OverTheWire Bandit Level 4 Writeup — Spot the Real Text File Among Junk
The inhere directory holds several similarly-named files, only one of which is actual human-readable text. The file command identifies each file's real type without opening it. Platform: OverTheWire Bandit Category:
The inhere directory holds several similarly-named files, only one of which is actual human-readable text. The file command identifies each file's real type without opening it.
- Platform: OverTheWire Bandit
- Category: Linux Fundamentals
- Level: 4 → 5
- Difficulty: Beginner
- Technique: File type identification
Challenge description
Level 4's inhere directory contains around ten files with near-identical names (like -file00 through -file09). Only one is a plain text file — the rest are decoys with random binary data.
"Level Goal: The password for the next level is stored in the only human-readable file in the inhere directory. Tip: if your terminal is messed up, try the reset command."
Step 1 — List the decoy files
Log in as bandit4, move into inhere, and see what's there:
cd inhere
ls -la
-file00 -file01 -file02 -file03 -file04
-file05 -file06 -file07 -file08 -file09
Step 2 — Identify each file's real type
Rather than opening every file by hand, ask the file command what each one actually contains — it inspects the content, not just the name:
file ./*
./-file00: data
./-file01: data
./-file02: data
...
./-file07: ASCII text
./-file08: data
./-file09: data
Step 3 — Read the real text file
Only one file is reported as ASCII text — that's the password. The filenames start with a dash, so use the same ./ fix from Level 1:
cat ./-file07
[PASSWORD FOR bandit5]
🔑 password intentionally hidden
The password is deliberately hidden — follow the method, you've earned it. 💪
Key takeaways
A file's extension or name tells you nothing reliable about its actual content — file reads the real bytes and reports the true type. It's one of the fastest ways to triage a pile of unknown files before deciding which ones are worth opening.
-
fileinspects a file's actual content, not its name or extension - A wildcard like
./*runs it against every file in the directory at once - The dash-prefixed filenames here need the same
./fix as Level 1
Originally published on CTFdojo — join the CTFdojo Discord to discuss writeups and get notified about new ones.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.