fix chall itoid

This commit is contained in:
Rayhan Hanaputra
2025-10-28 09:08:35 +07:00
parent 35b4b74cbb
commit 615f8aa130
2 changed files with 84 additions and 72 deletions
+52 -52
View File
@@ -205,61 +205,61 @@ class Blogpost(Challenge):
self.logger.error(f" ✗ View post failed: {e}")
return False
# # 6) Verify the uploaded image is accessible and check metadata
# self.logger.info("[7/7] Verifying uploaded image and metadata ...")
# try:
# # Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
# m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
# assert m, "No uploaded image link found on post page"
# image_name = m.group(1)
# self.logger.info(f" → Found image: {image_name}")
# 6) Verify the uploaded image is accessible and check metadata
self.logger.info("[7/7] Verifying uploaded image and metadata ...")
try:
# Find something like /uploads/<sha256>.png (or .jpg/.jpeg/.bmp)
m = re.search(r'/uploads/([A-Za-z0-9_.-]+\.(?:png|jpg|jpeg|bmp))', vp.text, flags=re.IGNORECASE)
assert m, "No uploaded image link found on post page"
image_name = m.group(1)
self.logger.info(f" → Found image: {image_name}")
# # Verify the image itself is accessible
# img_url = base_url + f"/uploads/{image_name}"
# img_r = s.get(img_url, timeout=10)
# assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}"
# assert len(img_r.content) > 0, "Image file is empty"
# self.logger.info(" ✓ Uploaded image accessible")
# Verify the image itself is accessible
img_url = base_url + f"/uploads/{image_name}"
img_r = s.get(img_url, timeout=10)
assert img_r.status_code == 200, f"Image file HTTP {img_r.status_code}"
assert len(img_r.content) > 0, "Image file is empty"
self.logger.info(" ✓ Uploaded image accessible")
# # Check if metadata file exists
# meta_url = base_url + f"/uploads/{image_name}.meta"
# self.logger.info(f" → Trying metadata at: {meta_url}")
# mr = s.get(meta_url, timeout=10)
# if mr.status_code == 200:
# meta_text = mr.text.strip()
# if any(tag in meta_text for tag in self._exif_markers):
# self.logger.info(" ✓ Exif metadata present and readable")
# else:
# self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output")
# else:
# # Try without .meta extension, maybe it's embedded or stored differently
# self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}")
# # Non-fatal - as long as upload/display works
# except Exception as e:
# self.logger.error(f" ✗ Upload verification failed: {e}")
# return False
# Check if metadata file exists
meta_url = base_url + f"/uploads/{image_name}.meta"
self.logger.info(f" → Trying metadata at: {meta_url}")
mr = s.get(meta_url, timeout=10)
if mr.status_code == 200:
meta_text = mr.text.strip()
if any(tag in meta_text for tag in self._exif_markers):
self.logger.info(" ✓ Exif metadata present and readable")
else:
self.logger.warning(f" ⚠ Metadata file exists but doesn't look like ExifTool output")
else:
# Try without .meta extension, maybe it's embedded or stored differently
self.logger.warning(f" ⚠ Metadata file returned HTTP {mr.status_code}")
# Non-fatal - as long as upload/display works
except Exception as e:
self.logger.error(f" ✗ Upload verification failed: {e}")
return False
# # 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
# try:
# proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
# out = (proc.stdout or "").strip()
# if "__MISSING__" in out or proc.returncode not in (0,):
# self.logger.warning("⚠ Flag file missing inside container")
# else:
# self.logger.info(" ✓ Container flag present")
# # Optional: compare with host flag if present
# try:
# with open(self.flag_location, "r") as f:
# host_flag = f.read().strip()
# if host_flag and host_flag == out:
# self.logger.info(" ✓ Host and container flags match")
# else:
# self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
# except FileNotFoundError:
# self.logger.warning("⚠ Host flag not found; skipping comparison")
# except Exception as e:
# # Non-fatal: you can tune this to fail the round if flag is mandatory.
# self.logger.warning(f"Flag existence check encountered an issue: {e}")
# 7) Flag existence in container (do not fail SLA if only host copy exists but container is missing—treat as warning or policy-driven)
try:
proc = self._docker_exec(["/bin/sh", "-lc", f"test -f {self.container_flag_path} && cat {self.container_flag_path} || echo __MISSING__"])
out = (proc.stdout or "").strip()
if "__MISSING__" in out or proc.returncode not in (0,):
self.logger.warning("⚠ Flag file missing inside container")
else:
self.logger.info(" ✓ Container flag present")
# Optional: compare with host flag if present
try:
with open(self.flag_location, "r") as f:
host_flag = f.read().strip()
if host_flag and host_flag == out:
self.logger.info(" ✓ Host and container flags match")
else:
self.logger.warning("⚠ Host/container flag mismatch (may be expected if rotated separately)")
except FileNotFoundError:
self.logger.warning("⚠ Host flag not found; skipping comparison")
except Exception as e:
# Non-fatal: you can tune this to fail the round if flag is mandatory.
self.logger.warning(f"Flag existence check encountered an issue: {e}")
self.logger.info("SLA check passed ✅")
return True
+16 -4
View File
@@ -17,22 +17,26 @@ while True:
print("2. bingo")
print("3. decrypt")
print("4. key?")
try:
inp = int(input("> "))
except (ValueError, EOFError):
print("Invalid input")
continue
if inp == 1:
print("pt (hex)")
try:
inp = input("> ")
ct = cipher.encrypt(int(inp, 16))
print('ct : ', '{0:x}'.format(ct))
except (ValueError, EOFError):
print("Invalid hex input")
elif inp == 2:
print("key (hex)")
user_hex = input("> ").strip()
try:
user_hex = input("> ").strip()
user_key = bytes.fromhex(user_hex)
except Exception:
print("nope")
continue
if len(user_key) == 66 and user_key == key:
try:
@@ -41,16 +45,24 @@ while True:
print(flag_bytes.hex())
else:
print("nope")
except (ValueError, EOFError):
print("nope")
elif inp == 3:
print("ct (hex)")
try:
inp = input("> ")
pt = cipher.decrypt(int(inp, 16))
print('pt : ', '{0:x}'.format(pt))
except (ValueError, EOFError):
print("Invalid hex input")
elif inp == 4:
try:
ct = cipher.encrypt(key_int)
print('ct : ', '{0:x}'.format(ct))
except Exception:
print("Encryption error")
else:
exit()