fix chall itoid
This commit is contained in:
@@ -205,61 +205,61 @@ class Blogpost(Challenge):
|
||||
self.logger.error(f" ✗ View post failed: {e}")
|
||||
return False
|
||||
|
||||
# # 6) Verify the uploaded image is accessible and check metadata
|
||||
# self.logger.info("[7/7] Verifying uploaded image and metadata ...")
|
||||
# try:
|
||||
# # Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
|
||||
# m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
|
||||
# assert m, "No uploaded image link found on post page"
|
||||
# image_name = m.group(1)
|
||||
# self.logger.info(f" → Found image: {image_name}")
|
||||
# 6) Verify the uploaded image is accessible and check metadata
|
||||
self.logger.info("[7/7] Verifying uploaded image and metadata ...")
|
||||
try:
|
||||
# Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
|
||||
m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
|
||||
assert m, "No uploaded image link found on post page"
|
||||
image_name = m.group(1)
|
||||
self.logger.info(f" → Found image: {image_name}")
|
||||
|
||||
# # Verify the image itself is accessible
|
||||
# img_url = base_url + f"/uploads/{image_name}"
|
||||
# img_r = s.get(img_url, timeout=10)
|
||||
# assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}"
|
||||
# assert len(img_r.content) > 0, "Image file is empty"
|
||||
# self.logger.info(" ✓ Uploaded image accessible")
|
||||
# Verify the image itself is accessible
|
||||
img_url = base_url + f"/uploads/{image_name}"
|
||||
img_r = s.get(img_url, timeout=10)
|
||||
assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}"
|
||||
assert len(img_r.content) > 0, "Image file is empty"
|
||||
self.logger.info(" ✓ Uploaded image accessible")
|
||||
|
||||
# # Check if metadata file exists
|
||||
# meta_url = base_url + f"/uploads/{image_name}.meta"
|
||||
# self.logger.info(f" → Trying metadata at: {meta_url}")
|
||||
# mr = s.get(meta_url, timeout=10)
|
||||
# if mr.status_code == 200:
|
||||
# meta_text = mr.text.strip()
|
||||
# if any(tag in meta_text for tag in self._exif_markers):
|
||||
# self.logger.info(" ✓ Exif metadata present and readable")
|
||||
# else:
|
||||
# self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output")
|
||||
# else:
|
||||
# # Try without .meta extension, maybe it's embedded or stored differently
|
||||
# self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}")
|
||||
# # Non-fatal - as long as upload/display works
|
||||
# except Exception as e:
|
||||
# self.logger.error(f" ✗ Upload verification failed: {e}")
|
||||
# return False
|
||||
# Check if metadata file exists
|
||||
meta_url = base_url + f"/uploads/{image_name}.meta"
|
||||
self.logger.info(f" → Trying metadata at: {meta_url}")
|
||||
mr = s.get(meta_url, timeout=10)
|
||||
if mr.status_code == 200:
|
||||
meta_text = mr.text.strip()
|
||||
if any(tag in meta_text for tag in self._exif_markers):
|
||||
self.logger.info(" ✓ Exif metadata present and readable")
|
||||
else:
|
||||
self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output")
|
||||
else:
|
||||
# Try without .meta extension, maybe it's embedded or stored differently
|
||||
self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}")
|
||||
# Non-fatal - as long as upload/display works
|
||||
except Exception as e:
|
||||
self.logger.error(f" ✗ Upload verification failed: {e}")
