removed old files

This commit is contained in:
Rayhan Hanaputra
2025-10-11 11:59:21 +07:00
parent 9b1227378d
commit d42b472b3e
1230 changed files with 28 additions and 288310 deletions
-105
View File
@@ -1,105 +0,0 @@
from .Challenge import Challenge
from modules.blinkpdf import *
import io
import requests
import subprocess
import re
class BlinkPDF(Challenge):
flag_location = 'flags/blinkpdf.txt'
history_location = 'history/blinkpdf.txt'
def distribute(self, flag):
try:
with open(self.flag_location, 'w') as f:
f.write(flag)
with open(self.history_location, 'a') as f:
f.write(flag + '\n')
self.logger.info(f'Flag {flag} written to {self.flag_location}')
return True
except Exception as e:
self.logger.error(f'Could not write flag to {self.flag_location}: {e}')
return False
def check(self):
try:
# Getting private key
container_env = subprocess.run(
["docker", "exec", "blinkpdf_container", "cat", "/opt/.env"],
capture_output=True,
text=True
).stdout.strip()
private_key = re.search(r'PRIVATE_KEY="(.+?)"', container_env).group(1)
assert len(private_key) > 0, 'Missing PRIVATE_KEY on .env'
sess = requests.Session()
# Checking C1: Login as user
url = f'http://localhost:{self.port}/login'
data = {"username": "user", "password": "user"}
r = sess.post(url, data=data, timeout=5)
assert 'Welcome to the PDF Signature App'.lower() in r.text.lower(), 'Cannot login as user'
pdfpath = 'files/blinkpdf_hellodocs.pdf'
pdfbytes = open(pdfpath, 'rb').read()
# Checking C2: Sign pdf as user
sign_url = f'http://localhost:{self.port}/sign'
r = sess.post(sign_url, timeout=5)
sendata = ('main.pdf', pdfbytes, 'application/pdf')
filedata = {'file': sendata}
r = sess.post(sign_url, files=filedata, timeout=5)
signed_pdf = r.content
assert r.status_code == 200 and 'application/pdf' in r.headers['Content-Type'], 'Signed PDF not available or incorrect content type'
signed_pdf_stream = io.BytesIO(signed_pdf)
assert verify_signature(signed_pdf_stream, private_key), 'Algorithm for signature process is changed'
# Checking C3: Verify valid pdf as user
pdf_bytes_stream = io.BytesIO(pdfbytes)
signed_pdf_stream = sign_pdf(pdf_bytes_stream, private_key)
verify_url = f'http://localhost:{self.port}/verify'
sendata = ('main_signed.pdf', signed_pdf_stream, 'application/pdf')
filedata = {'file': sendata}
r = sess.post(verify_url, files=filedata, timeout=5)
assert 'The signature is <strong>valid</strong>.' in r.text, 'Verify function not working or algoritm verify process is changed'
# Checking C3: Verify invalid pdf as user
verify_url = f'http://localhost:{self.port}/verify'
sendata = ('main_signed.pdf', pdfbytes, 'application/pdf')
filedata = {'file': sendata}
r = sess.post(verify_url, files=filedata, timeout=5)
assert 'The signature is <strong>invalid' in r.text, 'Verify function not working or algoritm verify process is changed for invalid signature'
# Checking C4: Checking flag on container
with open(self.flag_location, 'r') as f:
host_flag = f.read().strip()
container_flag = subprocess.run(
["docker", "exec", "blinkpdf_container", "cat", "/flag.txt"],
capture_output=True,
text=True
).stdout.strip()
assert host_flag == container_flag, 'Flag mismatch between host and container'
# Checking C5: Login as admin and enc_flag checking
url = f'http://localhost:{self.port}/login'
data = {'username': "admin", "password": f'{private_key}'}
r = sess.post(url, data=data, timeout=5)
assert 'Welcome to the PDF Signature App'.lower() in r.text.lower(), 'Cannot login as admin'
url = f'http://localhost:{self.port}/admin_panel'
r = sess.get(url, timeout=5)
enc_flag = r.text.split('encrypted flag: ')[1].split('</p>')[0]
cek, dec = decryptMessage(enc_flag, private_key)
assert dec.decode() == host_flag, 'Change algorithm for encryption flag'
assert cek == True, 'Change signature algorithm for encryption flag'
self.logger.info('Check passed for blinkpdf')
return True
except Exception as e:
self.logger.error(f'Could not check blinkpdf: {e}')
return False
-93
View File
@@ -1,93 +0,0 @@
from .Challenge import Challenge
import io
import requests
import random
import subprocess
import json
class Niko(Challenge):
flag_location = 'flags/niko.txt'
history_location = 'history/niko.txt'
def distribute(self, flag):
try:
with open(self.flag_location, 'w') as f:
f.write(flag)
with open(self.history_location, 'a') as f:
f.write(flag + '\n')
self.logger.info(f'Flag {flag} written to {self.flag_location}')
return True
except Exception as e:
self.logger.error(f'Could not write flag to {self.flag_location}: {e}')
return False
def check(self):
error_messages = [
"あなたはどんなオタクですか",
"冗談じゃないよ!",
"tch なんだよ こいつ",
"どうしてそんなことが可能でしょうか…不可能です",
"本当のあなたは何ですか?",
"うわー、ごめんなさい",
"御心のままに、主よ",
"もういいよ、やめて!",
"時間です",
"悪くないよ。"
]
try:
# Step 1: Check if the flag still exists and matches the one in the container
with open(self.flag_location, 'r') as f:
host_flag = f.read().strip()
container_flag = subprocess.run(
["docker", "exec", "niko_container", "cat", "/flag.txt"],
capture_output=True,
text=True
).stdout.strip()
assert host_flag == container_flag, 'Flag mismatch between host and container'
self.logger.info('Flag check passed for niko')
# Step 2: Check if can access flag
container_key = subprocess.run(
["docker", "exec", "niko_container", "cat", "/opt/flag"],
capture_output=True,
text=True
).stdout.strip()
urlFlag = f'http://localhost:{self.port}/api/getFlag?flag={container_key}'
expected_output = container_flag
response2 = requests.get(urlFlag)
assert response2.text.strip() == expected_output, 'Get Flag check does not work'
self.logger.info('Get flag endpoint check passed for niko')
# Step 3: Check if the webpage can be accessed
url = f'http://localhost:{self.port}/'
response = requests.get(url)
status_code = response.status_code
assert status_code == 200, 'Webpage is not accessible'
self.logger.info('Webpage accessibility check passed for niko')
# Step 4: Check if the output of the specific URL equals the expected string
urlFlag = f'http://localhost:{self.port}/api/getFlag?flag=1'
expected_output = "(⋟﹏⋞) 私をバカにしようとしているのか (´ ͡༎ຶ ͜ʖ ͡༎ຶ `)︵‿︵"
response2 = requests.get(urlFlag)
assert response2.text.strip() == expected_output, 'Webpage output does not match expected output'
self.logger.info('Webpage output check passed for niko')
# Step 5: Check if the chat endpoint is working
urlChat = f'http://localhost:{self.port}/api/chat'
data = 'test'
response3 = requests.post(urlChat, data=data)
assert json.loads(response3.text.strip()).get("output") in error_messages, 'Api endpoint is not accessible'
self.logger.info('Webpage delay check passed for niko')
return True
except Exception as e:
self.logger.error(f'Could not check niko: {e}')
return False