- all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed - apt-insecure.conf (AllowInsecureRepositories) copied into images so participants can apt-get install despite expired Ubuntu/Debian GPG keys - warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04 - installed vim+git live into all 18 running team containers - team portal target dropdown reloads after login (was empty pre-auth) - attack log endpoint + A/D submit (attacker vs target) verified e2e
Blogpost
db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start}
feature: [authentication required with login and register, register default as "user" role]
- search feature
- create, edit, visit post form that can upload images (png, jpg/jpeg, bmp) query the image metadata taken with exiftool to the sqlite database
- profile (if the account type is admin, render the content of flag.txt)
vuln1: Command injection on exiftool (payload: exp1.py) vuln2: SQLi on image metadata to enable altering user account into admin account (payload: sqli.png, exp2.py)
patching rules?: