Initial commit
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
FROM python:3.9-slim
|
||||
|
||||
ARG PASSWORD
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
RUN apt-get update && \
|
||||
apt-get install -y nano openssh-server \
|
||||
gcc curl
|
||||
|
||||
# Create ctfuser and set password
|
||||
RUN useradd -m -d /app ctfuser && echo ctfuser:${PASSWORD} | chpasswd
|
||||
|
||||
# Configure SSH for ctfuser
|
||||
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
|
||||
echo "PermitRootLogin no" >> /etc/ssh/sshd_config && \
|
||||
echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config
|
||||
|
||||
# Start SSH service
|
||||
RUN ssh-keygen -A
|
||||
RUN mkdir -p /run/sshd && chmod 755 /run/sshd
|
||||
|
||||
RUN apt update
|
||||
RUN apt install python3-pip -y
|
||||
RUN pip3 install flask==3.0.2 --break-system-packages
|
||||
|
||||
COPY /src .
|
||||
COPY flag.txt ../
|
||||
|
||||
# Restrict ctfuser access to only the working directory
|
||||
RUN chown -R ctfuser:ctfuser /app/scripts && \
|
||||
chmod 700 /app/scripts
|
||||
|
||||
# Restrict ctfuser access to only the working directory
|
||||
RUN chown -R ctfuser:ctfuser /app/satanize.py && \
|
||||
chmod 700 /app/satanize.py
|
||||
|
||||
COPY start.sh .
|
||||
RUN chmod +x start.sh
|
||||
|
||||
# Start SSH service as root and then switch to ctfuser
|
||||
CMD service ssh start && ./start.sh
|
||||
@@ -0,0 +1,15 @@
|
||||
version: "3"
|
||||
|
||||
services:
|
||||
naraka:
|
||||
restart: always
|
||||
container_name: naraka
|
||||
build:
|
||||
context: ./
|
||||
args:
|
||||
- PASSWORD=PASSWORD_12000
|
||||
ports:
|
||||
- "12000:5000"
|
||||
- "12022:22"
|
||||
# volumes:
|
||||
# - ./flag.txt:/flag.txt:ro
|
||||
@@ -0,0 +1 @@
|
||||
Th1s_15_y0Ur_Fl4G
|
||||
@@ -0,0 +1 @@
|
||||
Flask==3.0.2
|
||||
Binary file not shown.
@@ -0,0 +1,77 @@
|
||||
from flask import Flask, request, render_template_string, render_template
|
||||
import subprocess
|
||||
import os
|
||||
import satanize
|
||||
|
||||
app = Flask(__name__)
|
||||
|
||||
# Load flag content
|
||||
FLAG = open('../flag.txt', 'r').read().strip()
|
||||
|
||||
@app.route('/', methods=['GET', 'POST'])
|
||||
def index():
|
||||
return render_template("index.html", result="")
|
||||
|
||||
@app.route('/chall', methods=['POST'])
|
||||
def chall():
|
||||
userinput = ""
|
||||
name = ""
|
||||
if request.method == 'POST':
|
||||
challindex = request.form['chall']
|
||||
if challindex != '1' and challindex != '2':
|
||||
return render_template("index.html", result="")
|
||||
if challindex == '1':
|
||||
script = "scripts/execute.py"
|
||||
desc = "It will execute every single line code (Math, Logical check, Concat String, Statistics): a = 5;b = 4;print(a+b), x = 23;y = 23;print(x==y), a = 'The'; b = 'demon'; print(a+b), x = [1,2,3,4,5,6,7,8];print(max(x)), etc"
|
||||
elif challindex == '2':
|
||||
script = "scripts/evaluate.py"
|
||||
desc = "It will calculate your sins: 1+1, 2*2, 5-2, etc"
|
||||
try:
|
||||
userinput = request.form['input']
|
||||
except Exception as e:
|
||||
return render_template("chall.html", challindex = challindex, result = "", desc=desc)
|
||||
|
||||
if(userinput != ""):
|
||||
try:
|
||||
FLAG = open('../flag.txt', 'r').read().strip()
|
||||
result = subprocess.check_output(['python', script, userinput, FLAG])
|
||||
print(result)
|
||||
except subprocess.CalledProcessError as e:
|
||||
result = e.output.decode()
