> For the complete documentation index, see [llms.txt](https://thamizhiniyancs.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://thamizhiniyancs.gitbook.io/writeups/overthewire/natas/level-23-level-24.md).

# Level 23 - Level 24

```
Username: natas24
Password: 0xzF30T9Av8lgXhW7slhFCIsVKAPyl2r
URL:      http://natas24.natas.labs.overthewire.org
```

## Overview

This time we got an input field and also a link to the source code.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FNrxwpjicINQQ23V04Ble%2Fimage.png?alt=media&amp;token=f4b9a85d-ae6f-4bbc-9413-58a5d0d65d9f" alt=""><figcaption></figcaption></figure>

***

## Source Code Anlysis

The application looks out for a URL parameter `passwd` and if it exists, it compares with the the `<censored>` string using PHP `strcmp` function, and if it satisfies the condition, it will show the credentials for the next level.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FAxPbOJTHyIbG1aVQOpWn%2Fimage.png?alt=media&amp;token=46a9b2b5-7152-4a5d-9ce8-37cd0856f869" alt=""><figcaption></figcaption></figure>

In the above PHP code block, the comparison is done using the `strcmp` function. This function is not array-aware, and it is designed for comparing two strings. When you pass an array to `strcmp`, it will treat the array as a string, resulting in unexpected behavior.

***

## Getting the Password

The problem here is that `strcmp` is expecting a string, but the value of "passwd" is an array (`passwd[]= ''`). When `strcmp` encounters an array, it treats it as a string, and the result might not be as expected. In this case, result will be `0` because the array is cast to a string, resulting in an empty string (`''`), and `strcmp` compares it with the other string (`'<censored>'`), which satisfies the condition and shows the credentials for the next level.

<figure><img src="https://1858660820-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrGZ5yoqZSj85T6vq2w3c%2Fuploads%2FBrgc6agJGNwE2TtsGTO8%2Fimage.png?alt=media&amp;token=c1f1ca94-7433-4c12-b8a8-2bef7c072b57" alt=""><figcaption></figcaption></figure>
