- topology nodes draggable (pointer events, SVG transform), layout hint shown - attack visualizer: /api/attacks logs attacker->target events; red pulsing dashed arcs on recent attacks (60s hot), ⚔ counts ok/fail - submit_flag now takes attacker_idx vs target_idx (A/D semantics); UI has target dropdown (enemy teams), leaderboard records target - containers get vim+curl+wget+netcat+git+pip3 (Dockerfiles blogpost/cdn/ phew/sheesh/warmup); warmup base ubuntu:20.04 EOL -> 24.04 - team portal: target dropdown refreshed after login (was empty pre-auth)
Blogpost
db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start}
feature: [authentication required with login and register, register default as "user" role]
- search feature
- create, edit, visit post form that can upload images (png, jpg/jpeg, bmp) query the image metadata taken with exiftool to the sqlite database
- profile (if the account type is admin, render the content of flag.txt)
vuln1: Command injection on exiftool (payload: exp1.py) vuln2: SQLi on image metadata to enable altering user account into admin account (payload: sqli.png, exp2.py)
patching rules?: