Bandit 17 → 18: which side of the diff
After the port scanning and the TLS handshakes of the last level, this one is a
single command. Two files, one line different between them. The only part worth
slowing down for is that diff doesn’t hand you the line — it hands you both
sides of the change, and you have to know which side you’re standing on.
the goal
There are 2 files in the homedirectory:
passwords.oldandpasswords.new. The password for the next level is inpasswords.newand is the only line that has been changed betweenpasswords.oldandpasswords.new
the approach
diff is built for exactly this question, so there was no detour:
diff passwords.old passwords.new
42c42
< <old-password>
---
> <password>
Two strings, not one — which is the whole character of this level. A changed
line is a pair, and diff prints both halves because it has no idea which one
you came for. 42c42 says line 42 of the left file changed into line 42 of the
right file; < marks the left, > marks the right.
The markers settle it without testing: passwords.old was passed first, so >
is the passwords.new side, and the level puts the answer in passwords.new.
Two candidates and one cheap test each is a fine place to stop reasoning and start trying. Reading the markers is the version that keeps working when the diff is forty lines long.
the takeaway
< is the left file, > is the right file. That’s the entire content of
this level. diff a b marks lines from a with < and lines from b with >,
so the argument order you type decides which marker your answer is sitting
behind. Get the order backwards and you’ll still see the right pair of lines —
you’ll just be reading the wrong half of it. The NNcNN header above the pair is
the same information again: left line number, c for changed, right line number.
Guessing is fine here because a wrong guess costs nothing. Worth noticing when that stops being true.