removed old files
This commit is contained in:
@@ -1,105 +0,0 @@
|
||||
from .Challenge import Challenge
|
||||
from modules.blinkpdf import *
|
||||
|
||||
import io
|
||||
import requests
|
||||
import subprocess
|
||||
import re
|
||||
|
||||
class BlinkPDF(Challenge):
|
||||
flag_location = 'flags/blinkpdf.txt'
|
||||
history_location = 'history/blinkpdf.txt'
|
||||
|
||||
def distribute(self, flag):
|
||||
try:
|
||||
with open(self.flag_location, 'w') as f:
|
||||
f.write(flag)
|
||||
|
||||
with open(self.history_location, 'a') as f:
|
||||
f.write(flag + '\n')
|
||||
|
||||
self.logger.info(f'Flag {flag} written to {self.flag_location}')
|
||||
return True
|
||||
|
||||
except Exception as e:
|
||||
self.logger.error(f'Could not write flag to {self.flag_location}: {e}')
|
||||
return False
|
||||
|
||||
def check(self):
|
||||
try:
|
||||
# Getting private key
|
||||
container_env = subprocess.run(
|
||||
["docker", "exec", "blinkpdf_container", "cat", "/opt/.env"],
|
||||
capture_output=True,
|
||||
text=True
|
||||
).stdout.strip()
|
||||
private_key = re.search(r'PRIVATE_KEY="(.+?)"', container_env).group(1)
|
||||
assert len(private_key) > 0, 'Missing PRIVATE_KEY on .env'
|
||||
|
||||
sess = requests.Session()
|
||||
|
||||
# Checking C1: Login as user
|
||||
url = f'http://localhost:{self.port}/login'
|
||||
data = {"username": "user", "password": "user"}
|
||||
r = sess.post(url, data=data, timeout=5)
|
||||
assert 'Welcome to the PDF Signature App'.lower() in r.text.lower(), 'Cannot login as user'
|
||||
|
||||
pdfpath = 'files/blinkpdf_hellodocs.pdf'
|
||||
pdfbytes = open(pdfpath, 'rb').read()
|
||||
|
||||
# Checking C2: Sign pdf as user
|
||||
sign_url = f'http://localhost:{self.port}/sign'
|
||||
r = sess.post(sign_url, timeout=5)
|
||||
sendata = ('main.pdf', pdfbytes, 'application/pdf')
|
||||
filedata = {'file': sendata}
|
||||
r = sess.post(sign_url, files=filedata, timeout=5)
|
||||
signed_pdf = r.content
|
||||
assert r.status_code == 200 and 'application/pdf' in r.headers['Content-Type'], 'Signed PDF not available or incorrect content type'
|
||||
signed_pdf_stream = io.BytesIO(signed_pdf)
|
||||
assert verify_signature(signed_pdf_stream, private_key), 'Algorithm for signature process is changed'
|
||||
|
||||
# Checking C3: Verify valid pdf as user
|
||||
pdf_bytes_stream = io.BytesIO(pdfbytes)
|
||||
signed_pdf_stream = sign_pdf(pdf_bytes_stream, private_key)
|
||||
verify_url = f'http://localhost:{self.port}/verify'
|
||||
sendata = ('main_signed.pdf', signed_pdf_stream, 'application/pdf')
|
||||
filedata = {'file': sendata}
|
||||
r = sess.post(verify_url, files=filedata, timeout=5)
|
||||
assert 'The signature is <strong>valid</strong>.' in r.text, 'Verify function not working or algoritm verify process is changed'
|
||||
|
||||
# Checking C3: Verify invalid pdf as user
|
||||
verify_url = f'http://localhost:{self.port}/verify'
|
||||
sendata = ('main_signed.pdf', pdfbytes, 'application/pdf')
|
||||
filedata = {'file': sendata}
|
||||
r = sess.post(verify_url, files=filedata, timeout=5)
|
||||
assert 'The signature is <strong>invalid' in r.text, 'Verify function not working or algoritm verify process is changed for invalid signature'
|
||||
|
||||
# Checking C4: Checking flag on container
|
||||
with open(self.flag_location, 'r') as f:
|
||||
host_flag = f.read().strip()
|
||||
|
||||
container_flag = subprocess.run(
|
||||
["docker", "exec", "blinkpdf_container", "cat", "/flag.txt"],
|
||||
capture_output=True,
|
||||
text=True
|
||||
).stdout.strip()
|
||||
assert host_flag == container_flag, 'Flag mismatch between host and container'
|
||||
|
||||
# Checking C5: Login as admin and enc_flag checking
|
||||
url = f'http://localhost:{self.port}/login'
|
||||
data = {'username': "admin", "password": f'{private_key}'}
|
||||
r = sess.post(url, data=data, timeout=5)
|
||||
assert 'Welcome to the PDF Signature App'.lower() in r.text.lower(), 'Cannot login as admin'
