nyupcs / pcs-sp21-lab6-server

0 stars 0 forks source link

exploit-main #38

Open kylesyx opened 3 years ago

kylesyx commented 3 years ago

-----BEGIN PGP MESSAGE-----

hQIMA7KtScPIyW/lAQ/+KularQ0PtDRKWPL0EipK2TVb+y3FBHvQCtzU0XX7701L vxa7ilMNjlQfk2/keBYG9vflnSOpD3sg4JFDWuMZh7x/swuK0ABlmGUx9tU61ZXu Oa6Q5kmXsf6eYTVs4fTrRDZCblUVnhOo5YijQz0NOrF2gYq9wjZ846jKHDSHpV9o ZVEL1o//AM9Rl8pBWX46q2IaTGSCjmvfLWAYHXjFsVDGgF7x6N3wE17ojNG7MmI6 UsL09rm64KI+QOkUz+tciYxhRtoQmnBekKchf6eNqy/ncLWIfffut0m32CBpnnw6 +UMgNlbMvvlrdQPBEUyWOnP5q+0Vak+Pn+Vf0SmlpBZA7nMBvkr+aLwLPmoIC6Rt /2/MvrOe78jQkJGp8IBkvOZ8GodOYOcB4Hoka3lK4q7Rre49cVq/v9bMztQiNYYU A3foVUnZ3x9EXCaRxXxw0c6RlAiWuINtgdFdie8ULDCwPHQIYeOxMWQGAY2idDgp KFCeXr9HFuoBmRK8aEqKQWpRR3DZS1dMl7aKh8d2kZMyQoY9EcXuPIKyjoSTFJo8 TUTq/O3uWd9lkHELjFS3cvfSSgerfcPnUjJZWmTJYAa0RfRBhhVlb9BK4P+0090M Qkhr8BjZjie/LHgHSufWk7dei4TmDE/ovM6JhLU86wmBVSyXSG2nI8OEUnTPm27S 6gGhrbsI7uSMzlYyYAUeqqGXGxtNnC2Crz1/vh4wWnRlJadFGMxjQiY0+JiS2orA Llb5nXGgv3cCI2thEDuK0Jufjc0EHGDn8uYHNgNgURP1HCZP2c3glcTVYcqrOKLg Zlj1Z45ea9/sZ+EVrGEfBDQEshdB9a1fZP0jIe0f77F2wp5HK+SQXZlJxvjugy2H 9quArn2ZvgVvHHVpVXMh36+MBcozT2Ut1/vvzuO8H72Sbql78MxtrqOwfj3g+QD1 dl5iDOr6gSRSJ/OczRS0+8XE3QlnWQYHw9mUxD3+00s2jZST60FmJs7QBwduj/9W 0zAyJzd3RWYNQyGSZKfssFWNbhOUg1mKSOcH6LaUwLhGS9WT+OJO5317NQBwgtMP f1UdWnM6oBTfO2pNBriMKbAKTa5GXjZT1wrppR4zW73ytxp4txF3S+eQQDq/KuDH 0sFY6xCci4ajkkNy6jsNlGSdiuBYIXYrusMACMSxPVCP3myXiIl13UQlBttDfQEO +EUyMn8mcAzFCmqcOo+fSpbAyIywDmqtaTCnnYOOuRATuamY598rh5/qyCpnlhV3 grsXjHAlGmoOMkr20+b4PIwEtkj+sjpSI9CdflVI0Xt22aOWpxHI5TC3u2W6rKzN