Passwords failed on 10/16 challenges while state.json looked correct:
- only the 6 native GEMASTIK XVIII images provision 'ctfuser'; every imported
XVI/XVII image does 'echo root:${PASSWORD} | chpasswd' and logs in as root.
set_ssh_passwords() hardcoded ctfuser, so chpasswd set a password on an
account nobody uses -> 'Permission denied' everywhere.
Registry gains a per-challenge 'ssh_user'; chpasswd now targets the real
login (and ctfuser/ctf when present) and reports failures loudly.
- phew checker: chall.py block-buffers stdout through the docker exec pipe
(PYTHONUNBUFFERED now set) and leaks chall.py inside the container on
timeout (26 orphans, container saturated) -> reaps the whole exec process
group. Startup does a fresh Pailier keygen (~12 s) so crypto reads need
_CRYPTO_TIMEOUT, not the 5 s prompt default.
Adds panel/verify_ssh_creds.py (proves the state->container binding from
inside via a real login), audit_ssh_users.sh, reset_runtime.sh.
29 lines
680 B
Docker
29 lines
680 B
Docker
FROM ruby:3.2-slim-bookworm
|
|
|
|
ARG PASSWORD
|
|
|
|
RUN echo root:${PASSWORD} | chpasswd
|
|
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
|
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
|
|
apt-get install -y --no-install-recommends \
|
|
openssh-server curl \
|
|
build-essential \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
RUN echo "PasswordAuthentication yes" >> /etc/ssh/sshd_config
|
|
RUN echo "PermitRootLogin yes" >> /etc/ssh/sshd_config
|
|
RUN service ssh start
|
|
|
|
WORKDIR /ctf/art/
|
|
|
|
RUN useradd -m ctf
|
|
RUN chown -R root:root /ctf/art/
|
|
|
|
COPY Gemfile .
|
|
COPY app.rb .
|
|
COPY start.sh .
|
|
|
|
RUN bundle install
|
|
RUN touch /flag.txt
|
|
|
|
RUN chmod +x start.sh
|
|
CMD ./start.sh |