Initial commit

This commit is contained in:
Rayhan Hanaputra
2025-10-10 22:18:06 +07:00
committed by GitHub
commit ea02892f14
1246 changed files with 289342 additions and 0 deletions
+42
View File
@@ -0,0 +1,42 @@
FROM python:3.9-slim
ARG PASSWORD
WORKDIR /app
RUN apt-get update && \
apt-get install -y nano openssh-server \
gcc curl
# Create ctfuser and set password
RUN useradd -m -d /app ctfuser && echo ctfuser:${PASSWORD} | chpasswd
# Configure SSH for ctfuser
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && \
echo "PermitRootLogin no" >> /etc/ssh/sshd_config && \
echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config
# Start SSH service
RUN ssh-keygen -A
RUN mkdir -p /run/sshd && chmod 755 /run/sshd
RUN apt update
RUN apt install python3-pip -y
RUN pip3 install flask==3.0.2 --break-system-packages
COPY /src .
COPY flag.txt ../
# Restrict ctfuser access to only the working directory
RUN chown -R ctfuser:ctfuser /app/scripts && \
chmod 700 /app/scripts
# Restrict ctfuser access to only the working directory
RUN chown -R ctfuser:ctfuser /app/satanize.py && \
chmod 700 /app/satanize.py
COPY start.sh .
RUN chmod +x start.sh
# Start SSH service as root and then switch to ctfuser
CMD service ssh start && ./start.sh
+15
View File
@@ -0,0 +1,15 @@
version: "3"
services:
naraka:
restart: always
container_name: naraka
build:
context: ./
args:
- PASSWORD=PASSWORD_12000
ports:
- "12000:5000"
- "12022:22"
# volumes:
# - ./flag.txt:/flag.txt:ro
+1
View File
@@ -0,0 +1 @@
Th1s_15_y0Ur_Fl4G
+1
View File
@@ -0,0 +1 @@
Flask==3.0.2
+77
View File
@@ -0,0 +1,77 @@
from flask import Flask, request, render_template_string, render_template
import subprocess
import os
import satanize
app = Flask(__name__)
# Load flag content
FLAG = open('../flag.txt', 'r').read().strip()
@app.route('/', methods=['GET', 'POST'])
def index():
return render_template("index.html", result="")
@app.route('/chall', methods=['POST'])
def chall():
userinput = ""
name = ""
if request.method == 'POST':
challindex = request.form['chall']
if challindex != '1' and challindex != '2':
return render_template("index.html", result="")
if challindex == '1':
script = "scripts/execute.py"
desc = "It will execute every single line code (Math, Logical check, Concat String, Statistics): a = 5;b = 4;print(a+b), x = 23;y = 23;print(x==y), a = 'The'; b = 'demon'; print(a+b), x = [1,2,3,4,5,6,7,8];print(max(x)), etc"
elif challindex == '2':
script = "scripts/evaluate.py"
desc = "It will calculate your sins: 1+1, 2*2, 5-2, etc"
try:
userinput = request.form['input']
except Exception as e:
return render_template("chall.html", challindex = challindex, result = "", desc=desc)
if(userinput != ""):
try:
FLAG = open('../flag.txt', 'r').read().strip()
result = subprocess.check_output(['python', script, userinput, FLAG])
print(result)
except subprocess.CalledProcessError as e:
result = e.output.decode()
return render_template("chall.html", challindex = challindex, result=result, desc = desc)
else:
return render_template("chall.html", challindex = challindex, result = "", desc = desc)
@app.route('/render', methods=['GET'])
def render():
with open('templates/template.html', 'r') as file:
template = file.read()
name = request.args.get('name')
if name != "":
try:
stn = satanize.Satanize()
if(stn.satanizer(name)):
name = "Bad boy"
return render_template_string(template.replace("thisistemplate",name))
except Exception as e:
pass
return render_template_string(template.replace("thisistemplate",request.args.get('name')))
else:
return "Hello, please send me your 'name'"
@app.route('/sourcecode/<challindex>', methods=['GET'])
def sourcecode(challindex):
if challindex == '1':
sc = "scripts/execute.py"
elif challindex == '2':
sc = "scripts/evaluate.py"
elif challindex == '3':
sc = "satanize.py"
# Read the content of script.py
with open(sc, 'r') as script_file:
script_content = script_file.read()
return render_template("source.html", script_content=script_content)
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000, debug=1)
Binary file not shown.
