- topology nodes draggable (pointer events, SVG transform), layout hint shown - attack visualizer: /api/attacks logs attacker->target events; red pulsing dashed arcs on recent attacks (60s hot), ⚔ counts ok/fail - submit_flag now takes attacker_idx vs target_idx (A/D semantics); UI has target dropdown (enemy teams), leaderboard records target - containers get vim+curl+wget+netcat+git+pip3 (Dockerfiles blogpost/cdn/ phew/sheesh/warmup); warmup base ubuntu:20.04 EOL -> 24.04 - team portal: target dropdown refreshed after login (was empty pre-auth)
CDN
db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start}
feature:
[authentication required with login and register, register default as "user" role]
- upload image
Vulns
vuln1: SSTI on image Date Created metadata, exiftool cant insert this, need to write the image's blob
example:
(base) jons@01-20-jonathanmarbun:/mnt/c/1Jonathan/CTFS/gawe/gms25/web2/exploit$ exiftool -overwrite_original -IPTC:DateCreated="{{7*7}}" image.png
Warning: Invalid date format (use YYYY:mm:dd) in IPTC:DateCreated (ValueConvInv)
Nothing to do.
payload to inject:
{{lipsum.__builtins__['open']('flag.txt').read()}}
when editing the Date Created metadata manually, somehow it has limit of 46 char (but we can expand that to make it more by deleting the content of another metadata) -> check ssti.png it probably have different behavior on another image file or format payload: check exploit/exp3.py
vuln2:
Patching Rule?
- dont remove flag.txt/changes its content
- ensure image metadata generation still available
- ensure exiftool still used