Files
2025-10-25 04:56:33 +07:00

2.3 KiB

File Viewer Challenge

Description

A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at /flag.txt.

Challenge Overview

  • Simple file viewer web application
  • Players can view sample files through the /view endpoint
  • The file parameter is vulnerable to path traversal
  • The flag is located at /flag.txt
  • No flag validation - players must exploit the vulnerability to read the flag

Endpoints

  • / - Main page with file viewer interface
  • /view?file=<filename> - View files (vulnerable to LFI)

Files Structure

  • /opt/challenge - The compiled Go binary
  • /opt/index.html - HTML template
  • /opt/main.go - Source code (can be modified)
  • /opt/rebuild.sh - Script to rebuild the challenge after patching
  • /opt/files/welcome.txt - Sample file
  • /opt/files/info.txt - Info about the file viewer
  • /opt/files/hint.txt - Hint for the challenge
  • /flag.txt - The flag file (target, read-only)

Vulnerability

The /view endpoint uses filepath.Join() to concatenate the base directory with user input:

filePath := filepath.Join("/opt/files/", filename)

This is vulnerable to path traversal attacks. Players can use ../ sequences to escape the /opt/files/ directory and read arbitrary files on the system.

Solution

  1. Access the file viewer at http://localhost:14000
  2. Notice the /view?file=welcome.txt endpoint
  3. Try path traversal: /view?file=../flag.txt (won't work - resolves to /opt/flag.txt)
  4. Use more ../ sequences: /view?file=../../flag.txt
  5. This resolves to /opt/files/../../flag.txt = /flag.txt
  6. Read the flag

Example Exploit

# Read the flag
curl http://localhost:14000/view?file=../../flag.txt

Deployment

docker-compose up --build -d

Access

Patching the Challenge

Players can patch the vulnerability by:

  1. SSH into the container
  2. Edit /opt/main.go to fix the LFI vulnerability
  3. Run /opt/rebuild.sh to rebuild and restart the challenge
  4. Test that the vulnerability is fixed

Example fix - add path validation:

// Prevent path traversal
if strings.Contains(filename, "..") {
    http.Error(w, "Invalid file path", http.StatusBadRequest)
    return
}