This level has a bluff. The html has a password which does not work. Diving deeper into the html shows before
and after
tags with an image at /files
route. If we use this route we can see a users.txt
which has the password
There are some directories of a website which are prevented by the user to be searched over google and these file. Robots.txt file is the instruction for web crawlers to follow.
http://natas3.natas.labs.overthewire.org/robots.txt User-agent: * Disallow: /s3cr3t/