This level involves something called DomainAuthenticator, a quick, insecure way of authenticating yourself as a user from a domain.
First, the easy thing to do is upload a authenticated.txt to the level02 server you were using before and then use that to login. The contents of the file should look like
AUTHENTICATED
with the trailing new line.
Then, you can submit the form to the DomainAuthenticator with the URL to that .txt file, and DomainAuthenticator will log you in!
To give you the key password you need, DomainAuthenicator requires that you've authenticated from the same domain it's running on - not level02.
The DomainAuthenticator authenticated page actually contains the text of your authenticated.txt file in it. You can use that to log you in!
Just submit your pingback URL as:
and you're logged in and can view the password.