~$ skillshelf
← OverTheWire Bandit

Bandit 0 → 1: getting a foothold

banditsshlinux

The first Bandit level isn’t really a puzzle — it’s a handshake. It checks that you can SSH into a box and read a file. That’s it. But it’s worth writing up cleanly, because every level after this one starts the exact same way: connect, look around, find the password for the next level.

the goal

The password for the next level is stored in a file called readme located in the home directory. Use this password to log into level 1.

Connection details for Bandit are always the same host, on a non-standard port:

  • host: bandit.labs.overthewire.org
  • port: 2220
  • user for this level: bandit0
  • password for this level: bandit0

getting in

SSH takes the port with a lowercase -p. Worth fixing in your head now, because scp and sftp use a capital -P for the same thing and they aren’t interchangeable — that catches people out around level 13:

ssh bandit0@bandit.labs.overthewire.org -p 2220

It’ll ask for a password. Type bandit0 (nothing shows as you type — that’s normal, not a frozen terminal).

looking around

Once you’re in, see what’s in the home directory:

ls
readme

There it is. Read it:

cat readme

That prints the password for level 1. Copy it somewhere — you’ll need it for the next connection (ssh bandit1@bandit.labs.overthewire.org -p 2220).

the takeaway

Nothing here is hard, but two habits start now and never stop:

  1. ls then cat is the whole game at the start of every level — orient, then read.
  2. Keep a password log. Every level hands you the next password once. Lose it and you’re re-solving the level to get back in. A plain text file is fine here — these are throwaway credentials to a public practice box, worth nothing to anyone. That’s a judgement about these specific secrets, not a habit to carry anywhere real.

On to 1 → 2, where the filename stops cooperating.