- all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed - apt-insecure.conf (AllowInsecureRepositories) copied into images so participants can apt-get install despite expired Ubuntu/Debian GPG keys - warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04 - installed vim+git live into all 18 running team containers - team portal target dropdown reloads after login (was empty pre-auth) - attack log endpoint + A/D submit (attacker vs target) verified e2e
40 lines
997 B
Docker
40 lines
997 B
Docker
# Dockerfile
|
|
FROM ubuntu:24.04
|
|
|
|
# Build-time args
|
|
ARG PASSWORD=root
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
WORKDIR /home/ctfuser/chall
|
|
|
|
# Allow apt on hosts whose clock is past GPG key expiry (2026+)
|
|
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
|
|
|
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && \
|
|
apt-get -y --allow-unauthenticated install --no-install-recommends \
|
|
make \
|
|
g++ \
|
|
socat \
|
|
build-essential \
|
|
openssh-server \
|
|
bash \
|
|
nano \
|
|
vim \
|
|
curl \
|
|
wget \
|
|
netcat-openbsd \
|
|
git \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser && echo "ctfuser:${PASSWORD}" | chpasswd
|
|
|
|
RUN mkdir -p /var/run/sshd
|
|
|
|
COPY chall/ /home/ctfuser/chall
|
|
COPY ./entrypoint.sh /entrypoint.sh
|
|
|
|
RUN chmod +x /entrypoint.sh /home/ctfuser/chall/run.sh && \
|
|
chown -R ctfuser:ctfuser /home/ctfuser/chall && chmod -R 755 /home/ctfuser/chall
|
|
|
|
EXPOSE 9000 22
|
|
CMD ["/entrypoint.sh"]
|