~$ skillshelf
← OverTheWire Bandit

Bandit 14 → 15: the port that waits for you to talk first

banditnetworkingnetcatlinux

Short level, and the command isn’t the hard part. The hard part is that once you’re connected, nothing happens — no prompt, no banner, no Password: line — and there is no obvious signal telling you the connection worked or what you’re supposed to do next.

the goal

The password for the next level can be retrieved by submitting the password of the current level to port 30000 on localhost.

the approach

The level page lists ssh, telnet, nc, openssl, s_client, nmap. Worth separating those out, because they don’t all do the same job: nmap tells you whether a port is open and what’s behind it. It doesn’t hold a conversation with one. nc, telnet and openssl s_client do — they wire your terminal straight to the socket.

nc it is:

nc -N 127.0.0.1 30000

The -N came off an example in man nc and made sense the moment I saw it — it shuts the socket down for writing once stdin hits end-of-file, so the connection closes cleanly instead of hanging around after you’re done talking.

And then: nothing. No output at all. The silence reads as “this hasn’t done anything yet”, which sends you looking for something to print. There isn’t anything to print — the connection is open and the server is waiting for you to speak first.

That’s the whole conceptual gap in this level. A raw TCP port isn’t a program with a UI. There’s no prompt because nobody wrote one — you’re just connected, and whatever you type goes down the wire when you press Enter.

So: paste the level 14 password into the blank terminal and hit Enter. Both passwords redacted here:

nc -N 127.0.0.1 30000
<bandit14 password>
Correct!
<bandit15 password>

One line of acknowledgement, then the thing you came for. That Correct! is the first output of the entire session — everything before it is typing into what looks like a dead terminal.

the takeaway

Silence on an open socket means the server is waiting on you. It is not a hang and it is not a failed command. The absence of a prompt is the normal state of a raw TCP connection — a prompt is a thing an application chooses to send, and plenty don’t.

Scanning a port and talking to a port are different jobs. nmap answers “is anything there?”. nc answers “what does it say when I say something?”. Reaching for the scanner when you actually need the client is an easy reflex to build and a slow one to unlearn.

localhost and 127.0.0.1 are the same destination. Free thing to swap when one form is giving you trouble.