One command, one password (bandit0), and you are logged into a real Linux server that exists only to be puzzled over. That is OverTheWire: a free set of wargames where every level hides the password to the next one, and the only way forward is learning the command line properly.
This guide covers what the OverTheWire wargames are, how to connect to Bandit level 0, what each stage of Bandit teaches, the order to play the other games in, and how to get unstuck without reading a spoiler. If the terminal is brand new to you, HackerDNA's Linux terminal basics course covers the commands Bandit expects, one hands-on chapter at a time.
TL;DR: OverTheWire is a free, volunteer-run collection of security wargames. Start with Bandit by running ssh [email protected] -p 2220 with the password bandit0. Bandit's 34 levels (bandit0 to bandit33) teach Linux basics, then you pick a track: Natas for web security, Krypton for cryptography, or Leviathan and Narnia on the way to binary exploitation. Save every password you find: progress is not stored.
What is OverTheWire?
OverTheWire is a free, community-run website that hosts security wargames. Each game is a chain of levels on a shared server: you log in over SSH (or, for the web game Natas, open a website), find the password for the next level, and log in again as the next user. No account, no sign-up, no installation.
There is no scoreboard and no hand-holding. Each level page states a goal and suggests a few commands to read up on, and the rest is you, the man pages and the terminal. That is exactly why OverTheWire sits near the top of our list of hacking games that teach real skills.
Why wargames work for learning
Wargames give you immediate, honest feedback. If the password works, you understood the level. If it does not, you experiment until it does, on a machine you are explicitly allowed to poke at. That loop builds the one habit every security job needs: reading unfamiliar output and figuring out what it means.
How to Connect to OverTheWire Bandit (Level 0)
Bandit runs on bandit.labs.overthewire.org, SSH port 2220 (not the default 22). The level 0 username and password are both bandit0:
ssh [email protected] -p 2220
- Open a terminal. Linux and macOS ship with an SSH client. On Windows 10 and 11, the OpenSSH client is built into PowerShell and Windows Terminal; PuTTY also works.
- Run the command above and type
bandit0at the password prompt (nothing appears while you type, which is normal). - Read the banner, then read the goal for the next level on the official Bandit page. Level 0 to 1 asks you to read a file called
readmein your home directory. - Log out and in as the next user with
exit(or Ctrl+D), thenssh [email protected] -p 2220and the password you just found. - Write the password down. OverTheWire does not save progress, and if you lose a password you start over from bandit0.
In practice, the first stumble is rarely the puzzle. It is the port: forget -p 2220 and the connection simply times out. If you play from a virtual machine and get a "broken pipe" error, the Bandit page's own fix is adding IPQoS throughput to /etc/ssh/ssh_config, or switching the VM network adapter to bridged mode.
ls -la, find and grep to recover the secret they hid, the same moves Bandit's first levels drill.
Bandit Levels: What Each Stage Teaches
Bandit has 34 playable levels, bandit0 through bandit33. Reaching bandit33 finishes the game (the level 34 page just says it does not exist yet). The levels cluster into skills, and knowing the cluster tells you which man pages to open:
| Levels | What you learn | Commands to read up on |
|---|---|---|
| 0 | Logging in over SSH on a non-standard port | ssh -p |
| 0 to 4 | Reading awkward files: a file named -, spaces in names, hidden dotfiles | ls -a, cat, quoting |
| 4 to 7 | Finding one file by its properties: human-readable, size, owner, group | file, find, 2>/dev/null |
| 7 to 13 | Text processing and encodings: unique lines, strings in binary data, Base64, ROT13, a hexdump of a file compressed many times | grep, sort, uniq, strings, base64, tr, xxd, gzip, bzip2, tar |
| 13 to 17 | SSH keys and networking: logging in with a private key, talking to local ports, TLS, finding the right port in a range | ssh -i, nc, openssl s_client, nmap |
| 17 to 21 | Comparing files, a login that kicks you out, setuid binaries, running a listener | diff, ssh with a command, nc -l |
| 21 to 25 | Cron jobs, reading and writing small shell scripts, looping over a 4-digit PIN | /etc/cron.d, bash |
| 25 to 27 | Escaping a restricted login shell | man more, man vi |
| 27 to 32 | Git: cloning, history, branches, tags, pushing | git |
| 32 to 33 | One last shell escape | sh, man |
Looking for Bandit passwords? You will not find them here. OverTheWire's rules ask anyone writing guides not to publish credentials, and the passwords change from time to time, so leaked lists are often stale anyway. The level goals above plus the man pages are enough to solve every stage.
