Bandit Level 13 → Level 14

Level Goal

The password for the next level is stored in /etc/bandit_pass/bandit14 and can only be read by user bandit14. For this level, you don’t get the next password, but you get a private SSH key that can be used to log into the next level. \ Note: localhost is a hostname that refers to the machine you are working on

Commands you may need to solve this level

ssh, telnet, nc, openssl, s_client, nmap


The clue are coming from level goal. First, a private SSH key is in the home directory of bandit13.

sshkey.private

Next, the NOTE tells us that localhost is a hostname that refer to the machine that we are working on. Since we must login as bandit14 using this private key. Checking ssh man page will find that to use the key, we need to use the identify file option (-i).

ssh -i sshkey.private bandit14@localhost

Once we login as bandit14, all need to do is look at the content of the file it mentioned to find the password for the next level.

cat /etc/bandit_pass/bandit14
4wcYUJFw0k0XLShlDzztnTBHiqxU3b3e
Advertisements