|
||||
return render_template("chall.html", challindex = challindex, result=result, desc = desc)
|
||||
else:
|
||||
return render_template("chall.html", challindex = challindex, result = "", desc = desc)
|
||||
|
||||
@app.route('/render', methods=['GET'])
|
||||
def render():
|
||||
with open('templates/template.html', 'r') as file:
|
||||
template = file.read()
|
||||
name = request.args.get('name')
|
||||
if name != "":
|
||||
try:
|
||||
stn = satanize.Satanize()
|
||||
if(stn.satanizer(name)):
|
||||
name = "Bad boy"
|
||||
return render_template_string(template.replace("thisistemplate",name))
|
||||
except Exception as e:
|
||||
pass
|
||||
return render_template_string(template.replace("thisistemplate",request.args.get('name')))
|
||||
else:
|
||||
return "Hello, please send me your 'name'"
|
||||
|
||||
@app.route('/sourcecode/<challindex>', methods=['GET'])
|
||||
def sourcecode(challindex):
|
||||
if challindex == '1':
|
||||
sc = "scripts/execute.py"
|
||||
elif challindex == '2':
|
||||
sc = "scripts/evaluate.py"
|
||||
elif challindex == '3':
|
||||
sc = "satanize.py"
|
||||
# Read the content of script.py
|
||||
with open(sc, 'r') as script_file:
|
||||
script_content = script_file.read()
|
||||
|
||||
return render_template("source.html", script_content=script_content)
|
||||
|
||||
if __name__ == '__main__':
|
||||
app.run(host='0.0.0.0', port=5000, debug=1)
|
||||
Binary file not shown.
@@ -0,0 +1,12 @@
|
||||
class Satanize:
|
||||
def __init__(self):
|
||||
FLAG = open('../flag.txt', 'r').read().strip()
|
||||
self.banned_words = ["7","import","system"]
|
||||
# self.banned_words = ""
|
||||
|
||||
def satanizer(self, text):
|
||||
for word in self.banned_words:
|
||||
if word in text:
|
||||
print("SATANNNNNNNN")
|
||||
return True
|
||||
return False
|
||||
@@ -0,0 +1,19 @@
|
||||
import sys
|
||||
import string
|
||||
BLACKLIST ="abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ"
|
||||
# BLACKLIST = ""
|
||||
# You cannot change the value of FLAG, FLAG can only be filled with sys.argv[2]
|
||||
FLAG = sys.argv[2]
|
||||
|
||||
|
||||
def security_check(user_input, blacklist):
|
||||
for bl in blacklist:
|
||||
if bl in user_input:
|
||||
return 1
|
||||
|
||||
if __name__ == "__main__":
|
||||
user_input = sys.argv[1]
|
||||
if(security_check(user_input,BLACKLIST)):
|
||||
print("too bad")
|
||||
else:
|
||||
print(eval(user_input))
|
||||
@@ -0,0 +1,23 @@
|
||||
import sys
|
||||
import string
|
||||
|
||||
BLACKLIST =['FLAG','cat']
|
||||
# BLACKLIST = ""
|
||||
# You cannot change the value of FLAG, FLAG can only be filled with sys.argv[2]
|
||||
FLAG = sys.argv[2]
|
||||
|
||||
def security_check(user_input, blacklist):
|
||||
for bl in blacklist:
|
||||
if bl in user_input:
|
||||
return 1
|
||||
|
||||
if __name__ == "__main__":
|
||||
user_input = sys.argv[1]
|
||||
if(security_check(user_input,BLACKLIST)):
|
||||
print("too bads")
|
||||
else:
|
||||
try:
|
||||
user_input = eval(user_input)
|
||||
except Exception as e:
|
||||
pass
|
||||
exec(user_input)
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 1.7 MiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.9 MiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.7 MiB |
@@ -0,0 +1,47 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>It is not Jail, it is Hellllll</title>
|
||||
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
|
||||
<style>
|
||||
