Files
attack-defense-platform/services/blogpost
root 24dbf0a662 draggable topology + attack visualizer + tools in containers
- topology nodes draggable (pointer events, SVG transform), layout hint shown
- attack visualizer: /api/attacks logs attacker->target events; red pulsing
  dashed arcs on recent attacks (60s hot), ⚔ counts ok/fail
- submit_flag now takes attacker_idx vs target_idx (A/D semantics); UI has
  target dropdown (enemy teams), leaderboard records target
- containers get vim+curl+wget+netcat+git+pip3 (Dockerfiles blogpost/cdn/
  phew/sheesh/warmup); warmup base ubuntu:20.04 EOL -> 24.04
- team portal: target dropdown refreshed after login (was empty pre-auth)
2026-09-23 18:05:44 +08:00
..
2025-10-26 15:09:49 +07:00
2025-10-26 01:03:54 +07:00
2025-10-26 15:09:49 +07:00
2025-10-11 13:08:07 +07:00
2025-10-11 12:42:26 +07:00

Blogpost

db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start}

feature: [authentication required with login and register, register default as "user" role]

  1. search feature
  2. create, edit, visit post form that can upload images (png, jpg/jpeg, bmp) query the image metadata taken with exiftool to the sqlite database
  3. profile (if the account type is admin, render the content of flag.txt)

vuln1: Command injection on exiftool (payload: exp1.py) vuln2: SQLi on image metadata to enable altering user account into admin account (payload: sqli.png, exp2.py)

patching rules?: