Sunday, October 26, 2014

Natas 3

http://natas3.natas.labs.overthewire.org/

This one's body section looks like this:
 
<body>
<h1>natas3</h1>
<div id="content">
There is nothing on this page
<!-- No more information leaks!! Not even Google will find it this time... -->
</div>
</body>


The "not even Google" part is probably a reference to the robots.txt file used to restrict bots & spiders.

Looking at http://natas3.natas.labs.overthewire.org/robots.txt shows there's secret, hidden directory called "/s3cr3t/"

Browsing there, we find another users.txt file.

Done!

No comments:

Post a Comment