Overview
This is a walkthrough of the beginner Linux CTF hosted by the Offensive Security Club at Dakota State University. The challenge consists of 16 levels (0-15), each accessed via SSH. Each level requires finding a password that grants access to the next level.
The goal is to teach basic Linux command-line skills, file system navigation, and common Unix security concepts.
Setup
SSH into level 0:
ssh level0@<ctf-host> -p 2222
Password for level 0 is provided on the CTF page.
Level 0
The password for the next level is in a file in the home directory.
ls
cat readme
The readme file contains the password for level 1.
Level 1
Password is stored in a file with spaces in the filename.
ls
cat "file with spaces"
Quoting the filename or escaping spaces with backslashes: cat file\ with\ spaces
Level 2
Password is in a hidden file.
ls -la
cat .hidden
Files prefixed with . don’t show in regular ls output.
Level 3
Multiple files in the directory. Password is in the only human-readable one.
file *
cat <the-ascii-text-file>
The file command identifies file types. Look for “ASCII text.”
Level 4
Password is stored in a file somewhere under the home directory.
find . -type f -name "*.txt" 2>/dev/null
# or
grep -r "password" . 2>/dev/null
Recursive search. Redirect stderr to suppress permission errors.
Level 5
File owned by a specific user and group, with a specific size.
find / -user level6 -group level5 -size 33c 2>/dev/null
cat <result>
The find command filters by owner, group, and size. 33c means 33 bytes.
Level 6
Password is stored in a file with specific properties: not executable, 1033 bytes, non-binary.
find . -type f -size 1033c ! -executable 2>/dev/null | while read f; do
file "$f" | grep -q "ASCII" && cat "$f"
done
Combining find filters with file type checking.
Level 7
Password is stored somewhere on the system. You know a piece of the string.
grep -r "known-string" / 2>/dev/null
When you know part of the content, grep recursively.
Level 8
Data in a file, password is the only unique line.
sort data.txt | uniq -u
sort | uniq -u prints only lines that appear exactly once.
Level 9
Password is in a binary file, in one of the human-readable strings.
strings data.txt | grep "="
strings extracts printable character sequences from binary files. Base64 strings often contain = padding.
Level 10
Data is base64 encoded.
base64 -d data.txt
Straightforward decode.
Level 11
Data is hex-dumped. Reverse it.
xxd -r data.txt
xxd -r converts a hex dump back to binary.
Level 12
Repeated compression. The file has been compressed multiple times with gzip, bzip2, and tar.
# Check file type, decompress accordingly, repeat
file data
# gzip compressed -> mv data data.gz && gzip -d data.gz
# bzip2 compressed -> mv data data.bz2 && bzip2 -d data.bz2
# tar archive -> tar xf data
Keep checking file output and applying the correct decompression until you get ASCII text.
Level 13
Password for the next level is in a private SSH key.
cat sshkey.private
ssh -i sshkey.private level14@localhost
Use the private key directly to authenticate as the next level.
Level 14
Password can be retrieved by submitting the current level’s password to a specific port.
echo "<current-password>" | nc localhost 30000
nc (netcat) sends data to a TCP port and prints the response.
Level 15
SSL-encrypted connection.
echo "<current-password>" | openssl s_client -connect localhost:30001 -quiet
openssl s_client handles the TLS handshake. -quiet suppresses certificate output.
Takeaways
find,grep,file,strings,sort,uniq,base64,xxd,nc,openssl- these are the fundamental tools.- Redirect stderr (
2>/dev/null) to keep output clean. - Always check
fileoutput before assuming a file’s type. - Piping commands together is the core Unix workflow.