Credentials

Username: natas3
Password: G6ctbMJ5Nb4cbFwhpMPSvxGHhQ7I6W8Q
URL:      <http://natas3.natas.labs.overthewire.org>

Working

There seems to be nothing on this page too.

web.png

Methodology

  1. Check for filename robots.txt in the URL
  2. Visit the directory or route(/s3cr3t/) listed in the Disallow section of robots.txt
  3. users.txt file is present inside the directory, if we look at the contents we can find the credentials for the next level.

Findings

We can see how the robots.txt file looks and analyze the content.

robots.png

Directory which natas was trying to protect.

index.png

Contents of users.txt

pass.png

Password: tKOcJIbzM4lTs8hbCmzn5Zr4434fGZQm