Passwords failed on 10/16 challenges while state.json looked correct:
- only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password on an
account nobody uses -> 'Permission denied' everywhere.
Registry gains a per-challenge 'ssh_user'; chpasswd now targets the real
login (and ctfuser/ctf when present) and reports failures loudly.
- phew checker: chall.py block-buffers stdout through the docker exec pipe
(PYTHONUNBUFFERED now set) and leaks chall.py inside the container on
timeout (26 orphans, container saturated) -> reaps the whole exec process
group. Startup does a fresh Pailier keygen (~12 s) so crypto reads need
_CRYPTO_TIMEOUT, not the 5 s prompt default.
Adds panel/verify_ssh_creds.py (proves the state->container binding from
inside via a real login), audit_ssh_users.sh, reset_runtime.sh.
34 lines
1.1 KiB
Python
34 lines
1.1 KiB
Python
#!/usr/bin/env python3
|
|
"""Open (or close) UFW for every live team's port block.
|
|
|
|
The panel opens a team's ports at create time, but teams created out-of-band
|
|
(scripts, git checkout, a half-finished create_team) never got rules, and this
|
|
host's UFW defaults to deny(incoming) — so those teams are blackholed. Run
|
|
after any bulk team creation:
|
|
|
|
python3 panel/sync_all_team_ufw.py # open
|
|
python3 panel/sync_all_team_ufw.py --remove # close
|
|
"""
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
sys.path.insert(0, str(Path(__file__).resolve().parent))
|
|
import teams as orch
|
|
|
|
def main():
|
|
remove = "--remove" in sys.argv
|
|
live = orch.list_teams()
|
|
if not live:
|
|
print("no teams")
|
|
return
|
|
for t in live:
|
|
idx = t["index"]
|
|
r = orch.sync_team_ufw(idx, remove=remove)
|
|
verb = "closed" if remove else "opened"
|
|
bad = f" FAILED={r['failed']}" if r.get("failed") else ""
|
|
print(f"team{idx} ({t.get('label')}): {verb} {len(r.get('closed' if remove else 'opened', []))}"
|
|
f"/{r['ports']} ports{bad}")
|
|
|
|
if __name__ == "__main__":
|
|
main()
|