All OverTheWire Wargames in the Recommended Order
OverTheWire's own suggested order is Bandit first, then pick one of Natas, Krypton, Leviathan or Narnia, then continue into Behemoth, Utumno and Maze. Every SSH game uses its own port on <game>.labs.overthewire.org:
| Wargame | Focus | How to connect | Levels |
|---|---|---|---|
| Bandit | Linux and command-line basics | SSH, port 2220 | 0-33 |
| Natas | Server-side web security | Browser: natas0.natas.labs.overthewire.org | 0-34 |
| Krypton | Classical cryptography | SSH, port 2231 | 0-6 |
| Leviathan | Poking at setuid binaries, no programming needed | SSH, port 2223 | 0-7 |
| Narnia | Intro to binary exploitation, source code provided | SSH, port 2226 | 0-9 |
| Behemoth | Buffer overflows, race conditions, privilege escalation | SSH, port 2221 | 0-8 |
| Utumno | Harder binary exploitation | SSH, port 2227 | 0-8 |
| Maze | Exploitation plus reverse engineering in gdb | SSH, port 2225 | 0-9 |
| Vortex | Long mixed track, from socket programming to exploitation | SSH, port 2228 | 0-26 |
| Manpage, Drifter, FormulaOne | Specialist games for after the core path | SSH, ports 2224, 2230, 2232 | varies |
Natas: web security
Natas has no SSH at all. Each level is a website at http://natasX.natas.labs.overthewire.org, and you start with username and password natas0. The early levels are pure page-source reading; later ones cover robots.txt, HTTP headers and cookies, file inclusion, command injection, blind SQL injection, predictable session IDs, file upload flaws and PHP deserialization. Pair it with HackerDNA's web attacks course for the theory behind each bug class.
Krypton: classical cryptography
Krypton walks from simple encodings to real cryptanalysis: Base64 and ROT13, then Caesar, substitution ciphers broken with frequency analysis, Vigenère, and finally a weak repeating-key cipher. Old ciphers, but the habit of attacking the key rather than the math is exactly what modern crypto challenges test.
Leviathan: a gentle bridge
Rated 1/10 by its authors, Leviathan's eight levels need "just a bit of common sense and some knowledge about basic *nix commands." You investigate setuid programs with tools like ltrace and strings, which makes it the softest entry into reverse engineering.
Narnia, Behemoth, Utumno and Maze: binary exploitation
This is the exploitation ladder, rated 2/10 (Narnia) up to 5/10 (Maze). Narnia hands you the C source of each level so you can spot the bug and focus on buffer overflows and format strings. Behemoth adds race conditions and privilege escalation, Utumno is described as "a lot harder than Leviathan and a bit harder than Behemoth", and Maze expects you to live in gdb.
Vortex and the specialist games
Vortex is a 27-level track that opens with network programming and climbs into exploitation. Manpage is about C programming pitfalls you can find in the man pages, Drifter follows in Vortex's footsteps, and FormulaOne makes you work out which other game hosts its first level's source. Leave these for after the core path.
