Overview

This is a walkthrough of the beginner Linux CTF hosted by the Offensive Security Club at Dakota State University. The challenge consists of 16 levels (0-15), each accessed via SSH. Each level requires finding a password that grants access to the next level.

The goal is to teach basic Linux command-line skills, file system navigation, and common Unix security concepts.

Setup

SSH into level 0:

ssh level0@<ctf-host> -p 2222

Password for level 0 is provided on the CTF page.

Level 0

The password for the next level is in a file in the home directory.

ls
cat readme

The readme file contains the password for level 1.

Level 1

Password is stored in a file with spaces in the filename.

ls
cat "file with spaces"

Quoting the filename or escaping spaces with backslashes: cat file\ with\ spaces

Level 2

Password is in a hidden file.

ls -la
cat .hidden

Files prefixed with . don’t show in regular ls output.

Level 3

Multiple files in the directory. Password is in the only human-readable one.

file *
cat <the-ascii-text-file>

The file command identifies file types. Look for “ASCII text.”

Level 4

Password is stored in a file somewhere under the home directory.

find . -type f -name "*.txt" 2>/dev/null
# or
grep -r "password" . 2>/dev/null

Recursive search. Redirect stderr to suppress permission errors.

Level 5

File owned by a specific user and group, with a specific size.

find / -user level6 -group level5 -size 33c 2>/dev/null
cat <result>

The find command filters by owner, group, and size. 33c means 33 bytes.

Level 6

Password is stored in a file with specific properties: not executable, 1033 bytes, non-binary.

find . -type f -size 1033c ! -executable 2>/dev/null | while read f; do
  file "$f" | grep -q "ASCII" && cat "$f"
done

Combining find filters with file type checking.

Level 7

Password is stored somewhere on the system. You know a piece of the string.

grep -r "known-string" / 2>/dev/null

When you know part of the content, grep recursively.

Level 8

Data in a file, password is the only unique line.

sort data.txt | uniq -u

sort | uniq -u prints only lines that appear exactly once.

Level 9

Password is in a binary file, in one of the human-readable strings.

strings data.txt | grep "="

strings extracts printable character sequences from binary files. Base64 strings often contain = padding.

Level 10

Data is base64 encoded.

base64 -d data.txt

Straightforward decode.

Level 11

Data is hex-dumped. Reverse it.

xxd -r data.txt

xxd -r converts a hex dump back to binary.

Level 12

Repeated compression. The file has been compressed multiple times with gzip, bzip2, and tar.

# Check file type, decompress accordingly, repeat
file data
# gzip compressed -> mv data data.gz && gzip -d data.gz
# bzip2 compressed -> mv data data.bz2 && bzip2 -d data.bz2
# tar archive -> tar xf data

Keep checking file output and applying the correct decompression until you get ASCII text.

Level 13

Password for the next level is in a private SSH key.

cat sshkey.private
ssh -i sshkey.private level14@localhost

Use the private key directly to authenticate as the next level.

Level 14

Password can be retrieved by submitting the current level’s password to a specific port.

echo "<current-password>" | nc localhost 30000

nc (netcat) sends data to a TCP port and prints the response.

Level 15

SSL-encrypted connection.

echo "<current-password>" | openssl s_client -connect localhost:30001 -quiet

openssl s_client handles the TLS handshake. -quiet suppresses certificate output.

Takeaways

  • find, grep, file, strings, sort, uniq, base64, xxd, nc, openssl - these are the fundamental tools.
  • Redirect stderr (2>/dev/null) to keep output clean.
  • Always check file output before assuming a file’s type.
  • Piping commands together is the core Unix workflow.