nyupcs / pcs-sp21-lab6-server

0 stars 0 forks source link

exploit-main #41

Open EAirPeter opened 3 years ago

EAirPeter commented 3 years ago

-----BEGIN PGP MESSAGE-----

hQIMA7KtScPIyW/lARAAjqq0QhUuKi7741R42EBHKMPsb71J7zS4uj0C1PQ4PAZN 3Yma4o0Vsk2RlLDNiddqDyfmEA/Q8O92PaBqbg+gAW78o9BPDOJXSt5omzUTGs9j J9tyf2i2HuZWczcm5YxMsBsLxcShLP02JSUT8xUnBq4uQ8V/rl0eX4rek4ee5ZTQ QRpBwljGmOxfLmoJz6Y9svMJKi89QVFE9X1iGCSdV+mRRbGRWl+XJAMqPo8eLYm6 8IM3yptxj1FyOgvWXKss+xP8v2Ln4v/IHMwgqZqYn84ubi7f/SCWYib2UKL26AIZ W9QZk7R6+0F8a+3ObTHuY/AD55RGphF+u9jsxruBUwA0SSJ7Rp+MRgBMvB0L2al/ wGYu/cwHHsL2FTxm/dC6k7dQPP2m3QSng2kWd1hDSuoFfupC8mqdDDWM2pjMRzGN kDC1wDlUfAHFd+ftIyLztIlzBlX2xgnn0KFij/kf/SEneMit0OFBy+BRicE9yXIp 16uDQA/PZxWHAkgbXos2JRSf5b+5xWOhoxojNhVBdJ7dNvEYviuUuikllqD3lgzl 9BwxQEE1meGAH/4WPIRjDQJgvQQ6JMO5DtriPhqBdd7U4HEj9Ddqu6xulw/Eehfp Qy1fZA30iGacgAxDrc64tNRUKCHNT6HCcTZYUffkv1Yfiny7S6Uuo4Ev2dU28FzS 6gF+1Pjb60BrShu3F6h+vJjWxmMnWq9WdHc3V7UdOmRhJpLohDlz3uLe/wZ6SAij a54GS0vIqyHZc0orHvuFJGjlkOiSdqDlN7k310NNGIIJk7uv8nZ/Wx+hWzYPQqCT NDhNuLzMGIQagQegs1eV3k8WGXOtTewIsDAxDT6UXlgy8kNfij4AVaz2SQOJaOZh jjnZpUgLatyAlNlc+Flf5gISJU/p6IX81Z3qkFdEhY5Vk9oYDLHOSeMHX65oUdp7 F05CcblbILtYm+BhtRsftEQvNzdXtLwfg9/owx9HZHoy+lse/c2GW1MOFzqzPDAN 8E04FEJZOC+3dsHfYCiQYflW2yJQ5KUY2thRXyFIwcidxcmVuAeu+5mAJYijdNzg jLNRSWbYjj9uY+cAPiJLxCrIftm1z0e+VmSxdAgE71faKj/MW9jeV4R4+cbVQRDj DMvnpRdzXN9jUD9sOPA+xtV70EHMMjAy2+5N1HLX6cRPwXvBxEdauUkbo09dPzbJ mJIT4ucyJh6K12eZ+I05KZscrxWmKYM0+5p/qE85Y06eLBYu8v2qm/zlk3akxZuu xCPMbLRWjytr5qcF3De/5xmrjToKDMvqxsP3bnOd1NNf2WDsizwtnZ9AlFV3Ut1/ h38QlHKFXWsXyChfuOfsfIlAccU9tkTHKvjRaPfhvqy3mB7gl1cpFmyvgQpWC4Jq bFva8timH/osmicLwL/03czFzAvQ2axAmQNiycXQRj7dcAi91ks710qzd9M1+OGD Iin0rIL/WUiNzcPjeiNnCTKdJ9y9rtVWaRm77wz3ZaVC5cmszAqfTFmzWtjYGTBQ uu2Bj7g0yJPOYK6HzFu6RdvdoNN3sHOeMLMnfuUzkDIbpvoa/+OaCXqA2EAFxlSM 7iLZ4mrOCvoO1Zo5fEe0xZOCDO+h5Kj1A9zdt5Kgg5+ARZg92Y2zF1xW2YxYphiL T5Ohf5z/h4dNjFltqwh+yRVZ0fpEj3zEUIldTOJhsCNYVvt45bI5bN9N1AIoTlr+ rp3JvuiS6NLmYDJh/81j1uuO8rhA44g6Crqqu4lG0GxilHF3/n0m/+zgAQ4M8xbT 1LWf3lwDNWgneONelxycPh/GS7EYRRAArzGxJziZJO1nV51KSjV6pZhnyyPQlsGi SoMjFqqmNd3kitW/ffr1WqXuUEshKapKHR2FKdXjy+3JdMbK17pN6RdKo8reiPkU sI2q/bPnwhXM5J91+fx4PYvOLtwKTMmNnQABU00lubQpMEB/WJ5woT12U0LDFWuE xeIXa1SdjCe/tVUI7L9OiL9gP3BvexKo4dj3BWkbpQ56qKsJykS3b+LnhAaEdvO6 YnYeBQU4Irw7mWY6SXIWIGHpSIps9Aq6JCpnH5j0RMScEwxX4PC8bT7GCmujkVZV 4z2jS8WMsWrASSezES9pQJLy+9LfLNoKnls2GXFNBvFRARfXslg3jqNoew0kkX7X nPHskhQ60A7FR8dx4SZTM3jgPsJAfA1wFJsggmXUkksyPaET2235SP4UKydkhrU+ RLfWBfN3x2HLjmvRfr9+25GSQWwYEjcNuzWZdgwjeu70WwTrg2MH+JAAcMO61+Qx lP3lYMkonPFXyI93iRG4FZTBLPGpH77CIZ0VRTAsscSEfwBFX3kvAqU9PIMV7++r 8+KLT7fKBLtAtH++Yu2BIWR3aXlrKOFdi2eMC+5L9ArFZQo8T6o3c/8nK4kLC8kB eXH85P7TnbcxbyKCs7ghzR4dnx3bwLEQ/1PctUW7+lsTjBN1qzilgXeNrOMwgxbz ZQeZFaq/kwR3+13ePmjjUpucB/3Q0pIpWcZQX9cw7rSvN3y6nUWG2wyBc1t0gG8T FZmPL/x5dl272rpL3R6cZ7w4+FmgaP76juOIRB9d1CbFNk9QmFHDQzhhjOT/9A8d eTmDLngDlPZSdl+nbgm+BkBUgc9Dy4/HHhOH3HJwFu3AIE7Qn7xo8/Ip4yfIsAQz 09HNifKAfFHs40dXabl+XdrUwPxXFz4QTYUgn9gNXfJY8BJSo+IikJXPArcZ3sd1 edGALVERF8SYJkkPd/hgAA501XUmQyoiXWw8MLsCX+WI39RG6JTJ+vQk8l+2lrcM 189eIDDfU+D5YxukUm4atmQI40f/grSQ1G9EeMEbwf2StF8C7z85vfPc8HjT5Lyp Vn+Yty6ywuLyhRleybLnxW833N25DFqPYHYBOTgYim35u3o= =u8sc -----END PGP MESSAGE-----

