From 029b0f809aa93e36fdaa412f8fd0b67374bce564 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 23 Sep 2026 18:54:03 +0800 Subject: [PATCH] tools in all containers + apt GPG fix for 2026 clock + target dropdown fixed - all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed - apt-insecure.conf (AllowInsecureRepositories) copied into images so participants can apt-get install despite expired Ubuntu/Debian GPG keys - warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04 - installed vim+git live into all 18 running team containers - team portal target dropdown reloads after login (was empty pre-auth) - attack log endpoint + A/D submit (attacker vs target) verified e2e --- services/apt-insecure.conf | 5 +++++ services/blogpost/Dockerfile | 7 +++++-- services/carbeat/Dockerfile | 11 +++++++++-- services/cdn/Dockerfile | 7 +++++-- services/phew/Dockerfile | 5 ++++- services/sheesh/Dockerfile | 5 ++++- services/warmup/Dockerfile | 5 ++++- 7 files changed, 36 insertions(+), 9 deletions(-) create mode 100644 services/apt-insecure.conf diff --git a/services/apt-insecure.conf b/services/apt-insecure.conf new file mode 100644 index 0000000..aeb1bce --- /dev/null +++ b/services/apt-insecure.conf @@ -0,0 +1,5 @@ +# Allow apt to work on hosts whose clock is past GPG key expiry (2026+) +Acquire::AllowInsecureRepositories "true"; +Acquire::AllowDowngradeToInsecureRepositories "true"; +Apt::Get::AllowUnauthenticated "true"; +Apt::Get::force-yes "true"; diff --git a/services/blogpost/Dockerfile b/services/blogpost/Dockerfile index eb2fc01..b07fb8d 100644 --- a/services/blogpost/Dockerfile +++ b/services/blogpost/Dockerfile @@ -12,9 +12,12 @@ WORKDIR /app ENV DEBIAN_FRONTEND=noninteractive ENV DB_PATH=/data/app.db +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + # Install packages we need (exiftool, sqlite3, sshd, build tools, editor) -RUN apt-get update && \ - apt-get install -y --no-install-recommends \ +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \ + apt-get -y --allow-unauthenticated install --no-install-recommends \ libimage-exiftool-perl \ sqlite3 \ openssh-server \ diff --git a/services/carbeat/Dockerfile b/services/carbeat/Dockerfile index 30a172c..092b5e4 100644 --- a/services/carbeat/Dockerfile +++ b/services/carbeat/Dockerfile @@ -6,8 +6,11 @@ ARG PASSWORD=root ENV DEBIAN_FRONTEND=noninteractive WORKDIR /home/ctfuser/chall -RUN apt-get update && \ - apt-get install -y --no-install-recommends \ +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \ + apt-get -y --allow-unauthenticated install --no-install-recommends \ make \ g++ \ socat \ @@ -16,6 +19,10 @@ RUN apt-get update && \ bash \ nano \ vim \ + curl \ + wget \ + netcat-openbsd \ + git \ && rm -rf /var/lib/apt/lists/* RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser && echo "ctfuser:${PASSWORD}" | chpasswd diff --git a/services/cdn/Dockerfile b/services/cdn/Dockerfile index a6474fc..6173e20 100644 --- a/services/cdn/Dockerfile +++ b/services/cdn/Dockerfile @@ -13,9 +13,12 @@ ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 \ PIP_NO_CACHE_DIR=1 +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + # Install packages we need (exiftool, sqlite3, sshd, build tools, editor) -RUN apt-get update && \ - apt-get install -y --no-install-recommends \ +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \ + apt-get -y --allow-unauthenticated install --no-install-recommends \ libimage-exiftool-perl \ sqlite3 \ openssh-server \ diff --git a/services/phew/Dockerfile b/services/phew/Dockerfile index 7ef7cd6..50d8d86 100644 --- a/services/phew/Dockerfile +++ b/services/phew/Dockerfile @@ -5,7 +5,10 @@ ENV DEBIAN_FRONTEND=noninteractive ENV HOME=/home/ctfuser WORKDIR /home/ctfuser/chall -RUN apt-get update && apt-get install -y --no-install-recommends \ +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get -y --allow-unauthenticated install --no-install-recommends \ openssh-server \ build-essential \ libffi-dev \ diff --git a/services/sheesh/Dockerfile b/services/sheesh/Dockerfile index e093940..f7c0911 100644 --- a/services/sheesh/Dockerfile +++ b/services/sheesh/Dockerfile @@ -5,7 +5,10 @@ ENV DEBIAN_FRONTEND=noninteractive ENV HOME=/home/ctfuser WORKDIR /home/ctfuser/chall -RUN apt-get update && apt-get install -y --no-install-recommends \ +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get -y --allow-unauthenticated install --no-install-recommends \ openssh-server \ build-essential \ libffi-dev \ diff --git a/services/warmup/Dockerfile b/services/warmup/Dockerfile index c0469c7..1df7b64 100644 --- a/services/warmup/Dockerfile +++ b/services/warmup/Dockerfile @@ -12,8 +12,11 @@ ARG PASSWORD ENV DEBIAN_FRONTEND=noninteractive +# Allow apt on hosts whose clock is past GPG key expiry (2026+) +COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure + # Install necessary packages -RUN apt-get update && apt-get install -y nano vim git openssh-server python3 curl netcat-traditional wget sudo nginx golang-go && rm -rf /var/lib/apt/lists/* +RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get -y --allow-unauthenticated install nano vim git openssh-server python3 python3-pip curl netcat-traditional wget sudo nginx golang-go && rm -rf /var/lib/apt/lists/* # Create ctfuser and set password RUN useradd -m -d /home/ctfuser ctfuser && echo ctfuser:${PASSWORD} | chpasswd