Files
attack-defense-platform/receiver/challenges/xvii/checkers.py
T
MythEclipse d4c741926d fix: make challenge toggle actually work end-to-end (5 root-cause bugs)
Found by testing a real enable/disable cycle (art, fjb, gift-card):

1. compose_gen always swapped build->image, so a never-built challenge
   produced 'pull access denied for services-<name>'. Now it only reuses
   the image when it exists locally, otherwise keeps build: so
   'docker compose up --build' builds it.
2. Canonical templates use 'build: context: .' (written for the shared
   services/ tree). In the per-team compose that resolves to the team dir
   which has no Dockerfile -> 'failed to read dockerfile'. The renderer
   now rewrites the main service's context to ./<name>.
3. Teams created before the XVI/XVII import had no xvi/xvii subpackages
   under their local challenges/ dir, so the regenerated receiver main.py
   crash-looped on import. gen_receiver_main now mirrors ALL shared
   checkers (native + xvi + xvii) into every team receiver on each sync.
4. systemd Environment= keys can't contain hyphens, so
   CHALLENGE_PORT_GIFT-CARD was silently dropped. Keys are now
   normalized to underscores on both the writer and reader side.
5. Several checkers called 'docker exec' with no timeout; against a
   container with accumulated chall.py zombies that blocks forever and
   stalls the whole SLA loop. Added mandatory timeouts (Phew, Sheesh,
   Carbeat, Poke, Warmup).

Also: enabling a challenge now copies its source tree into each team's
services/ dir (team dirs only held challenges enabled at create_team
time), and the XVII checkers were rewritten to be protocol-aware
(gift-card/gift-voucher are socat TCP, not HTTP) with strict timeouts.
2026-09-25 15:36:09 +08:00

183 lines
5.3 KiB
Python

"""SLA checkers for GEMASTIK XVII challenges (imported from
github.com/vidner/gemastik-xvii-final — no upstream receiver was provided).
Each checker validates liveness (+ flag presence where the flag is a file) with
STRICT timeouts so a wedged service can never hang the receiver's check loop.
Protocol classes:
- WEB : HTTP GET on the challenge port
- TCP : socat/xinetd line service — connect and expect a prompt/banner
- WEB+FLAG: WEB plus the flag must be mounted inside the container
Env-var convention: systemd Environment= keys are normalized to underscores
(CHALLENGE_PORT_GIFT_CARD for the challenge "gift-card"), so the lookup helper
does the same normalization.
"""
import os
import socket
import subprocess
import requests
from .Challenge import Challenge
def _key(name: str) -> str:
return name.upper().replace("-", "_")
def _container(challenge: str) -> str:
return os.environ.get(
f"CHALLENGE_CONTAINER_{_key(challenge)}", f"{challenge}_container"
)
def _docker_exec(container: str, *args, timeout: int = 10):
try:
return subprocess.run(["docker", "exec", container, *args],
capture_output=True, text=True, timeout=timeout)
except Exception:
return None
def _flag_in_container(container: str, path: str = "/flag.txt") -> bool:
r = _docker_exec(container, "sh", "-c", f"test -s {path} && echo FLAG_OK || echo MISSING")
return bool(r and "FLAG_OK" in (r.stdout or ""))
def _web_alive(port: int, timeout: float = 5.0) -> bool:
"""Any HTTP response (even 4xx/5xx) proves the listener is up."""
try:
r = requests.get(f"http://127.0.0.1:{port}/", timeout=timeout, allow_redirects=False)
return r.status_code < 600
except requests.exceptions.RequestException:
return False
except Exception:
return False
def _tcp_alive(port: int, timeout: float = 5.0, send: bytes = None) -> bool:
"""Connect to a line service and read a prompt/banner (or survive silence).
Some socat services wait for input before greeting, so a successful connect
with no data is also treated as alive; a refused connection is not.
"""
try:
s = socket.create_connection(("127.0.0.1", port), timeout=timeout)
except Exception:
return False
try:
s.settimeout(timeout)
if send:
s.sendall(send)
try:
data = s.recv(256)
except socket.timeout:
# connected but silent — service is accepting connections
return True
return True if data is not None else True
finally:
try:
s.close()
except Exception:
pass
class AntiAlchemy(Challenge):
flag_location = "flags/anti-alchemy.txt"
history_location = "history/anti-alchemy.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("anti-alchemy"))
class Asmr(Challenge):
flag_location = "flags/asmr.txt"
history_location = "history/asmr.txt"
def check(self):
return _tcp_alive(self.port)
class BitCanvas(Challenge):
flag_location = "flags/bit-canvas.txt"
history_location = "history/bit-canvas.txt"
def check(self):
return _tcp_alive(self.port)
class Fjb(Challenge):
flag_location = "flags/fjb.txt"
history_location = "history/fjb.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("fjb"))
class GiftCard(Challenge):
"""socat TCP line service (python main.py on :5000), NOT http."""
flag_location = "flags/gift-card.txt"
history_location = "history/gift-card.txt"
def check(self):
return _tcp_alive(self.port, send=b"1\n") and _flag_in_container(
_container("gift-card"), "/ctf/gift-card/flag.txt")
class GiftVoucher(Challenge):
"""socat TCP line service, NOT http."""
flag_location = "flags/gift-voucher.txt"
history_location = "history/gift-voucher.txt"
def check(self):
return _tcp_alive(self.port, send=b"1\n") and _flag_in_container(
_container("gift-voucher"), "/ctf/gift-voucher/flag.txt")
class GleamDrive(Challenge):
flag_location = "flags/gleam-drive.txt"
history_location = "history/gleam-drive.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("gleam-drive"))
class GoGreen(Challenge):
flag_location = "flags/go-green.txt"
history_location = "history/go-green.txt"
def check(self):
return _tcp_alive(self.port)
class KodeViewer(Challenge):
flag_location = "flags/kode-viewer.txt"
history_location = "history/kode-viewer.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("kode-viewer"))
class MoreLess(Challenge):
flag_location = "flags/more-less.txt"
history_location = "history/more-less.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("more-less"))
class TempestPoc(Challenge):
flag_location = "flags/tempest-poc.txt"
history_location = "history/tempest-poc.txt"
def check(self):
return _web_alive(self.port) and _flag_in_container(_container("tempest-poc"))
class Ticketer(Challenge):
flag_location = "flags/ticketer.txt"
history_location = "history/ticketer.txt"
def check(self):
return _tcp_alive(self.port)