74 lines
2.3 KiB
Markdown
74 lines
2.3 KiB
Markdown
# File Viewer Challenge
|
|
|
|
## Description
|
|
A simple web challenge featuring a Local File Inclusion (LFI) vulnerability. Players need to exploit the file viewer functionality to read the flag located at `/flag.txt`.
|
|
|
|
## Challenge Overview
|
|
- Simple file viewer web application
|
|
- Players can view sample files through the `/view` endpoint
|
|
- The file parameter is vulnerable to path traversal
|
|
- The flag is located at `/flag.txt`
|
|
- **No flag validation** - players must exploit the vulnerability to read the flag
|
|
|
|
## Endpoints
|
|
- `/` - Main page with file viewer interface
|
|
- `/view?file=<filename>` - View files (vulnerable to LFI)
|
|
|
|
## Files Structure
|
|
- `/opt/challenge` - The compiled Go binary
|
|
- `/opt/index.html` - HTML template
|
|
- `/opt/main.go` - Source code (can be modified)
|
|
- `/opt/rebuild.sh` - Script to rebuild the challenge after patching
|
|
- `/opt/files/welcome.txt` - Sample file
|
|
- `/opt/files/info.txt` - Info about the file viewer
|
|
- `/opt/files/hint.txt` - Hint for the challenge
|
|
- `/flag.txt` - The flag file (target, read-only)
|
|
|
|
## Vulnerability
|
|
The `/view` endpoint uses `filepath.Join()` to concatenate the base directory with user input:
|
|
|
|
```go
|
|
filePath := filepath.Join("/opt/files/", filename)
|
|
```
|
|
|
|
This is vulnerable to path traversal attacks. Players can use `../` sequences to escape the `/opt/files/` directory and read arbitrary files on the system.
|
|
|
|
## Solution
|
|
1. Access the file viewer at http://localhost:14000
|
|
2. Notice the `/view?file=welcome.txt` endpoint
|
|
3. Try path traversal: `/view?file=../flag.txt` (won't work - resolves to `/opt/flag.txt`)
|
|
4. Use more `../` sequences: `/view?file=../../flag.txt`
|
|
5. This resolves to `/opt/files/../../flag.txt` = `/flag.txt`
|
|
6. Read the flag
|
|
|
|
## Example Exploit
|
|
```bash
|
|
# Read the flag
|
|
curl http://localhost:14000/view?file=../../flag.txt
|
|
```
|
|
|
|
## Deployment
|
|
```bash
|
|
docker-compose up --build -d
|
|
```
|
|
|
|
## Access
|
|
- Web: http://localhost:14000
|
|
- SSH: ssh ctfuser@localhost -p 14022 (password: warmup123)
|
|
|
|
## Patching the Challenge
|
|
Players can patch the vulnerability by:
|
|
1. SSH into the container
|
|
2. Edit `/opt/main.go` to fix the LFI vulnerability
|
|
3. Run `/opt/rebuild.sh` to rebuild and restart the challenge
|
|
4. Test that the vulnerability is fixed
|
|
|
|
Example fix - add path validation:
|
|
```go
|
|
// Prevent path traversal
|
|
if strings.Contains(filename, "..") {
|
|
http.Error(w, "Invalid file path", http.StatusBadRequest)
|
|
return
|
|
}
|
|
```
|