pdbo4xI/XLbNCmRS0s1j8P3Ufp7IQeB9fO6bLt+rpCAVPddHLnsaD6cnIWCE1Kee Lbmt5UIN0IOwTHeakqSH9di0gLiY2V+AN/WtXjlaCbB7l+OJfAzBL+dBKxpgme2r zuxin4wHWAPIpcGKFAldt2/SewNwrzbS09dis4ABvj/FgFLxxyz6FZJ3e04dNnIV gUUVgrws+/vzj9wMtrxpmfAwE7DuABSQkI+1BLtmA3XHV6oHn1JyjAj3ikSCxiMA P14ABsttcITFmL6i7YiKtn5Wfm4PZSpm+ROag6F4OyfZTO7RmtlpW3dlzbuszwdK XbHmL1lrf76CmC6CBA1fq2kgEGWAdK3KyT4C3nPEhgKsx8EyRJE30A7dt0DndNzs af/KuR/63Cv0uIIJviubGtM41ywAUfWg9HTUm1294UDatB2d4E+KFInOVLM08nvz Xt2+PS41opa0yPWf8TLlxjTQ9+HjA+eyJnlqlW6Vm+X7UiPLF9gNpCsyxkUsKOw7 lsUH6VoRqSvhNXKtCp9V8L0OzSVUIepQ7bbE/Sd5fIp2C25G4CPtMo3cc4W10cSO Eru7DGSrynQDfab6U9WFxvr5KfFyTpod3zHQLggjDGafyn1m+RA2QmzLu1xjjnO3 EuGLihWGwFtMt3OSMN3zoY9PNL468lXovrhrTJdqwHiLtTz51d/e26nyF68LEDsg msjB0gvZF0FMCiAuwqjILNbpafQIgH06NTx9oxmihYK407dylkpHZ8aSb8M/pcrL mxAL4sDzhexjiFrRFgeLXKS8nYXTOrM1g+akqpF8Hh3wo0nVjJ7i0I7qR+KNMQvD IremKWEb26d6hZemZ5qSCHmwBGn1mFhyfW1Ec6m4Bel5iNBEt14msQpNE5BjnJAg OZvCa0b3/PhNEZGCFlvLBrnawqVN9K9zZwVYx10oJ2K2s0Nx+JDLdLRzNNDcET6J QoNdBMV48M0O2uYNoUWqBia6ipa6mtbfhn7CdkOtop4VGrze6e09nQWCKLG7MaJT /v7cma1UKKeee2D7d1vNEhE3QiYzCUfppZEHws5+SiPm79uCpr/1LbFuFWO/dbHV MwqA8UCgUU4bCQx5kFDwjwRHYJN1nj/9qR9dvRgjxJ3+o4sPQV5tWltypXwOT9lO 3/HR0qVmdhdPUzGGUedW6JytxliirA2YU7TQfHtiZsLLtlRsWtYVTeBwq4Pa3+n2 BQBR3yJM7kd+jwpq740RhWE94xykoCKrwxJVaqMT2MLTmytZPSm5gbYGd2yn15JU ZaXyNcIq14XSB+ODv6fjq9BH6rFzZ/rNWeYmiJqMgN7L3ukTXJE3ejD43f7sjPz9 6YidkDoiaSIZxEOARiSHkYy+8eV9ypR/LQzEUcJjr3jUctoPRRAfuUClihJGBi7p AoUuSu4salBlUoIQBr0oZN+BZH3e22nVabgpVMEP7zBHhEJxQQjsFl1IgVRimxQE kA== =5Hl2 -----END PGP MESSAGE-----

