We’re met with the same message this time, nothing on this page. Checking the source, there’s a comment taunting us that not even google will be able to find the answer this time. So, that should give us a hint. How would google find the answer? It would probably spider all of the links. So, how would that be stopped? By telling google (or its spidery minions) to take a hike. Lets check the robots.txt file.

/robots.txt

User-agent: *
Disallow: /s3cr3t/

Huh, that looks pretty suspicious. Checking this directory gives us another directory listing, complete with another user.txt file containing the password for natas4.

/s3cr3t/users.txt

natas4:XXXXXXXXXXXXXXXXXXXXXXXXXXXX