From the bandit2 home directory, run cat "./--spaces in this filename--". Quoting keeps the spaces in one filename argument, while ./ prevents the leading hyphens from being treated like command options. The file’s output is the credential for Bandit Level 3.
What Bandit Level 2 asks you to read
OverTheWire places the next password in a file named --spaces in this filename-- in the home directory. The two leading hyphens and two trailing hyphens are part of the filename.
Log in as bandit2 and confirm that you are in its home directory before running the command.
The reliable command
- Connect to the Bandit server as
bandit2. - Run:
cat "./--spaces in this filename--"
- Copy the displayed value as the password for the next level. Do not publish that credential; game passwords can change and should be retrieved in your own authorized session.
Why the command works
Quotes preserve the spaces
The shell normally treats unquoted whitespace as an argument separator. Without quotes, the filename would be split into several words before cat runs. Double quotes tell the shell to pass the entire path as one argument; the quote characters themselves are removed during command parsing.
#1 Best Overall
./ handles the leading hyphens
The actual name starts with --, which can look like an option to a command. Prefixing it with ./ turns the argument into an explicit relative path beginning with a dot, so cat receives a path rather than an option-like token.
An equivalent escaping form
You can escape each space instead:
cat ./--spaces in this filename--
Both commands address the same file. Quoting is usually easier to read; backslash escaping makes each protected space visible.
| Form | What it demonstrates | Readability |
|---|---|---|
cat "./--spaces in this filename--" |
Quotes preserve the complete path as one argument. | Concise and generally clearest. |
cat ./--spaces in this filename-- |
Each space is escaped individually. | More typing, but explicit. |
Why the unquoted attempt fails
cat --spaces in this filename--
This does not represent one filename. The shell splits it at each unquoted space, producing multiple arguments. The initial hyphens can also be interpreted as option syntax. Use a quoted or escaped relative path instead.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Useful checks if you are unsure of the name
The level’s official hints include ls, cd, cat, file, du, and find. You do not need every command to complete the level. From the home directory, ls can show the entry; once the spelling is confirmed, use the quoted cat command above.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Best Value
Rank #4
Common mistakes
- Leaving out one or both sets of hyphens.
- Typing the spaces without quotes or backslashes.
- Omitting
./and allowing the name to be parsed as an option-like argument. - Trying to use a password copied from an old walkthrough instead of reading the current file in your own session.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