+12
View File
@@ -0,0 +1,12 @@
class Satanize:
def __init__(self):
FLAG = open('../flag.txt', 'r').read().strip()
self.banned_words = ["7","import","system"]
# self.banned_words = ""
def satanizer(self, text):
for word in self.banned_words:
if word in text:
print("SATANNNNNNNN")
return True
return False
+19
View File
@@ -0,0 +1,19 @@
import sys
import string
BLACKLIST ="abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ"
# BLACKLIST = ""
# You cannot change the value of FLAG, FLAG can only be filled with sys.argv[2]
FLAG = sys.argv[2]
def security_check(user_input, blacklist):
for bl in blacklist:
if bl in user_input:
return 1
if __name__ == "__main__":
user_input = sys.argv[1]
if(security_check(user_input,BLACKLIST)):
print("too bad")
else:
print(eval(user_input))
+23
View File
@@ -0,0 +1,23 @@
import sys
import string
BLACKLIST =['FLAG','cat']
# BLACKLIST = ""
# You cannot change the value of FLAG, FLAG can only be filled with sys.argv[2]
FLAG = sys.argv[2]
def security_check(user_input, blacklist):
for bl in blacklist:
if bl in user_input:
return 1
if __name__ == "__main__":
user_input = sys.argv[1]
if(security_check(user_input,BLACKLIST)):
print("too bads")
else:
try:
user_input = eval(user_input)
except Exception as e:
pass
exec(user_input)
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.7 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.9 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.7 MiB

+47
View File
@@ -0,0 +1,47 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>It is not Jail, it is Hellllll</title>
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
<style>
/* Animasi flicker */
.flicker {
animation: flickerAnimation 0.1s infinite;
}
@keyframes flickerAnimation {
0% {
opacity: 1;
}
50% {
opacity: 0.5;
}
100% {
opacity: 1;
}
}
</style>
</head>
<body class="bg-black text-red-500 min-h-screen flex flex-col justify-center items-center flicker">
<div class="w-full max-w-md p-8 bg-gray-800 rounded-lg shadow-lg">
<h1 class="text-4xl font-bold text-center mb-8 text-red-600">It is not Jail, it is Hellllll</h1>
<a>{{ desc }}</a>
<form method="POST" action="/chall" class="space-y-4">
<div>
<label for="input" class="block text-lg font-medium text-red-500">Input:</label>
<input type="text" id="input" name="input" class="w-full p-2 rounded bg-gray-700 text-white focus:outline-none focus:ring-2 focus:ring-red-600" required />
</div>
<input type="text" id="chall" name="chall" value="{{challindex}}" hidden />
<button type="submit" class="w-full p-3 mt-4 bg-red-600 hover:bg-red-700 text-white rounded font-bold">Submit</button>
</form>
<a href="/"><button class="w-full p-3 mt-4 bg-black hover:bg-gray-700 text-red rounded font-bold">Back</button></a>
<h2 class="text-2xl font-semibold mt-8 text-red-500">Output:</h2>
<pre class="bg-gray-900 p-4 rounded text-white mt-2">{{ result }}</pre>
<a href="/sourcecode/{{challindex}}" class="block mt-6 text-center text-red-400 hover:text-red-500 underline">Source code</a>
</div>
<!-- Include footer -->
{% include 'footer.html' %}
</body>
</html>
@@ -0,0 +1,7 @@
<footer class="bg-red-900 text-white py-4 mt-10">
<div class="container mx-auto text-center">
<p>Made with ❤️ by AODreamer</p>
</div>
</footer>
</body>
</html>
+27
View File
@@ -0,0 +1,27 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>NARAKA</title>
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
<style>
/* Animasi flicker */
.flicker {
animation: flickerAnimation 0.1s infinite;
}
@keyframes flickerAnimation {
0% { opacity: 1; }
50% { opacity: 0.5; }
100% { opacity: 1; }
}
</style>
</head>
<body class="flex flex-col min-h-screen bg-red-800 flicker">
