~$ skillshelf
← OverTheWire Bandit

Bandit 5 → 6: three properties, one file

banditlinuxshell

The level hands you three properties and hides one file among hundreds. The interesting part isn’t finding it — it’s that the three properties are not equally useful, and I picked the weakest one on purpose.

the goal

The password for the next level is stored in a file somewhere under the inhere directory and has all of the following properties: human-readable, 1033 bytes in size, not executable.

the approach

inhere isn’t one directory this time. It’s twenty of them:

cd inhere && ls
maybehere00  maybehere02  maybehere04  ...  maybehere19

Worth opening one before doing anything clever:

ls -la maybehere00

Ten or so files each, some of them hidden — which is why -a matters here. Times twenty directories, that’s a couple of hundred files. Too many to eyeball, which is the whole point of the level.

A loop lists all of them at once:

for d in maybehere*; do
  echo "== $d"
  ls -la "$d"
done

That prints every file in every directory with its permissions. And in that wall of output one line doesn’t match the others — almost everything carries an x in the permission column, and one file in maybehere07 doesn’t. Not executable. cat it and there’s the password.

taking the long way on purpose

There were two faster routes available here — filter on the 1033-byte size, or hand the whole thing to find with all three properties as flags — and I passed on both.

That’s the rule I work under: an AI writes syntax, it doesn’t do the connecting. Taking the size filter would have meant the tool found the file and I watched. So: the loose filter, the slower solve, and the thinking stays mine. A choice, not a limitation.

the takeaway

The three properties the level gives you are not equally good filters, and noticing which is which is the actual skill.

  • human-readable — narrows it a bit, most of these files aren’t.
  • not executable — the loosest of the three. Plenty of files aren’t executable. It only worked here because the level made almost everything else executable on purpose.
  • 1033 bytes — the one that’s genuinely unique. Exactly one file in that tree is exactly that size.

Given a list of properties, look for the one that’s most specific and start there. find takes all three at once, which is where this goes next:

find inhere -type f -size 1033c ! -executable

-size 1033c means exactly 1033 bytes — the c is what makes it count bytes rather than 512-byte blocks, and forgetting it is the classic mistake.