kylesyx commented 3 years ago

My NetID is ys4375,Yuxuan Sun, and my pub key id is B5B5B53B

kylesyx commented 3 years ago

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQGNBGArFgkBDADCKeJf8mb1VagGxynHwJnbvU6LWtHUx8fDygYDhVzRKqyBITt2 WDX90vzLPMQwmN9W0nooZPf23dKy0QH0zVawse3sMRr+3WW2VoXdyMmzVnr4nLFM WncrVFjD4oo7mHcHCM2Xyz/SEkHDZlBn141nslezuc3eHslKQQZTCLA8KW3xBU5u Ll45jTpWedOUhcY4dQPOyGpzxWvuRp3BuxchqXNVeYEyDWyd+R1zbEfFByG3eNoc gEAIyDwjOCnSMhkjFYP8sVNFqdWasB6Ej/5hAKd8ROHzmz3Vh8tVrtOsNHnHrbn6 cBr2uykZHIKd9+e3e1iK77aAJTatgUQsn+j/GFnpCxeiu2i7NvGeDY9bl3pwYGHD K77/W+VOjP389MKKNPVi2bDlE02ah3ARENMNB084/ZlhVW1ULX9ALHh30CgMy9OA ZDRM4xT9P0DbakwDyxFSv5D6vNKRHO7MtbVZNX71SUV0q8vW6+rm1rKDsZxgdufv yMAH5uHUXl9rPhkAEQEAAbQdWXV4dWFuIFN1biA8NTQyMjUxNDg5QHFxLmNvbT6J Ac4EEwEIADgWIQTE83RLidwioEpPUcEGfpextbW1OwUCYCsWCQIbAwULCQgHAgYV CgkICwIEFgIDAQIeAQIXgAAKCRAGfpextbW1O6XVDACfB2jqYtArwH0ccG5aYhbI 5vXaTa6iD+UQtyodmffwC+9kXyXUdBnI+Xe5zUlHk8ovovTPAWsovSptJ5/tfVw5 75KqHlPuCc/MB0HfeyD/pjCanErpRM85yRPARycx4dYNrSlhfUrA183LEJYCsTAX i0Lv1P5BB9F2YKp9fwkZxDqW0QmogLU+ZYWL8Sr8gqKAK1GkHVEAXv61Adk6WBsM q/kKLmLVYLh+TE6BKFmauxXnUyBjVm8ylle0BK+w06FOrJtI6CQ2S2UTFxgKYXCA FoOU6DLmtjpToNgsT25Wg1rsEfEeM4p7Jl1EsMBtAjFDaK0tKxD7pjcNgm2XenPU SpKzKdebFM1YAt36Ki8+7MaQCAVmT9oK0dz9MHIdi1EqPVWuZSdW5f9+r/QWeCO3 1JR66BfLSpLzs2Npm6FY3Gpc1tlqyt9rL+rAK+alf0dDcR9otay3YQaJ3OepLwQa fEXAcCjfn8DIdSD9nBaAzy/3zT03bVAfkTseV16IEGu5AY0EYCsWCQEMAM9MwxUX 5iMVi4tTJaN70Gqt0wlrQE23N6vJr9dEG5knl3F7QNGRDRoU6vIb72+p4/qpdtAo c3F+33QwdJoKvFtfqhxEwuWXVU660Ol9d38bY/NHPpeEtOCSpRPCO9zFRbsJsT4s qNI63fiSJHJ4HZS3K8Ab8FNsDCJgBb6v3mqtBUWHrGfTUFb8ctv6tKg+3gsb8wv7 +DFlks/Ke3SSnNiI5oXtnRSbER3z/MaTZoho2zSIr02a7AaY/Ng9ERoxsYR9bOrd mNJbCoeyZy8kBtlGgODMTU5ozgjtGcX1jPeC9AfSsyn+zTNUdLA70qGrheSmNf2A drbVNtZzQJ/FOdvsOEJex/CEuzrsxjJz6t5WP1LeCwwgEZ117HjARLMZcAgngLZ2 t9wvqlGunEc1GUF45qmWDZ91p/ImBtizAeftOfdTr1+Yy/UIm/fz3nvDUbosnPBU uCk9/whjejqYNL6XEq0Xu1T9GmRnTF9wOnuJ1W/Hsa/ZD+P8t0vsP0jfVQARAQAB iQG2BBgBCAAgFiEExPN0S4ncIqBKT1HBBn6XsbW1tTsFAmArFgkCGwwACgkQBn6X sbW1tTsqCQv/Y3qzPZFUVnIk3+Adyeq6zkCyLJQv473G/8x7F1haIvCK14RaSJGX fpL/xNBDJSEpFIKC5Ae2mNpZ9yvf5i8fobz/afNdkZDyvORko1nMWw2kjCvoCis9 hNuXZ3EsNGV9ir6w6MN8npM6+ajRd14J5lhsxOxPfKwY1W3Q2z7Msz2PHlqpQIAF hlqw241PsVZbkqs6UKOcvSqtimR9Kf2oEaEiYaycsEfQ3dIAeUj2f9K2AQAZVjEp 1gN+PH9+37OtxzSorcBcLd6xRzpjoR9iV9S4KYvhlGXVmxWcw1p+c5lRBIN2cwjc jCCoWCJaKX/MHzegeU9Sk7pYj0BNfYTrX9Ql7rKDLmLr3ukCJOiUZVDAbw0iIy0A daGKNvlpdXJ0ugT22aPdhzmcJY5ACC/5rFaFSYaxH1A3zvVXkafzq3iyx9bf5yFY fNnnXmfTG0tB7zUf/+LwqppblRKAxrbTflWqBGn/jK/btYOrxy3ETNqr1Ckjj/tx D0FTA+M0G91W =pHKF -----END PGP PUBLIC KEY BLOCK-----

ksmaybe commented 3 years ago
About exploit-main (exploit-service branch)
[*] Starting service from pcs-sp21-lab6-server (branch '0ff895975bf20c1233991128be75afbddf7b0049')
[*] Failed to start service
#1 [internal] load build definition from Dockerfile
#1 sha256:eaac83423bdcf4750f575573f11052b71f68d44d845d896c9b46dc80655ec351
#1 transferring dockerfile: 303B done
#1 DONE 0.0s

#2 [internal] load .dockerignore
#2 sha256:d06ffcd14bd5381eac4a65c4ee8457f81090a2d99763fe3299805ce5776701cf
#2 transferring context: 2B done
#2 DONE 0.0s

#3 [internal] load metadata for docker.io/selenium/standalone-chrome:89.0
#3 sha256:beb2bf66ef313fd2e3aace2d303a1c73abc80369b025ce6bfeb4a2cc5920b54e
#3 DONE 0.2s

