Bandit Level 13 → Level 14

Level Goal

The password for the next level is stored in /etc/bandit_pass/bandit14 and can only be read by user bandit14. For this level, you don’t get the next password, but you get a private SSH key that can be used to log into the next level. \ Note: localhost is a hostname that refers to the machine you are working on

Commands you may need to solve this level

ssh, telnet, nc, openssl, s_client, nmap


The clue are coming from level goal. First, a private SSH key is in the home directory of bandit13.

sshkey.private

Next, the NOTE tells us that localhost is a hostname that refer to the machine that we are working on. Since we must login as bandit14 using this private key. Checking ssh man page will find that to use the key, we need to use the identify file option (-i).

ssh -i sshkey.private bandit14@localhost

Once we login as bandit14, all need to do is look at the content of the file it mentioned to find the password for the next level.

cat /etc/bandit_pass/bandit14
4wcYUJFw0k0XLShlDzztnTBHiqxU3b3e
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s