added warmup chall

This commit is contained in:
Rayhan Hanaputra
2025-10-25 04:56:33 +07:00
parent 4552bcb0fe
commit 604bd24b04
15 changed files with 360 additions and 6 deletions
+60
View File
@@ -0,0 +1,60 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>File Viewer</title>
<style>
* { margin: 0; padding: 0; box-sizing: border-box; }
body {
font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, sans-serif;
background: #f5f5f5;
min-height: 100vh;
display: flex;
align-items: center;
justify-content: center;
padding: 20px;
}
.container {
background: white;
border-radius: 8px;
padding: 40px;
box-shadow: 0 2px 10px rgba(0, 0, 0, 0.1);
max-width: 500px;
width: 100%;
}
h1 { color: #333; font-weight: 600; margin-bottom: 10px; font-size: 1.8rem; }
.subtitle { color: #666; margin-bottom: 30px; font-size: 0.95rem; }
.file-section { border-top: 1px solid #eee; padding-top: 25px; margin-top: 25px; }
.file-title { color: #333; font-weight: 600; margin-bottom: 8px; font-size: 1rem; }
.file-description { color: #666; margin-bottom: 15px; font-size: 0.9rem; }
.file-links { display: flex; gap: 10px; flex-wrap: wrap; }
.file-link {
background: #f9f9f9;
color: #333;
text-decoration: none;
padding: 8px 16px;
border-radius: 4px;
font-size: 0.9rem;
transition: background 0.2s;
border: 1px solid #e0e0e0;
}
.file-link:hover { background: #e8e8e8; }
</style>
</head>
<body>
<div class="container">
<h1>File Viewer</h1>
<p class="subtitle">Simple file viewing application</p>
<div class="file-section">
<div class="file-title">Available Files</div>
<p class="file-description">View files from the collection</p>
<div class="file-links">
<a href="/view?file=welcome.txt" class="file-link">welcome.txt</a>
<a href="/view?file=info.txt" class="file-link">info.txt</a>
<a href="/view?file=hint.txt" class="file-link">hint.txt</a>
</div>
</div>
</div>
</body>
</html>
+54
View File
@@ -0,0 +1,54 @@
package main
import (
"fmt"
"io/ioutil"
"log"
"net/http"
"path/filepath"
)
// Vulnerable file viewing handler - LFI vulnerability
func viewHandler(w http.ResponseWriter, r *http.Request) {
// Get the file parameter
filename := r.URL.Query().Get("file")
// Default file if none specified
if filename == "" {
filename = "welcome.txt"
}
// Vulnerable: directly concatenating user input without proper validation
// This allows path traversal attacks
filePath := filepath.Join("/opt/files/", filename)
// Read the file
content, err := ioutil.ReadFile(filePath)
if err != nil {
http.Error(w, "File not found or cannot be read", http.StatusNotFound)
return
}
w.Header().Set("Content-Type", "text/plain")
w.Write(content)
}
func homeHandler(w http.ResponseWriter, r *http.Request) {
// Serve the HTML template
htmlContent, err := ioutil.ReadFile("/opt/index.html")
if err != nil {
http.Error(w, "Template not found", http.StatusNotFound)
return
}
w.Header().Set("Content-Type", "text/html")
w.Write(htmlContent)
}
func main() {
http.HandleFunc("/", homeHandler)
http.HandleFunc("/view", viewHandler)
fmt.Println("Starting server on :8081")
log.Fatal(http.ListenAndServe(":8081", nil))
}