Bandit 1 → 2: the file called -
This level is one file, and the file is named -. That’s it. The trick is that
- isn’t really a filename as far as most command-line tools are concerned —
they claimed that character for something else a long time ago. So the obvious
command doesn’t fail loudly. It just quietly doesn’t do what you meant.
the goal
The password for the next level is stored in a file called
-located in the home directory.
the approach
Look first, same as every level:
ls
-
ls -f confirms nothing else is hiding — the dash is the whole level. Then the
obvious move, which doesn’t work:
cat -
No error, no output, just a cursor sitting there. Not a bug: to cat, a bare -
is a convention meaning “read from standard input”, not a file to open. It’s
politely waiting for you to type the file at it. Ctrl+C to get out.
The fix is to stop it from looking like a bare dash — give it a path instead:
cat ./-
./ means “in the current directory”, so the argument is now ./-, which is a
path. cat has no special meaning for that, so it just opens the file. Password
printed — not reproduced here, since OverTheWire asks people not to publish them
and doing the step yourself is most of the point.
the takeaway
A leading - gets read as a flag or a stdin marker, not as part of the name.
Sticking ./ in front turns it back into an ordinary path, and that works for
any file whose name starts with a dash.
Worth knowing what doesn’t rescue you here: --, the “no more options after
this” separator. It works for things like rm -- -file because there the dash
is being parsed as an option. But - meaning stdin isn’t an option, so
cat -- - still sits there waiting on your keyboard. ./ is the one that
actually solves this.