar after navigating to this page, we see that the php page that we see is represented in the URL itself. So let's try editing that URL by replacing "about" with "/etc/natas_webpass/natas8" and see what happens.
http://natas7.natas.labs.overthewire.org/index.php?page=/etc/natas_webpass/natas8
Summary
Natas7 indicated a filepath on it's homepage page source where we could gain access to the password for the next level, and we were able to access that location by exploiting Local File Inclusion and editing the URL to include the indicated filepath, giving us access to the password for Natas8.
Finish
Comments
Post a Comment