- Rename repo/domain: attack-defense-platform / attackdefense.imrnes.team (all refs replaced)
- challenge_registry.json: single source of truth (28 challs across gemastik18/xvi/xvii)
- teams.py: registry-driven CHALLENGES, set_challenge_enabled, sync_challenge_runtime
(apply enable/disable to live teams: build/up or stop/remove + receiver restart)
- compose_gen.py: render per-team compose from canonical per-challenge templates
(image reuse, per-team ports 30xxx, flag mounts, passwords)
- gen_canonical_composes.py: canonical docker-compose.yml for all services
- import_new_challenges.py: import XVI/XVII services + EOL base image fixes
(debian:buster→bookworm, node:14→20, python:3.7-slim→3.11)
- receiver: xvi package (10 checkers) + xvii package (12 generic checkers),
Challenge base reads PASSWORD_<team_port> from env; gen_receiver_main.py
generates per-team main.py from registry
- main.py: /api/challenges returns full registry; PATCH /api/challenges/<name>
toggles enabled + applies to live teams
- index.html: 🏗️ Challenge Manager tab (toggle per challenge, grouped by set)
- SLA bonus now dynamic (all enabled challenges, not hardcoded 6)
File Viewer Challenge
Description
A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at /flag.txt.
Challenge Overview
- Simple file viewer web application
- Players can view sample files through the
/viewendpoint - The file parameter is vulnerable to path traversal
- The flag is located at
/flag.txt - No flag validation - players must exploit the vulnerability to read the flag
Endpoints
/- Main page with file viewer interface/view?file=<filename>- View files (vulnerable to LFI)
Files Structure
/opt/challenge- The compiled Go binary/opt/index.html- HTML template/opt/main.go- Source code (can be modified)/opt/rebuild.sh- Script to rebuild the challenge after patching/opt/files/welcome.txt- Sample file/opt/files/info.txt- Info about the file viewer/opt/files/hint.txt- Hint for the challenge/flag.txt- The flag file (target, read-only)
Vulnerability
The /view endpoint uses filepath.Join() to concatenate the base directory with user input:
filePath := filepath.Join("/opt/files/", filename)
This is vulnerable to path traversal attacks. Players can use ../ sequences to escape the /opt/files/ directory and read arbitrary files on the system.
Solution
- Access the file viewer at http://localhost:14000
- Notice the
/view?file=welcome.txtendpoint - Try path traversal:
/view?file=../flag.txt(won't work - resolves to/opt/flag.txt) - Use more
../sequences:/view?file=../../flag.txt - This resolves to
/opt/files/../../flag.txt=/flag.txt - Read the flag
Example Exploit
# Read the flag
curl http://localhost:14000/view?file=../../flag.txt
Deployment
docker-compose up --build -d
Access
- Web: http://localhost:14000
- SSH: ssh ctfuser@localhost -p 14022 (password: warmup123)
Patching the Challenge
Players can patch the vulnerability by:
- SSH into the container
- Edit
/opt/main.goto fix the LFI vulnerability - Run
/opt/rebuild.shto rebuild and restart the challenge - Test that the vulnerability is fixed
Example fix - add path validation:
// Prevent path traversal
if strings.Contains(filename, "..") {
http.Error(w, "Invalid file path", http.StatusBadRequest)
return
}