|
||||
url = f'http://localhost:{self.port}/admin_panel'
|
||||
r = sess.get(url, timeout=5)
|
||||
enc_flag = r.text.split('encrypted flag: ')[1].split('</p>')[0]
|
||||
cek, dec = decryptMessage(enc_flag, private_key)
|
||||
assert dec.decode() == host_flag, 'Change algorithm for encryption flag'
|
||||
assert cek == True, 'Change signature algorithm for encryption flag'
|
||||
|
||||
self.logger.info('Check passed for blinkpdf')
|
||||
return True
|
||||
|
||||
except Exception as e:
|
||||
self.logger.error(f'Could not check blinkpdf: {e}')
|
||||
return False
|
||||
@@ -1,93 +0,0 @@
|
||||
from .Challenge import Challenge
|
||||
|
||||
import io
|
||||
import requests
|
||||
import random
|
||||
import subprocess
|
||||
import json
|
||||
|
||||
class Niko(Challenge):
|
||||
flag_location = 'flags/niko.txt'
|
||||
history_location = 'history/niko.txt'
|
||||
|
||||
def distribute(self, flag):
|
||||
try:
|
||||
with open(self.flag_location, 'w') as f:
|
||||
f.write(flag)
|
||||
|
||||
with open(self.history_location, 'a') as f:
|
||||
f.write(flag + '\n')
|
||||
|
||||
self.logger.info(f'Flag {flag} written to {self.flag_location}')
|
||||
return True
|
||||
|
||||
except Exception as e:
|
||||
self.logger.error(f'Could not write flag to {self.flag_location}: {e}')
|
||||
return False
|
||||
|
||||
def check(self):
|
||||
error_messages = [
|
||||
"あなたはどんなオタクですか",
|
||||
"冗談じゃないよ!",
|
||||
"tch なんだよ こいつ",
|
||||
"どうしてそんなことが可能でしょうか…不可能です",
|
||||
"本当のあなたは何ですか?",
|
||||
"うわー、ごめんなさい",
|
||||
"御心のままに、主よ",
|
||||
"もういいよ、やめて!",
|
||||
"時間です",
|
||||
"悪くないよ。"
|
||||
]
|
||||
try:
|
||||
# Step 1: Check if the flag still exists and matches the one in the container
|
||||
with open(self.flag_location, 'r') as f:
|
||||
host_flag = f.read().strip()
|
||||
|
||||
container_flag = subprocess.run(
|
||||
["docker", "exec", "niko_container", "cat", "/flag.txt"],
|
||||
capture_output=True,
|
||||
text=True
|
||||
).stdout.strip()
|
||||
|
||||
assert host_flag == container_flag, 'Flag mismatch between host and container'
|
||||
|
||||
self.logger.info('Flag check passed for niko')
|
||||
|
||||
# Step 2: Check if can access flag
|
||||
container_key = subprocess.run(
|
||||
["docker", "exec", "niko_container", "cat", "/opt/flag"],
|
||||
capture_output=True,
|
||||
text=True
|
||||
).stdout.strip()
|
||||
urlFlag = f'http://localhost:{self.port}/api/getFlag?flag={container_key}'
|
||||
expected_output = container_flag
|
||||
response2 = requests.get(urlFlag)
|
||||
assert response2.text.strip() == expected_output, 'Get Flag check does not work'
|
||||
self.logger.info('Get flag endpoint check passed for niko')
|
||||
|
||||
# Step 3: Check if the webpage can be accessed
|
||||
url = f'http://localhost:{self.port}/'
|
||||
response = requests.get(url)
|
||||
status_code = response.status_code
|
||||
assert status_code == 200, 'Webpage is not accessible'
|
||||
self.logger.info('Webpage accessibility check passed for niko')
|
||||
|
||||
# Step 4: Check if the output of the specific URL equals the expected string
|
||||
urlFlag = f'http://localhost:{self.port}/api/getFlag?flag=1'
|
||||
expected_output = "(⋟﹏⋞) 私をバカにしようとしているのか (´ ͡༎ຶ ͜ʖ ͡༎ຶ `)︵‿︵"
|
||||
response2 = requests.get(urlFlag)
|
||||
assert response2.text.strip() == expected_output, 'Webpage output does not match expected output'
|
||||
self.logger.info('Webpage output check passed for niko')
|
||||
|
||||
# Step 5: Check if the chat endpoint is working
|
||||
urlChat = f'http://localhost:{self.port}/api/chat'
|
||||
data = 'test'
|
||||
response3 = requests.post(urlChat, data=data)
|
||||
assert json.loads(response3.text.strip()).get("output") in error_messages, 'Api endpoint is not accessible'
|
||||
self.logger.info('Webpage delay check passed for niko')
|
||||
|
||||
return True
|
||||
|
||||
except Exception as e:
|
||||
self.logger.error(f'Could not check niko: {e}')
|
||||
return False
|
||||
Reference in New Issue
Block a user