OverTheWire Natas Level 9 Walkthrough
Today we're going to be doing a walkthrough of level 9 of the Natas CTF wargame hosted at: http://natas9.natas.labs.overthewire.org To access this page, we will need to authenticate into it by providing the current level of the Natas CTF game as the username (natas9), and the password obtained from the previous level as the password. Once we have authenticated into the page, we see this: An interesting looking web app. Let's take a look at the sourcecode link. http://natas9.natas.labs.overthewire.org/index-source.html From the source, we see that the app is taking user input string and passing it to the system running the server as a grep command, comparing the string to entries in a text file (dictionary.txt). This kind of code allows the user to perform a Local File Inclusion attack by passing the web app a malformed string. For example, if we pass the web app this string ; ls # The semicolon in the string will end the previous command and the hash symbol at th...