~$ skillshelf
← OverTheWire Bandit

Bandit 12 → 13: the hexdump matryoshka

banditlinuxcompressionshell

Not hard in the way a puzzle is hard. It’s a short method repeated until it stops working — and there are two things in the way before you can even start the method.

the goal

The password for the next level is stored in the file data.txt, which is a hexdump of a file that has been repeatedly compressed. For this level it may be useful to create a directory under /tmp in which you can work.

the approach

The first obstacle has nothing to do with compression. Writing the first output file next to data.txt fails — the home directory isn’t writable. That’s not a bug and not a trick; it’s how the level is set up, and it’s why the objective mentions /tmp almost in passing. Every step here produces a new file, so you need somewhere you’re allowed to create them.

/tmp is world-writable on every Linux box, which makes it the standard scratch space. Make your own directory inside it so you’re not tripping over anyone else’s files:

mkdir /tmp/sam12
cp data.txt /tmp/sam12/
cd /tmp/sam12

Now the work. data.txt is a hexdump — the bytes of some other file written out as readable hex pairs. xxd makes those, and xxd -r reverses one back into the bytes it came from:

xxd -r data.txt > data

What comes out is compressed, and under that is something else compressed, and so on. The trap is guessing what each layer is. Don’t guess — ask:

file data
data: gzip compressed data

file reads the first few bytes and recognises the format from them. It doesn’t care what the file is called, which matters here because none of these have useful names.

Then it’s the same three steps over and over:

file data                # 1. what is it?
mv data data.gz          # 2. give it the extension the tool expects
gzip -d data.gz          # 3. unpack it
bzip2 -d data.bz2        # bzip2 compressed data
tar -xf data.tar         # POSIX tar archive

Identify, rename, decompress, look again. Each round hands you a file one layer further in. You don’t need to know the order in advance — file tells you at every step, and that’s the thing that turns this from a guessing game into a loop.

Keep going until file says ASCII text, then cat it.

the takeaway

file tells you what something is; the extension only tells you what someone named it. Linux doesn’t decide file types from extensions the way Windows does — file looks at the actual bytes. A file called data with no extension isn’t a mystery, it’s one command away from being identified.

You still have to rename for the tools. gzip and bzip2 refuse to work on a file without the suffix they expect, which is the small annoyance at the centre of this level: file doesn’t care about the name, the decompressors do. Hence mv data data.gz before every unpack.

When you can’t write where you are, /tmp is where you go. Not a Bandit-only lesson — read-only home directories, read-only application directories, read-only containers, same answer every time. mkdir /tmp/something and work there.

That last one is the real brick. The compression was a loop; the useful thing was learning that an environment can refuse you, and what to do about it.