diff --git a/receiver/challenges/Blogpost.py b/receiver/challenges/Blogpost.py index fb03081..6f0f2b6 100644 --- a/receiver/challenges/Blogpost.py +++ b/receiver/challenges/Blogpost.py @@ -205,61 +205,61 @@ class Blogpost(Challenge): self.logger.error(f" ✗ View post failed: {e}") return False - # # 6) Verify the uploaded image is accessible and check metadata - # self.logger.info("[7/7] Verifying uploaded image and metadata ...") - # try: - # # Find something like /uploads/.png (or .jpg/.jpeg/.bmp) - # m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE) - # assert m, "No uploaded image link found on post page" - # image_name = m.group(1) - # self.logger.info(f" → Found image: {image_name}") + # 6) Verify the uploaded image is accessible and check metadata + self.logger.info("[7/7] Verifying uploaded image and metadata ...") + try: + # Find something like /uploads/.png (or .jpg/.jpeg/.bmp) + m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE) + assert m, "No uploaded image link found on post page" + image_name = m.group(1) + self.logger.info(f" → Found image: {image_name}") - # # Verify the image itself is accessible - # img_url = base_url + f"/uploads/{image_name}" - # img_r = s.get(img_url, timeout=10) - # assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}" - # assert len(img_r.content) > 0, "Image file is empty" - # self.logger.info(" ✓ Uploaded image accessible") + # Verify the image itself is accessible + img_url = base_url + f"/uploads/{image_name}" + img_r = s.get(img_url, timeout=10) + assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}" + assert len(img_r.content) > 0, "Image file is empty" + self.logger.info(" ✓ Uploaded image accessible") - # # Check if metadata file exists - # meta_url = base_url + f"/uploads/{image_name}.meta" - # self.logger.info(f" → Trying metadata at: {meta_url}") - # mr = s.get(meta_url, timeout=10) - # if mr.status_code == 200: - # meta_text = mr.text.strip() - # if any(tag in meta_text for tag in self._exif_markers): - # self.logger.info(" ✓ Exif metadata present and readable") - # else: - # self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output") - # else: - # # Try without .meta extension, maybe it's embedded or stored differently - # self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}") - # # Non-fatal - as long as upload/display works - # except Exception as e: - # self.logger.error(f" ✗ Upload verification failed: {e}") - # return False + # Check if metadata file exists + meta_url = base_url + f"/uploads/{image_name}.meta" + self.logger.info(f" → Trying metadata at: {meta_url}") + mr = s.get(meta_url, timeout=10) + if mr.status_code == 200: + meta_text = mr.text.strip() + if any(tag in meta_text for tag in self._exif_markers): + self.logger.info(" ✓ Exif metadata present and readable") + else: + self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output") + else: + # Try without .meta extension, maybe it's embedded or stored differently + self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}") + # Non-fatal - as long as upload/display works + except Exception as e: + self.logger.error(f" ✗ Upload verification failed: {e}") + return False - # # 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven) - # try: - # proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"]) - # out = (proc.stdout or "").strip() - # if "__MISSING__" in out or proc.returncode not in (0,): - # self.logger.warning("⚠ Flag file missing inside container") - # else: - # self.logger.info(" ✓ Container flag present") - # # Optional: compare with host flag if present - # try: - # with open(self.flag_location, "r") as f: - # host_flag = f.read().strip() - # if host_flag and host_flag == out: - # self.logger.info(" ✓ Host and container flags match") - # else: - # self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)") - # except FileNotFoundError: - # self.logger.warning("⚠ Host flag not found; skipping comparison") - # except Exception as e: - # # Non-fatal: you can tune this to fail the round if flag is mandatory. - # self.logger.warning(f"Flag existence check encountered an issue: {e}") + # 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven) + try: + proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"]) + out = (proc.stdout or "").strip() + if "__MISSING__" in out or proc.returncode not in (0,): + self.logger.warning("⚠ Flag file missing inside container") + else: + self.logger.info(" ✓ Container flag present") + # Optional: compare with host flag if present + try: + with open(self.flag_location, "r") as f: + host_flag = f.read().strip() + if host_flag and host_flag == out: + self.logger.info(" ✓ Host and container flags match") + else: + self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)") + except FileNotFoundError: + self.logger.warning("⚠ Host flag not found; skipping comparison") + except Exception as e: + # Non-fatal: you can tune this to fail the round if flag is mandatory. + self.logger.warning(f"Flag existence check encountered an issue: {e}") self.logger.info("SLA check passed ✅") return True diff --git a/services/phew/src/chall.py b/services/phew/src/chall.py index 5816d6e..ecaa332 100644 --- a/services/phew/src/chall.py +++ b/services/phew/src/chall.py @@ -17,40 +17,52 @@ while True: print("2. bingo") print("3. decrypt") print("4. key?") - inp = int(input("> ")) + try: + inp = int(input("> ")) + except (ValueError, EOFError): + print("Invalid input") + continue if inp == 1: print("pt (hex)") - inp = input("> ") - ct = cipher.encrypt(int(inp, 16)) - print('ct : ', '{0:x}'.format(ct)) + try: + inp = input("> ") + ct = cipher.encrypt(int(inp, 16)) + print('ct : ', '{0:x}'.format(ct)) + except (ValueError, EOFError): + print("Invalid hex input") elif inp == 2: print("key (hex)") - user_hex = input("> ").strip() try: + user_hex = input("> ").strip() user_key = bytes.fromhex(user_hex) - except Exception: - print("nope") - continue - - if len(user_key) == 66 and user_key == key: - try: - print(flag_bytes.decode()) - except Exception: - print(flag_bytes.hex()) - else: + + if len(user_key) == 66 and user_key == key: + try: + print(flag_bytes.decode()) + except Exception: + print(flag_bytes.hex()) + else: + print("nope") + except (ValueError, EOFError): print("nope") elif inp == 3: print("ct (hex)") - inp = input("> ") - pt = cipher.decrypt(int(inp, 16)) - print('pt : ', '{0:x}'.format(pt)) + try: + inp = input("> ") + pt = cipher.decrypt(int(inp, 16)) + print('pt : ', '{0:x}'.format(pt)) + except (ValueError, EOFError): + print("Invalid hex input") elif inp == 4: - ct = cipher.encrypt(key_int) - print('ct : ', '{0:x}'.format(ct)) + try: + ct = cipher.encrypt(key_int) + print('ct : ', '{0:x}'.format(ct)) + except Exception: + print("Encryption error") else: exit()