Files
attack-defense-platform/services/warmup/README.md
T
2025-10-25 04:56:33 +07:00

74 lines
2.3 KiB
Markdown

# File Viewer Challenge
## Description
A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at `/flag.txt`.
## Challenge Overview
- Simple file viewer web application
- Players can view sample files through the `/view` endpoint
- The file parameter is vulnerable to path traversal
- The flag is located at `/flag.txt`
- **No flag validation** - players must exploit the vulnerability to read the flag
## Endpoints
- `/` - Main page with file viewer interface
- `/view?file=<filename>` - View files (vulnerable to LFI)
## Files Structure
- `/opt/challenge` - The compiled Go binary
- `/opt/index.html` - HTML template
- `/opt/main.go` - Source code (can be modified)
- `/opt/rebuild.sh` - Script to rebuild the challenge after patching
- `/opt/files/welcome.txt` - Sample file
- `/opt/files/info.txt` - Info about the file viewer
- `/opt/files/hint.txt` - Hint for the challenge
- `/flag.txt` - The flag file (target, read-only)
## Vulnerability
The `/view` endpoint uses `filepath.Join()` to concatenate the base directory with user input:
```go
filePath := filepath.Join("/opt/files/", filename)
```
This is vulnerable to path traversal attacks. Players can use `../` sequences to escape the `/opt/files/` directory and read arbitrary files on the system.
## Solution
1. Access the file viewer at http://localhost:14000
2. Notice the `/view?file=welcome.txt` endpoint
3. Try path traversal: `/view?file=../flag.txt` (won't work - resolves to `/opt/flag.txt`)
4. Use more `../` sequences: `/view?file=../../flag.txt`
5. This resolves to `/opt/files/../../flag.txt` = `/flag.txt`
6. Read the flag
## Example Exploit
```bash
# Read the flag
curl http://localhost:14000/view?file=../../flag.txt
```
## Deployment
```bash
docker-compose up --build -d
```
## Access
- Web: http://localhost:14000
- SSH: ssh ctfuser@localhost -p 14022 (password: warmup123)
## Patching the Challenge
Players can patch the vulnerability by:
1. SSH into the container
2. Edit `/opt/main.go` to fix the LFI vulnerability
3. Run `/opt/rebuild.sh` to rebuild and restart the challenge
4. Test that the vulnerability is fixed
Example fix - add path validation:
```go
// Prevent path traversal
if strings.Contains(filename, "..") {
http.Error(w, "Invalid file path", http.StatusBadRequest)
return
}
```