~$ skillshelf
← OverTheWire Bandit

Bandit 17 → 18: which side of the diff

banditlinuxdiff

After the port scanning and the TLS handshakes of the last level, this one is a single command. Two files, one line different between them. The only part worth slowing down for is that diff doesn’t hand you the line — it hands you both sides of the change, and you have to know which side you’re standing on.

the goal

There are 2 files in the homedirectory: passwords.old and passwords.new. The password for the next level is in passwords.new and is the only line that has been changed between passwords.old and passwords.new

the approach

diff is built for exactly this question, so there was no detour:

diff passwords.old passwords.new
42c42
< <old-password>
---
> <password>

Two strings, not one — which is the whole character of this level. A changed line is a pair, and diff prints both halves because it has no idea which one you came for. 42c42 says line 42 of the left file changed into line 42 of the right file; < marks the left, > marks the right.

The markers settle it without testing: passwords.old was passed first, so > is the passwords.new side, and the level puts the answer in passwords.new.

Two candidates and one cheap test each is a fine place to stop reasoning and start trying. Reading the markers is the version that keeps working when the diff is forty lines long.

the takeaway

< is the left file, > is the right file. That’s the entire content of this level. diff a b marks lines from a with < and lines from b with >, so the argument order you type decides which marker your answer is sitting behind. Get the order backwards and you’ll still see the right pair of lines — you’ll just be reading the wrong half of it. The NNcNN header above the pair is the same information again: left line number, c for changed, right line number.

Guessing is fine here because a wrong guess costs nothing. Worth noticing when that stops being true.