/* Animasi flicker */
|
||||
.flicker {
|
||||
animation: flickerAnimation 0.1s infinite;
|
||||
}
|
||||
|
||||
@keyframes flickerAnimation {
|
||||
0% {
|
||||
opacity: 1;
|
||||
}
|
||||
50% {
|
||||
opacity: 0.5;
|
||||
}
|
||||
100% {
|
||||
opacity: 1;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body class="bg-black text-red-500 min-h-screen flex flex-col justify-center items-center flicker">
|
||||
<div class="w-full max-w-md p-8 bg-gray-800 rounded-lg shadow-lg">
|
||||
<h1 class="text-4xl font-bold text-center mb-8 text-red-600">It is not Jail, it is Hellllll</h1>
|
||||
<a>{{ desc }}</a>
|
||||
<form method="POST" action="/chall" class="space-y-4">
|
||||
<div>
|
||||
<label for="input" class="block text-lg font-medium text-red-500">Input:</label>
|
||||
<input type="text" id="input" name="input" class="w-full p-2 rounded bg-gray-700 text-white focus:outline-none focus:ring-2 focus:ring-red-600" required />
|
||||
</div>
|
||||
<input type="text" id="chall" name="chall" value="{{challindex}}" hidden />
|
||||
<button type="submit" class="w-full p-3 mt-4 bg-red-600 hover:bg-red-700 text-white rounded font-bold">Submit</button>
|
||||
</form>
|
||||
<a href="/"><button class="w-full p-3 mt-4 bg-black hover:bg-gray-700 text-red rounded font-bold">Back</button></a>
|
||||
<h2 class="text-2xl font-semibold mt-8 text-red-500">Output:</h2>
|
||||
<pre class="bg-gray-900 p-4 rounded text-white mt-2">{{ result }}</pre>
|
||||
<a href="/sourcecode/{{challindex}}" class="block mt-6 text-center text-red-400 hover:text-red-500 underline">Source code</a>
|
||||
</div>
|
||||
<!-- Include footer -->
|
||||
{% include 'footer.html' %}
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,7 @@
|
||||
<footer class="bg-red-900 text-white py-4 mt-10">
|
||||
<div class="container mx-auto text-center">
|
||||
<p>Made with ❤️ by AODreamer</p>
|
||||
</div>
|
||||
</footer>
|
||||
</body>
|
||||
</html>
|
||||
@@ -0,0 +1,27 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>NARAKA</title>
|
||||
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
|
||||
<style>
|
||||
/* Animasi flicker */
|
||||
.flicker {
|
||||
animation: flickerAnimation 0.1s infinite;
|
||||
}
|
||||
|
||||
@keyframes flickerAnimation {
|
||||
0% { opacity: 1; }
|
||||
50% { opacity: 0.5; }
|
||||
100% { opacity: 1; }
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body class="flex flex-col min-h-screen bg-red-800 flicker">
|
||||
<header class="bg-red-600 text-white py-4">
|
||||
<div class="container mx-auto text-center">
|
||||
<h1 class="text-4xl font-bold">NARAKA</h1>
|
||||
</div>
|
||||
</header>
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
{% include 'header.html' %}
|
||||
|
||||
<!-- Main content -->
|
||||
<main class="flex-grow container mx-auto mt-10 bg-red-800">
|
||||
<div class="grid grid-cols-1 md:grid-cols-3 gap-8">
|
||||
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div3" onclick="window.location.href = '/render?name=world!'">
|
||||
<img src="{{ url_for('static', filename='images/greetings.png') }}" alt="Menu 3" class="mx-auto mb-4" />
|
||||
<p class="text-lg font-semibold">Greetings</p>
|
||||
</div>
|
||||
|
||||
<!-- Menu Box 2 -->
|
||||
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div2">
|
||||
<form id="challForm2" action="/chall" method="POST">
|
||||
<input type="hidden" name="chall" value="2" />
|
||||
