- all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed - apt-insecure.conf (AllowInsecureRepositories) copied into images so participants can apt-get install despite expired Ubuntu/Debian GPG keys - warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04 - installed vim+git live into all 18 running team containers - team portal target dropdown reloads after login (was empty pre-auth) - attack log endpoint + A/D submit (attacker vs target) verified e2e
46 lines
1.2 KiB
Docker
46 lines
1.2 KiB
Docker
FROM python:3.12-slim
|
|
|
|
ARG PASSWORD=root
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
ENV HOME=/home/ctfuser
|
|
WORKDIR /home/ctfuser/chall
|
|
|
|
# Allow apt on hosts whose clock is past GPG key expiry (2026+)
|
|
COPY apt-insecure.conf /etc/apt/apt.conf.d/99gemastik-insecure
|
|
|
|
RUN apt-get -o Acquire::AllowInsecureRepositories=true update && apt-get -y --allow-unauthenticated install --no-install-recommends \
|
|
openssh-server \
|
|
build-essential \
|
|
libffi-dev \
|
|
libssl-dev \
|
|
python3-dev \
|
|
socat \
|
|
vim \
|
|
curl \
|
|
wget \
|
|
netcat-openbsd \
|
|
git \
|
|
bash \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN useradd -m -d /home/ctfuser -s /bin/bash ctfuser && \
|
|
echo "ctfuser:${PASSWORD}" | chpasswd
|
|
|
|
RUN mkdir -p /var/run/sshd
|
|
|
|
COPY requirements.txt /tmp/requirements.txt
|
|
RUN pip install --no-cache-dir -r /tmp/requirements.txt
|
|
|
|
COPY ./src /home/ctfuser/chall/src
|
|
COPY ./start.sh /start.sh
|
|
RUN chmod +x /start.sh /home/ctfuser/chall/src/run.sh
|
|
|
|
RUN chown -R root:root /home/ctfuser/chall && \
|
|
chmod -R 555 /home/ctfuser/chall && \
|
|
chown ctfuser:ctfuser /home/ctfuser/chall/src/Pailier.py && \
|
|
chmod 755 /home/ctfuser/chall/src/Pailier.py
|
|
|
|
EXPOSE 8000 22
|
|
CMD ["/start.sh"]
|
|
|