<header class="bg-red-600 text-white py-4">
<div class="container mx-auto text-center">
<h1 class="text-4xl font-bold">NARAKA</h1>
</div>
</header>
+44
View File
@@ -0,0 +1,44 @@
{% include 'header.html' %}
<!-- Main content -->
<main class="flex-grow container mx-auto mt-10 bg-red-800">
<div class="grid grid-cols-1 md:grid-cols-3 gap-8">
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div3" onclick="window.location.href = '/render?name=world!'">
<img src="{{ url_for('static', filename='images/greetings.png') }}" alt="Menu 3" class="mx-auto mb-4" />
<p class="text-lg font-semibold">Greetings</p>
</div>
<!-- Menu Box 2 -->
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div2">
<form id="challForm2" action="/chall" method="POST">
<input type="hidden" name="chall" value="2" />
<img src="{{ url_for('static', filename='images/evaluate.png') }}" alt="Menu 2" class="mx-auto mb-4" />
<p class="text-lg font-semibold">Evaluate</p>
</form>
</div>
<!-- Menu Box 1 -->
<div class="bg-red-700 rounded-lg shadow-lg p-4 text-center hover:bg-gray-900 cursor-pointer" id="div1">
<form id="challForm1" action="/chall" method="POST">
<input type="hidden" name="chall" value="1" />
<img src="{{ url_for('static', filename='images/execute.png') }}" alt="Menu 1" class="mx-auto mb-4" />
<p class="text-lg font-semibold">Execute</p>
</form>
</div>
<!-- Menu Box 3 -->
</div>
</main>
<script>
document.getElementById("div1").addEventListener("click", function () {
document.getElementById("challForm1").submit();
});
document.getElementById("div2").addEventListener("click", function () {
document.getElementById("challForm2").submit();
});
document.getElementById("div3").addEventListener("click", function () {
document.getElementById("challForm3").submit();
});
</script>
<!-- Include footer -->
{% include 'footer.html' %}
+60
View File
@@ -0,0 +1,60 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<title>Wujud Aseli</title>
<link href="https://cdn.jsdelivr.net/npm/tailwindcss@2.2.19/dist/tailwind.min.css" rel="stylesheet" />
<link href="https://cdn.jsdelivr.net/npm/prismjs@1.29.0/themes/prism.min.css" rel="stylesheet" />
<style>
pre {
background-color: #cd0000;
color: rgb(249, 249, 249);
border-radius: 8px;
padding: 16px;
overflow-x: auto;
white-space: pre-wrap; /* Allows long lines to wrap */
}
pre,
code {
user-select: none; /* Disable text selection */
-webkit-user-select: none; /* Disable text selection in WebKit browsers */
-moz-user-select: none; /* Disable text selection in Mozilla browsers */
-ms-user-select: none; /* Disable text selection in Internet Explorer/Edge */
pointer-events: none; /* Prevent all mouse events */
cursor: default; /* Set cursor to default */
}
/* Animasi flicker */
.flicker {
animation: flickerAnimation 0.0666s infinite;
}
@keyframes flickerAnimation {
0% {
opacity: 1;
}
50% {
opacity: 0.5;
}
100% {
opacity: 1;
}
}
</style>
</head>
<body class="bg-red-900 text-gray-100 flex flex-col min-h-screen flicker">
<header class="bg-gray-800 text-center py-4">
<h1 class="text-2xl font-bold">Wujud Aseli</h1>
</header>
<main class="flex-grow p-8">
<h2 class="text-xl font-semibold mb-4">Source Code:</h2>
<pre><code class="language-python">{{ script_content | safe }}</code></pre>
</main>
<footer class="bg-gray-800 text-center py-4">Made with love by AODreamer</footer>
<script src="https://cdn.jsdelivr.net/npm/prismjs@1.29.0/prism.min.js"></script>
<script>
// Highlight syntax after content is set
Prism.highlightAll();
</script>
</body>
</html>
File diff suppressed because one or more lines are too long
+4
View File
@@ -0,0 +1,4 @@
#!/bin/bash
/usr/sbin/sshd -D &
python3 app.py