feat: challenge registry-driven platform + XVI/XVII imports + admin toggle + domain rename
- Rename repo/domain: attack-defense-platform / attackdefense.imrnes.team (all refs replaced)
- challenge_registry.json: single source of truth (28 challs across gemastik18/xvi/xvii)
- teams.py: registry-driven CHALLENGES, set_challenge_enabled, sync_challenge_runtime
(apply enable/disable to live teams: build/up or stop/remove + receiver restart)
- compose_gen.py: render per-team compose from canonical per-challenge templates
(image reuse, per-team ports 30xxx, flag mounts, passwords)
- gen_canonical_composes.py: canonical docker-compose.yml for all services
- import_new_challenges.py: import XVI/XVII services + EOL base image fixes
(debian:buster→bookworm, node:14→20, python:3.7-slim→3.11)
- receiver: xvi package (10 checkers) + xvii package (12 generic checkers),
Challenge base reads PASSWORD_<team_port> from env; gen_receiver_main.py
generates per-team main.py from registry
- main.py: /api/challenges returns full registry; PATCH /api/challenges/<name>
toggles enabled + applies to live teams
- index.html: 🏗️ Challenge Manager tab (toggle per challenge, grouped by set)
- SLA bonus now dynamic (all enabled challenges, not hardcoded 6)
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
FROM ubuntu:24.04
|
||||
|
||||
ARG PASSWORD
|
||||
|
||||
ENV DEBIAN_FRONTEND noninteractive
|
||||
|
||||
RUN echo root:${PASSWORD} | chpasswd
|
||||
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
||||
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get install -y openssh-server lib32z1 xinetd cmake gcc curl
|
||||
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
||||
RUN echo "PermitRootLogin yes" >> /etc/ssh/sshd_config
|
||||
RUN service ssh start
|
||||
|
||||
RUN useradd -m ctf
|
||||
|
||||
WORKDIR /ctf
|
||||
|
||||
RUN echo "Connection blocked" > /etc/banner_fail
|
||||
COPY ctf.xinetd /etc/xinetd.d/ctf
|
||||
COPY ./src/main.c ./
|
||||
COPY ./start.sh ./
|
||||
RUN gcc /ctf/main.c -no-pie -fno-stack-protector -Wl,-z,relro,-z,now -o /ctf/main
|
||||
RUN touch /flag.txt
|
||||
RUN chmod -R 755 /ctf
|
||||
RUN chmod +x /ctf/start.sh
|
||||
|
||||
ENTRYPOINT []
|
||||
CMD ["/usr/sbin/xinetd", "-dontfork"]
|
||||
|
||||
EXPOSE 8000
|
||||
@@ -0,0 +1,3 @@
|
||||
Acquire::AllowInsecureRepositories "true";
|
||||
Acquire::AllowDowngradeToInsecureRepositories "true";
|
||||
Apt::Get::AllowUnauthenticated "true";
|
||||
@@ -0,0 +1,18 @@
|
||||
service ctf
|
||||
{
|
||||
disable = no
|
||||
socket_type = stream
|
||||
protocol = tcp
|
||||
wait = no
|
||||
user = root
|
||||
type = UNLISTED
|
||||
port = 8000
|
||||
bind = 0.0.0.0
|
||||
server = /bin/sh
|
||||
server_args = /ctf/start.sh
|
||||
banner_fail = /etc/banner_fail
|
||||
# safety options
|
||||
per_source = 10 # the maximum instances of this service per source IP address
|
||||
rlimit_cpu = 1 # the maximum number of CPU seconds that the service may use
|
||||
#rlimit_as = 1024M # the Address Space resource limit for the service
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
services:
|
||||
back-to-basic:
|
||||
container_name: back-to-basic_container
|
||||
hostname: back-to-basic
|
||||
restart: always
|
||||
build:
|
||||
context: .
|
||||
args:
|
||||
- PASSWORD=$PASSWORD_22000
|
||||
volumes:
|
||||
- ../receiver/flags/back-to-basic.txt:/flag.txt:ro
|
||||
- ../utils/bashrc:/root/.bashrc:ro
|
||||
- ../utils/preexec.sh:/root/.preexec.sh:ro
|
||||
ports:
|
||||
- "22000:8000"
|
||||
- "22022:22"
|
||||
extra_hosts:
|
||||
- "host.docker.internal:host-gateway"
|
||||
@@ -0,0 +1,15 @@
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
void give_me_idea() {
|
||||
char buf[64];
|
||||
puts("Do you have a good idea?");
|
||||
fgets(buf, 200, stdin);
|
||||
}
|
||||
|
||||
void main() {
|
||||
setbuf(stdout, NULL);
|
||||
give_me_idea();
|
||||
puts("hmm... I'm also think the same thing...");
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
/usr/sbin/sshd -D &
|
||||
su ctf -c "/ctf/main"
|
||||
Reference in New Issue
Block a user