- all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed - apt-insecure.conf (AllowInsecureRepositories) copied into images so participants can apt-get install despite expired Ubuntu/Debian GPG keys - warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04 - installed vim+git live into all 18 running team containers - team portal target dropdown reloads after login (was empty pre-auth) - attack log endpoint + A/D submit (attacker vs target) verified e2e
File Viewer Challenge
Description
A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at /flag.txt.
Challenge Overview
- Simple file viewer web application
- Players can view sample files through the
/viewendpoint - The file parameter is vulnerable to path traversal
- The flag is located at
/flag.txt - No flag validation - players must exploit the vulnerability to read the flag
Endpoints
/- Main page with file viewer interface/view?file=<filename>- View files (vulnerable to LFI)
Files Structure
/opt/challenge- The compiled Go binary/opt/index.html- HTML template/opt/main.go- Source code (can be modified)/opt/rebuild.sh- Script to rebuild the challenge after patching/opt/files/welcome.txt- Sample file/opt/files/info.txt- Info about the file viewer/opt/files/hint.txt- Hint for the challenge/flag.txt- The flag file (target, read-only)
Vulnerability
The /view endpoint uses filepath.Join() to concatenate the base directory with user input:
filePath := filepath.Join("/opt/files/", filename)
This is vulnerable to path traversal attacks. Players can use ../ sequences to escape the /opt/files/ directory and read arbitrary files on the system.
Solution
- Access the file viewer at http://localhost:14000
- Notice the
/view?file=welcome.txtendpoint - Try path traversal:
/view?file=../flag.txt(won't work - resolves to/opt/flag.txt) - Use more
../sequences:/view?file=../../flag.txt - This resolves to
/opt/files/../../flag.txt=/flag.txt - Read the flag
Example Exploit
# Read the flag
curl http://localhost:14000/view?file=../../flag.txt
Deployment
docker-compose up --build -d
Access
- Web: http://localhost:14000
- SSH: ssh ctfuser@localhost -p 14022 (password: warmup123)
Patching the Challenge
Players can patch the vulnerability by:
- SSH into the container
- Edit
/opt/main.goto fix the LFI vulnerability - Run
/opt/rebuild.shto rebuild and restart the challenge - Test that the vulnerability is fixed
Example fix - add path validation:
// Prevent path traversal
if strings.Contains(filename, "..") {
http.Error(w, "Invalid file path", http.StatusBadRequest)
return
}