{"id":303,"date":"2012-10-31T10:55:08","date_gmt":"2012-10-31T17:55:08","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=303"},"modified":"2012-10-31T10:57:46","modified_gmt":"2012-10-31T17:57:46","slug":"natas-level-23-directory-listings","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=303","title":{"rendered":"Natas Level 2\/3 &#8211; Directory Listings"},"content":{"rendered":"<p>Welcome back. \u00a0In this post we&#8217;re going to continue on in the Natas wargame, provided by Over The Wire. \u00a0This is a web-based wargame highlighting web security issues. \u00a0Let&#8217;s get started.<\/p>\n<h2>Level 2<\/h2>\n<p>Upon logging into the level2 page with the password we acquired during the previous level, we see a message saying that there is nothing on this page. \u00a0That&#8217;s great, but lets see if there is anything of use. \u00a0View source! \u00a0Upon viewing source we can see two links to directory structures. \u00a0One is to the css file for Natas, and looking at the URL we might remember that&#8217;s the main URL of natas. \u00a0This means that when we go there, there must exist some sort of index.html file, the default file which is loaded when a directory is accessed. \u00a0Thus, we won&#8217;t be able to get a listing of the directory. \u00a0However, if we look at the other link, &#8220;files\/pixel.png&#8221;, we see that the local files directory is a directory we haven&#8217;t looked in yet. \u00a0So, let&#8217;s go there and see if we can get a directory listing to find anything interesting. \u00a0Hitting\u00a0<a href=\"http:\/\/natas2.natas.labs.overthewire.org\/files\/\">http:\/\/natas2.natas.labs.overthewire.org\/files\/<\/a>\u00a0we get a directory listing of two files, pixel.png and users.txt. \u00a0Looking in users.txt we see the password for the next level!<\/p>\n<p>Moral of the story? \u00a0Watch which directories are in a www view-able folder. \u00a0Throw in an index.html if you don&#8217;t want a directory listing in a directory, or use something like .htaccess to limit access in specific directories, or turn off directory listing in general!<\/p>\n<h2>Level 3<\/h2>\n<p>Upon logging into the level3 web page, we see a message saying nothing is there, again. \u00a0So let&#8217;s view source (this should be second nature by now). \u00a0A comment says there are no information leaks, not even to Google. \u00a0What could that mean?<\/p>\n<p>Well, if you know how Google works (at least in the big picture), you might know that they &#8220;crawl&#8221; through the internet looking for pages so that they can index them and search through them. \u00a0They also know that certain web owners may not want google searching through certain things. \u00a0As such, Google and many other search engines will look for specific files for them which describe what they can search through and what they shouldn&#8217;t, on a given webpage. \u00a0This might be what level3&#8217;s comment is talking about. \u00a0If this file exists telling Google not to look in certain places, it will give us an idea of the directory structure of this level! \u00a0This file is called robots.txt. \u00a0Let&#8217;s look for this file ourselves!<\/p>\n<p>Pointing our browser at robots.txt we see it specifies a directory which shouldn&#8217;t be searched. \u00a0However, since this is just a request for search engines to not search it, it still allows for us users to load it up! \u00a0Looking in this directory we see a single users.txt file with the password for the next level. \u00a0Done!<\/p>\n<p>Lesson? \u00a0Robots.txt requests for search engines to not search through directories, it doesn&#8217;t disallow them to, nor does it disallow directory listings. \u00a0Robots.txt is a polite request for someone not to do something, it isn&#8217;t a security measure!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome back. \u00a0In this post we&#8217;re going to continue on in the Natas wargame, provided by Over The Wire. \u00a0This is a web-based wargame highlighting web security issues. \u00a0Let&#8217;s get started. Level 2 Upon logging into the level2 page with &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=303\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[36,35,4],"tags":[],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/303"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=303"}],"version-history":[{"count":3,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/303\/revisions"}],"predecessor-version":[{"id":305,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/303\/revisions\/305"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}