Files
attack-defense-platform/services/cdn
root 029b0f809a tools in all containers + apt GPG fix for 2026 clock + target dropdown fixed
- all 6 Dockerfiles: vim curl wget netcat git python3-pip now installed
- apt-insecure.conf (AllowInsecureRepositories) copied into images so
  participants can apt-get install despite expired Ubuntu/Debian GPG keys
- warmup base ubuntu:20.04 (EOL, GPG expired) -> ubuntu:24.04
- installed vim+git live into all 18 running team containers
- team portal target dropdown reloads after login (was empty pre-auth)
- attack log endpoint + A/D submit (attacker vs target) verified e2e
2026-09-23 18:54:03 +08:00
..
2025-10-26 15:09:49 +07:00
2025-10-26 00:58:49 +07:00
2025-10-26 15:09:49 +07:00
2025-10-11 13:17:56 +07:00
2025-10-11 13:08:07 +07:00

CDN

db used: sqlite flag.txt: GEMASTIK{random sha256 generated on app start}

feature:

[authentication required with login and register, register default as "user" role]

  1. upload image

Vulns

vuln1: SSTI on image Date Created metadata, exiftool cant insert this, need to write the image's blob

example:

(base) jons@01-20-jonathanmarbun:/mnt/c/1Jonathan/CTFS/gawe/gms25/web2/exploit$ exiftool -overwrite_original -IPTC:DateCreated="{{7*7}}" image.png
Warning: Invalid date format (use YYYY:mm:dd) in IPTC:DateCreated (ValueConvInv)
Nothing to do.

payload to inject: {{lipsum.__builtins__['open']('flag.txt').read()}}

when editing the Date Created metadata manually, somehow it has limit of 46 char (but we can expand that to make it more by deleting the content of another metadata) -> check ssti.png it probably have different behavior on another image file or format payload: check exploit/exp3.py

vuln2:

Patching Rule?

  • dont remove flag.txt/changes its content
  • ensure image metadata generation still available
  • ensure exiftool still used