How to Get Unstuck Without Spoilers
- Read the manual first.
man findanswers most of levels 4 to 7. If a command has no man page, it is probably a shell built-in: tryhelp cd. - Think in pipes. Many levels fall to one chained line such as
sort data.txt | uniq -c | sort -n. Build it one command at a time and check the output at each step. - Work in a private scratch directory. The servers are shared, so create one with
mktemp -dinstead of a guessable name, and delete it when you are done, as the rules ask. - Struggle for 30 minutes, then take a hint, not a walkthrough. Re-read the level's suggested commands, or ask in the OverTheWire chat naming the game and level. A full solution skips exactly the part that teaches you.
- Keep notes, not just passwords. One line per level on how you solved it becomes your personal cheat sheet for every CTF afterwards.
In practice, the levels that stop most beginners are the hexdump decompression chain around level 12 (run file after every step and rename accordingly) and the port-range level around 16, where you first need a scanner. Both are worth the time: you will use exactly those skills in real CTFs.
OverTheWire vs PicoCTF, TryHackMe and Hack The Box
PicoCTF is Carnegie Mellon's free challenge board: short, self-contained puzzles across many categories plus a yearly competition. OverTheWire is narrower and deeper, a continuous grind on real shells. They complement each other well, and our PicoCTF guide covers where to start there.
TryHackMe gives far more guidance, with rooms that explain each concept before asking questions. Hack The Box is closer to real penetration testing: whole machines to enumerate and compromise, with much less help. Our TryHackMe vs Hack The Box comparison breaks down that choice.
A sensible order for most beginners: Bandit for command-line fluency, PicoCTF for breadth, then guided labs, then full machines.
Where to Go After Bandit
- Web security: Natas, then realistic vulnerable web apps.
- Binary exploitation: Leviathan, Narnia, Behemoth, Utumno, in that order. Slow going, but it builds rare, well-paid skills in vulnerability research.
- Cryptography: Krypton, then modern crypto challenges in CTFs.
- Competition: once you can solve a level without hints, try a timed event. Our guide to entering your first CTF competition covers CTFtime, formats and teams. Teachers and students who used CyberStart before it closed will find a school-focused version of this path in our CyberStart alternatives guide.
Frequently Asked Questions
Is OverTheWire safe?
Yes. You connect out to OverTheWire's servers with a standard SSH client, and nothing gets installed on your machine. Treat the servers as shared and public: never reuse a real password or key there, keep your files in a mktemp -d directory, and do not run anything you do not understand. Playing is legal because the servers exist to be attacked.
Is OverTheWire free?
Yes, completely. There is no account or paid tier. OverTheWire is run by a community of volunteers and relies on donations to keep the servers online.
How many levels does Bandit have?
34 playable levels, bandit0 through bandit33. The level 34 page exists but states that the level does not exist yet, so logging in as bandit33 means you have finished the game.
Can I play OverTheWire on Windows?
Yes. Windows 10 and 11 include an OpenSSH client, so the same ssh [email protected] -p 2220 command works in PowerShell or Windows Terminal. WSL gives you a full Linux shell if you want local tools too.
Where can I find the Bandit passwords?
OverTheWire asks content creators not to publish them, and they change occasionally. Each level page's goal and suggested commands are enough to find every password yourself, which is the entire point of the game.
Ethics and Legal Considerations
OverTheWire gives you permission to attack its servers. That permission ends at its servers. The techniques you practice, from finding hidden files to exploiting buffer overflows, work on real systems too, and using them without authorization is a crime in virtually every country.
Critical reminder: Always get explicit written authorization before testing any system. If you stumble on a real vulnerability, report it through the organization's disclosure or bug bounty program instead of exploring further.
Your Next Steps
OverTheWire wargames are still one of the best free ways to learn the command line the way attackers and defenders actually use it. Connect to Bandit level 0 today, keep a notes file, and aim for a few levels per session rather than a marathon.
When you want structured lessons alongside the grind, HackerDNA's Hacking 101 course explains the concepts behind the levels, and the HackerDNA challenges put them to work on realistic targets in your browser, no VPN needed. Start with HackerDNA's free tier, no credit card required.