FROM public.ecr.aws/docker/library/golang:1.21-alpine AS builder # Build the Go application WORKDIR /app COPY src/main.go . RUN go build -o challenge main.go # Final stage FROM public.ecr.aws/docker/library/ubuntu:20.04 ARG PASSWORD ENV DEBIAN_FRONTEND=noninteractive # Install necessary packages RUN apt-get update && apt-get install -y nano openssh-server python3 curl netcat-traditional wget sudo nginx golang-go && rm -rf /var/lib/apt/lists/* # Create ctfuser and set password RUN useradd -m -d /home/ctfuser ctfuser && echo ctfuser:${PASSWORD} | chpasswd # Configure SSH RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config && echo "PermitRootLogin no" >> /etc/ssh/sshd_config && echo "AllowUsers ctfuser" >> /etc/ssh/sshd_config && echo "PermitEmptyPasswords no" >> /etc/ssh/sshd_config # Generate SSH host keys RUN ssh-keygen -A RUN mkdir -p /run/sshd && chmod 755 /run/sshd # Create working directories RUN mkdir -p /opt/files && chmod 755 /opt && chmod 755 /opt/files # Copy the built binary from builder stage COPY --from=builder /app/challenge /opt/challenge RUN chmod 755 /opt/challenge && chown ctfuser:ctfuser /opt/challenge # Copy HTML template COPY src/index.html /opt/index.html RUN chmod 644 /opt/index.html # Create sample files for the file viewer RUN echo "Welcome to the File Viewer Challenge!\n\nThis is a simple file viewer application.\nYou can view different files using the /view endpoint.\n\nExample: /view?file=welcome.txt\n\nGood luck finding the flag!" > /opt/files/welcome.txt RUN echo "File Viewer v1.0\n\nThis application allows you to view text files stored in /opt/files/\n\nAvailable files:\n- welcome.txt\n- info.txt\n- hint.txt" > /opt/files/info.txt RUN echo "Hint: The flag is hidden somewhere on the system.\nMaybe you can try viewing other files?\nWhat about files outside the /opt/files/ directory?\n\nThink about path traversal..." > /opt/files/hint.txt RUN chmod 644 /opt/files/*.txt # Create flag file COPY flag.txt /flag.txt RUN chmod 444 /flag.txt && chown root:root /flag.txt # Copy main.go for users to patch COPY src/main.go /opt/main.go RUN chown ctfuser:ctfuser /opt/main.go && chmod 644 /opt/main.go # Create rebuild script for users RUN echo '#!/bin/bash' > /opt/rebuild.sh && \ echo 'echo "Building patched challenge..."' >> /opt/rebuild.sh && \ echo 'cd /opt' >> /opt/rebuild.sh && \ echo 'go build -o challenge.new main.go' >> /opt/rebuild.sh && \ echo 'if [ $? -ne 0 ]; then' >> /opt/rebuild.sh && \ echo ' echo "Build failed!"' >> /opt/rebuild.sh && \ echo ' exit 1' >> /opt/rebuild.sh && \ echo 'fi' >> /opt/rebuild.sh && \ echo 'chmod 755 /opt/challenge.new' >> /opt/rebuild.sh && \ echo 'echo "Restarting challenge..."' >> /opt/rebuild.sh && \ echo 'mv /opt/challenge.new /opt/challenge' >> /opt/rebuild.sh && \ echo 'pkill -f /opt/challenge' >> /opt/rebuild.sh && \ echo 'sleep 1' >> /opt/rebuild.sh && \ echo '/opt/challenge >/tmp/challenge.log 2>&1 &' >> /opt/rebuild.sh && \ echo 'echo "Challenge rebuilt and restarted!"' >> /opt/rebuild.sh && \ chmod +x /opt/rebuild.sh && \ chown ctfuser:ctfuser /opt/rebuild.sh # Configure nginx COPY nginx.conf /etc/nginx/sites-available/warmup RUN ln -s /etc/nginx/sites-available/warmup /etc/nginx/sites-enabled/warmup && rm -f /etc/nginx/sites-enabled/default && chown root:root /etc/nginx/sites-available/warmup && chmod 644 /etc/nginx/sites-available/warmup # Create startup script RUN echo '#!/bin/bash' > /opt/start.sh && echo 'set -e' >> /opt/start.sh && echo 'service ssh start' >> /opt/start.sh && echo 'nginx -t && service nginx start || echo "Nginx config error"' >> /opt/start.sh && echo 'su - ctfuser -c "/opt/challenge >/tmp/challenge.log 2>&1 &"' >> /opt/start.sh && echo 'sleep 1' >> /opt/start.sh && echo 'pgrep -f /opt/challenge > /tmp/challenge.pid' >> /opt/start.sh && echo 'trap "if [ -f /tmp/challenge.pid ]; then kill -TERM $(cat /tmp/challenge.pid) 2>/dev/null || true; fi; exit 0" SIGTERM SIGINT' >> /opt/start.sh && echo 'tail -f /dev/null' >> /opt/start.sh && chmod +x /opt/start.sh EXPOSE 8080 22 USER root CMD ["/opt/start.sh"]