Challange:
There is nothing on this page

Solving it:
Lets check the html code once again:

<html>
<head>
<!-- This stuff in the header has nothing to do with the level -->
<link rel="stylesheet" type="text/css" href="http://natas.labs.overthewire.org/css/level.css">
<link rel="stylesheet" href="http://natas.labs.overthewire.org/css/jquery-ui.css" />
<link rel="stylesheet" href="http://natas.labs.overthewire.org/css/wechall.css" />
<script src="https://natas.labs.overthewire.org/js/jquery-1.9.1.js"></script>
<script src="https://natas.labs.overthewire.org/js/jquery-ui.js"></script>
<script src=http://natas.labs.overthewire.org/js/wechall-data.js></script><script src="https://natas.labs.overthewire.org/js/wechall.js"></script>
<script>var wechallinfo = { "level": "natas3", "pass": "sJIJNW6ucpu6HPZ1ZAchaDtwd7oGrD14" };</script></head>
<body>
<h1>natas3</h1>
<div id="content">
There is nothing on this page
<!-- No more information leaks!! Not even Google will find it this time... -->
</div>
</body></html>

The comment “<!– No more information leaks!! Not even Google will find it this time… –>” indicates me that there is a file called robots.txt. Which tells the spiders that certain locations or files aren’t allowed to be indexed by for example google. Lets see if this file exists, for this we have to go to http://natas3.natas.labs.overthewire.org/robots.txt.
It does exist and it containts the following contents:

User-agent: *
Disallow: /s3cr3t/

By gaining this information there probably is a directory called “/s3cr3t/”. Lets browse to it by going to the link: http://natas3.natas.labs.overthewire.org/s3cr3t/. We found another users.txt, lets see if the natas3 user is in here:

natas4:Z9tkRkWmpt9Qr7XrR5jWRkgOU901swEZ

Yes there is, no other users this time. Somehow I was suspecting a list of 100+ users.

Leave a Reply

Your email address will not be published. Required fields are marked *