> For the complete documentation index, see [llms.txt](https://ravins-organization.gitbook.io/ctf-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ravins-organization.gitbook.io/ctf-writeups/2025/wapt-module-natas/natas-6.md).

# Natas 6

After loading the page, we see

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2FkQuSS8tFLbiWDL0oRGdV%2Fimage.png?alt=media&amp;token=d419d5c0-a722-4a77-96c6-aee5f5467ed6" alt=""><figcaption></figcaption></figure>

By checking the source code which shows

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2FzNKeQvhvO6mrPSgm2855%2Fimage.png?alt=media&amp;token=6f677dc7-a114-482a-bf0d-437863c340e4" alt=""><figcaption></figcaption></figure>

We see some interesting php code which shows to include the secret at `includes/secret.inc`

```php
<?

include "includes/secret.inc";

    if(array_key_exists("submit", $_POST)) {
        if($secret == $_POST['secret']) {
        print "Access granted. The password for natas7 is <censored>";
    } else {
        print "Wrong secret";
    }
    }
?>
```

By accessing <http://natas6.natas.labs.overthewire.org/includes/secret.inc>, it shows

```
<?
$secret = "FOEIUWGHFEEUHOFUOIU";
?>
```

By simply submitting this,

<figure><img src="https://175444261-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FyxEI13wXOyST4LLTOUiS%2Fuploads%2FXUZ2URpm5FSDcwrO34PI%2Fimage.png?alt=media&amp;token=59f3abca-a6fd-4242-806b-2412b819b6f9" alt=""><figcaption></figcaption></figure>

And thus the password is `bmg8SvU1LizuWjx3y7xkNERkHxGre0GS`
