added warmup chall
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
<title>File Viewer</title>
|
||||
<style>
|
||||
* { margin: 0; padding: 0; box-sizing: border-box; }
|
||||
body {
|
||||
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, sans-serif;
|
||||
background: #f5f5f5;
|
||||
min-height: 100vh;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
padding: 20px;
|
||||
}
|
||||
.container {
|
||||
background: white;
|
||||
border-radius: 8px;
|
||||
padding: 40px;
|
||||
box-shadow: 0 2px 10px rgba(0, 0, 0, 0.1);
|
||||
max-width: 500px;
|
||||
width: 100%;
|
||||
}
|
||||
h1 { color: #333; font-weight: 600; margin-bottom: 10px; font-size: 1.8rem; }
|
||||
.subtitle { color: #666; margin-bottom: 30px; font-size: 0.95rem; }
|
||||
.file-section { border-top: 1px solid #eee; padding-top: 25px; margin-top: 25px; }
|
||||
.file-title { color: #333; font-weight: 600; margin-bottom: 8px; font-size: 1rem; }
|
||||
.file-description { color: #666; margin-bottom: 15px; font-size: 0.9rem; }
|
||||
.file-links { display: flex; gap: 10px; flex-wrap: wrap; }
|
||||
.file-link {
|
||||
background: #f9f9f9;
|
||||
color: #333;
|
||||
text-decoration: none;
|
||||
padding: 8px 16px;
|
||||
border-radius: 4px;
|
||||
font-size: 0.9rem;
|
||||
transition: background 0.2s;
|
||||
border: 1px solid #e0e0e0;
|
||||
}
|
||||
.file-link:hover { background: #e8e8e8; }
|
||||
</style>
|
||||
</head>
|
||||
<body>
|
||||
<div class="container">
|
||||
<h1>File Viewer</h1>
|
||||
<p class="subtitle">Simple file viewing application</p>
|
||||
<div class="file-section">
|
||||
<div class="file-title">Available Files</div>
|
||||
<p class="file-description">View files from the collection</p>
|
||||
<div class="file-links">
|
||||
<a href="/view?file=welcome.txt" class="file-link">welcome.txt</a>
|
||||
<a href="/view?file=info.txt" class="file-link">info.txt</a>
|
||||
<a href="/view?file=hint.txt" class="file-link">hint.txt</a>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,54 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"io/ioutil"
|
||||
"log"
|
||||
"net/http"
|
||||
"path/filepath"
|
||||
)
|
||||
|
||||
// Vulnerable file viewing handler - LFI vulnerability
|
||||
func viewHandler(w http.ResponseWriter, r *http.Request) {
|
||||
// Get the file parameter
|
||||
filename := r.URL.Query().Get("file")
|
||||
|
||||
// Default file if none specified
|
||||
if filename == "" {
|
||||
filename = "welcome.txt"
|
||||
}
|
||||
|
||||
// Vulnerable: directly concatenating user input without proper validation
|
||||
// This allows path traversal attacks
|
||||
filePath := filepath.Join("/opt/files/", filename)
|
||||
|
||||
// Read the file
|
||||
content, err := ioutil.ReadFile(filePath)
|
||||
if err != nil {
|
||||
http.Error(w, "File not found or cannot be read", http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "text/plain")
|
||||
w.Write(content)
|
||||
}
|
||||
|
||||
func homeHandler(w http.ResponseWriter, r *http.Request) {
|
||||
// Serve the HTML template
|
||||
htmlContent, err := ioutil.ReadFile("/opt/index.html")
|
||||
if err != nil {
|
||||
http.Error(w, "Template not found", http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
|
||||
w.Header().Set("Content-Type", "text/html")
|
||||
w.Write(htmlContent)
|
||||
}
|
||||
|
||||
func main() {
|
||||
http.HandleFunc("/", homeHandler)
|
||||
http.HandleFunc("/view", viewHandler)
|
||||
|
||||
fmt.Println("Starting server on :8081")
|
||||
log.Fatal(http.ListenAndServe(":8081", nil))
|
||||
}
|
||||
Reference in New Issue
Block a user