|
||||
return False
|
||||
|
||||
# # 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
|
||||
# try:
|
||||
# proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
|
||||
# out = (proc.stdout or "").strip()
|
||||
# if "__MISSING__" in out or proc.returncode not in (0,):
|
||||
# self.logger.warning("⚠ Flag file missing inside container")
|
||||
# else:
|
||||
# self.logger.info(" ✓ Container flag present")
|
||||
# # Optional: compare with host flag if present
|
||||
# try:
|
||||
# with open(self.flag_location, "r") as f:
|
||||
# host_flag = f.read().strip()
|
||||
# if host_flag and host_flag == out:
|
||||
# self.logger.info(" ✓ Host and container flags match")
|
||||
# else:
|
||||
# self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
|
||||
# except FileNotFoundError:
|
||||
# self.logger.warning("⚠ Host flag not found; skipping comparison")
|
||||
# except Exception as e:
|
||||
# # Non-fatal: you can tune this to fail the round if flag is mandatory.
|
||||
# self.logger.warning(f"Flag existence check encountered an issue: {e}")
|
||||
# 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
|
||||
try:
|
||||
proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
|
||||
out = (proc.stdout or "").strip()
|
||||
if "__MISSING__" in out or proc.returncode not in (0,):
|
||||
self.logger.warning("⚠ Flag file missing inside container")
|
||||
else:
|
||||
self.logger.info(" ✓ Container flag present")
|
||||
# Optional: compare with host flag if present
|
||||
try:
|
||||
with open(self.flag_location, "r") as f:
|
||||
host_flag = f.read().strip()
|
||||
if host_flag and host_flag == out:
|
||||
self.logger.info(" ✓ Host and container flags match")
|
||||
else:
|
||||
self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
|
||||
except FileNotFoundError:
|
||||
self.logger.warning("⚠ Host flag not found; skipping comparison")
|
||||
except Exception as e:
|
||||
# Non-fatal: you can tune this to fail the round if flag is mandatory.
|
||||
self.logger.warning(f"Flag existence check encountered an issue: {e}")
|
||||
|
||||
self.logger.info("SLA check passed ✅")
|
||||
return True
|
||||
|
||||
+32
-20
@@ -17,40 +17,52 @@ while True:
|
||||
print("2. bingo")
|
||||
print("3. decrypt")
|
||||
print("4. key?")
|
||||
inp = int(input("> "))
|
||||
try:
|
||||
inp = int(input("> "))
|
||||
except (ValueError, EOFError):
|
||||
print("Invalid input")
|
||||
continue
|
||||
|
||||
if inp == 1:
|
||||
print("pt (hex)")
|
||||
inp = input("> ")
|
||||
ct = cipher.encrypt(int(inp, 16))
|
||||
print('ct : ', '{0:x}'.format(ct))
|
||||
try:
|
||||
inp = input("> ")
|
||||
ct = cipher.encrypt(int(inp, 16))
|
||||
print('ct : ', '{0:x}'.format(ct))
|
||||
except (ValueError, EOFError):
|
||||
print("Invalid hex input")
|
||||
|
||||
elif inp == 2:
|
||||
print("key (hex)")
|
||||
user_hex = input("> ").strip()
|
||||
try:
|
||||
user_hex = input("> ").strip()
|
||||
user_key = bytes.fromhex(user_hex)
|
||||
except Exception:
|
||||
print("nope")
|
||||
continue
|
||||
|
||||
if len(user_key) == 66 and user_key == key:
|
||||
try:
|
||||
print(flag_bytes.decode())
|
||||
except Exception:
|
||||
print(flag_bytes.hex())
|
||||
else:
|
||||
|
||||
if len(user_key) == 66 and user_key == key:
|
||||
try:
|
||||
print(flag_bytes.decode())
|
||||
except Exception:
|
||||
print(flag_bytes.hex())
|
||||
else:
|
||||
print("nope")
|
||||
except (ValueError, EOFError):
|
||||
print("nope")
|
||||
|
||||
elif inp == 3:
|
||||
print("ct (hex)")
|
||||
inp = input("> ")
|
||||
pt = cipher.decrypt(int(inp, 16))
|
||||
print('pt : ', '{0:x}'.format(pt))
|
||||
try:
|
||||
inp = input("> ")
|
||||
pt = cipher.decrypt(int(inp, 16))
|
||||
print('pt : ', '{0:x}'.format(pt))
|
||||
except (ValueError, EOFError):
|
||||
print("Invalid hex input")
|
||||
|
||||
elif inp == 4:
|
||||
ct = cipher.encrypt(key_int)
|
||||
print('ct : ', '{0:x}'.format(ct))
|
||||
try:
|
||||
ct = cipher.encrypt(key_int)
|
||||
print('ct : ', '{0:x}'.format(ct))
|
||||
except Exception:
|
||||
print("Encryption error")
|
||||
|
||||
else:
|
||||
exit()
|
||||
|
||||
Reference in New Issue
Block a user