#4 [1/7] FROM docker.io/selenium/standalone-chrome:89.0@sha256:beb559d9a8fddb3cc154122598a527c6fb00f19751577974013924a209431f91
#4 sha256:cfa7f2d3a3cae72a7b4a2fd6d9e3fe6bf7d6c6a4462d83f9fadb5866bd1543d1
#4 DONE 0.0s

#6 [internal] load build context
#6 sha256:d608b7a7505a367f0e2015ccf34a75f61441785c62549e84733528a6250fc721
#6 transferring context: 99.32kB 0.0s done
#6 DONE 0.0s

#5 [2/7] RUN apt-get update && apt-get install -y python3 python3-pip
#5 sha256:1f82db4cdd0345e13bbf91421a58803f0de60b2a8230a42c43c8a09334118de0
#5 CACHED

#7 [3/7] COPY . /app
#7 sha256:bb6231210a587489724cd7b136fefa56713c9fb463b791bcbe139d5ccafbaf0d
#7 DONE 0.0s

#8 [4/7] WORKDIR /app
#8 sha256:b2266befce51d70931d7f599b1130ba2b303350b70691111b8fa5e3bfc972769
#8 DONE 0.0s

#9 [5/7] RUN mkdir -p /var/ctf
#9 sha256:9aaa3b4a04878bd2c797764456bb7227fb48aa78bf65148d8c493cf2c75b7e8d
#9 DONE 0.3s

#10 [6/7] COPY flag /var/ctf/
#10 sha256:b9acc361ca77074da87b80db5bba3dd000b18ad16bd7c609dbc14c76aaa4ad9c
#10 DONE 0.0s

#11 [7/7] RUN pip3 install -r requirements.txt
#11 sha256:7c9c1d87946467299e0d364a0ab22a8ce0142a81cfd9631af36abf95c654bb26
#11 0.982 WARNING: The directory '/home/seluser/.cache/pip' or its parent directory is not owned or is not writable by the current user. The cache has been disabled. Check the permissions and owner of that directory. If executing pip with sudo, you may want sudo's -H flag.
#11 1.147 Collecting click==7.1.2
#11 1.191   Downloading click-7.1.2-py2.py3-none-any.whl (82 kB)
#11 1.376 Collecting Flask==1.1.2
#11 1.384   Downloading Flask-1.1.2-py2.py3-none-any.whl (94 kB)
#11 1.682 Collecting itsdangerous==1.1.0
#11 1.689   Downloading itsdangerous-1.1.0-py2.py3-none-any.whl (16 kB)
#11 1.873 Collecting Jinja2==2.11.3
#11 1.880   Downloading Jinja2-2.11.3-py2.py3-none-any.whl (125 kB)
#11 2.231 Collecting MarkupSafe==1.1.1
#11 2.238   Downloading MarkupSafe-1.1.1-cp38-cp38-manylinux2010_x86_64.whl (32 kB)
#11 2.463 Collecting selenium==3.141.0
#11 2.569   Downloading selenium-3.141.0-py2.py3-none-any.whl (904 kB)
#11 2.788 Collecting urllib3==1.26.3
#11 2.925   Downloading urllib3-1.26.3-py2.py3-none-any.whl (137 kB)
#11 3.121 Collecting Werkzeug==1.0.1
#11 3.263   Downloading Werkzeug-1.0.1-py2.py3-none-any.whl (298 kB)
#11 3.328 Installing collected packages: click, Werkzeug, itsdangerous, MarkupSafe, Jinja2, Flask, urllib3, selenium
#11 3.805 Successfully installed Flask-1.1.2 Jinja2-2.11.3 MarkupSafe-1.1.1 Werkzeug-1.0.1 click-7.1.2 itsdangerous-1.1.0 selenium-3.141.0 urllib3-1.26.3
#11 DONE 3.9s

#12 exporting to image
#12 sha256:e8c613e07b0b7ff33893b694f7759a10d42e180f2b4dc349fb57dc6b71dcab00
#12 exporting layers 0.1s done
#12 writing image sha256:ae18df41a59ca6af7f436e084fc0a2971b14c46b9b219448c4b30dcdf031afbc done
#12 naming to docker.io/library/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049 done
#12 DONE 0.1s
docker: Error response from daemon: Conflict. The container name "/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049" is already in use by container "8091eae6427042a587827ed4ffe9bb129700b81cd8917e1bf7ccecbbe79645d5". You have to remove (or rename) that container to be able to reuse that name.
See 'docker run --help'.

==========================

[*] The exploit did not work.

ksmaybe commented 3 years ago

This submission has been verified. Well done!