<img src="{{ url_for('static', filename='images/evaluate.png') }}" alt="Menu 2" class="mx-auto mb-4" />
|
||||
<p class="text-lg font-semibold">Evaluate</p>
|
||||
</form>
|
||||
</div>
|
||||
<!-- Menu Box 1 -->
|
||||
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div1">
|
||||
<form id="challForm1" action="/chall" method="POST">
|
||||
<input type="hidden" name="chall" value="1" />
|
||||
<img src="{{ url_for('static', filename='images/execute.png') }}" alt="Menu 1" class="mx-auto mb-4" />
|
||||
<p class="text-lg font-semibold">Execute</p>
|
||||
</form>
|
||||
</div>
|
||||
<!-- Menu Box 3 -->
|
||||
</div>
|
||||
</main>
|
||||
|
||||
<script>
|
||||
document.getElementById("div1").addEventListener("click", function () {
|
||||
document.getElementById("challForm1").submit();
|
||||
});
|
||||
document.getElementById("div2").addEventListener("click", function () {
|
||||
document.getElementById("challForm2").submit();
|
||||
});
|
||||
document.getElementById("div3").addEventListener("click", function () {
|
||||
document.getElementById("challForm3").submit();
|
||||
});
|
||||
</script>
|
||||
|
||||
<!-- Include footer -->
|
||||
{% include 'footer.html' %}
|
||||
@@ -0,0 +1,60 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
<head>
|
||||
<meta charset="UTF-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<title>Wujud Aseli</title>
|
||||
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
|
||||
<link href="https://cdn.jsdelivr.net/npm/prismjs@1.29.0/themes/prism.min.css" rel="stylesheet" />
|
||||
<style>
|
||||
pre {
|
||||
background-color: #cd0000;
|
||||
color: rgb(249, 249, 249);
|
||||
border-radius: 8px;
|
||||
padding: 16px;
|
||||
overflow-x: auto;
|
||||
white-space: pre-wrap; /* Allows long lines to wrap */
|
||||
}
|
||||
pre,
|
||||
code {
|
||||
user-select: none; /* Disable text selection */
|
||||
-webkit-user-select: none; /* Disable text selection in WebKit browsers */
|
||||
-moz-user-select: none; /* Disable text selection in Mozilla browsers */
|
||||
-ms-user-select: none; /* Disable text selection in Internet Explorer/Edge */
|
||||
pointer-events: none; /* Prevent all mouse events */
|
||||
cursor: default; /* Set cursor to default */
|
||||
}
|
||||
/* Animasi flicker */
|
||||
.flicker {
|
||||
animation: flickerAnimation 0.0666s infinite;
|
||||
}
|
||||
|
||||
@keyframes flickerAnimation {
|
||||
0% {
|
||||
opacity: 1;
|
||||
}
|
||||
50% {
|
||||
opacity: 0.5;
|
||||
}
|
||||
100% {
|
||||
opacity: 1;
|
||||
}
|
||||
}
|
||||
</style>
|
||||
</head>
|
||||
<body class="bg-red-900 text-gray-100 flex flex-col min-h-screen flicker">
|
||||
<header class="bg-gray-800 text-center py-4">
|
||||
<h1 class="text-2xl font-bold">Wujud Aseli</h1>
|
||||
</header>
|
||||
<main class="flex-grow p-8">
|
||||
<h2 class="text-xl font-semibold mb-4">Source Code:</h2>
|
||||
<pre><code class="language-python">{{ script_content | safe }}</code></pre>
|
||||
</main>
|
||||
<footer class="bg-gray-800 text-center py-4">Made with love by AODreamer</footer>
|
||||
<script src="https://cdn.jsdelivr.net/npm/prismjs@1.29.0/prism.min.js"></script>
|
||||
<script>
|
||||
// Highlight syntax after content is set
|
||||
Prism.highlightAll();
|
||||
</script>
|
||||
</body>
|
||||
</html>
|
||||
File diff suppressed because one or more lines are too long
@@ -0,0 +1,4 @@
|
||||
#!/bin/bash
|
||||
|
||||
/usr/sbin/sshd -D &
|
||||
python3 app.py
|
||||
Reference in New Issue
Block a user