EAirPeter commented 3 years ago

My NetID is zl2972,Zhen Li, and my pub key id is A319D9972D9D956A

EAirPeter commented 3 years ago

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBF5pSXwBEADjoAfFmkL7F8pnkHM6lbQjJByIonMJYOnABrXalzm19Fc3KRVD Qi1v4DGt28nn/hmxqNPDrIu6IOKuIbjbEO2Q0IqwnM4kUmlIH4h4xWErt3E9XZPQ ZzsrZM0nfCHT6cD8UMyg83QuUR65TpNPIr+kzebp4oU7Bcax73NoOETIzI727aju Yi/0KRxqTbNLIJLSDOrT51/SYb0vP2uw3Q4d4SWaW0CWdxmYy/dGq0uHZccsF+a0 Z7hZmn+8TqDerjbt2Vv+71t8V14GcygFRracVCuSAuwsqJNS90XhJn/ren44furH Qq1e0lCrcH5gQh4WKsBpgscZow4wiPf0HvleJPGaHyh+1dpoIziGrPmtGMVEhhgq WXhTkNP4oJNd8o0f52jvItEQzI7vmC2HR9hdhSond3YG6uhNg3IFeHswtl4s/96C ZfWEmf9XbqNAEgip53Aoq0DESaQ7VymoKbh+BWMB5UfFQ6MgeNQAEIILsMqEFaxF BlW5HX/f4SbzLTldKllSryn/O8Gq8whAwzyb12mZsgqAmYM4tJ0dx39oOEPm+kzH E9f7x6Od6LF3JxOotd2qwxKaVsprRgqE7+YCmNE4vywpk8G0CnELlZNGfMoR8nb2 nznr2uyWys1FPchZLwfvd7N0eRCwQk8fCibuoIhCI1I1FLf7G2jMTtO8kQARAQAB tD9FQWlyUGV0ZXIgKEZvciBHaXRodWIsIE1BUjExMjAyMCkgPFZpb2xldENyZXN0 ZmFsbEBob3RtYWlsLmNvbT6JAk4EEwEIADgWIQSGMZJWaheCnxTI/GyjGdmXLZ2V agUCXmlJfAIbAwULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRCjGdmXLZ2VaiHU D/0fnhuz3YIGrmfRAow664+gYuNs55dsAJ68w3f1lgmtbOjhty6H4YMN2ofcTa7Z oXiyn+b3oK2pyOBWs0dq9Hubc52L21Dn59qs/ZYNpYcYX7diE9UqjQrDJ72OyE7b SPO84+jG8BldJ6k2oG6HUyizVadLWyDF4O4EeIrsPLRzcoyZLtMC3GQEvsw5g8ol aDFrMhj5UavKWAkIPCEo+OFBszvwOr3h+y1tqq3R8FNK2QAljkcWg6iHV1rkeCS6 Lvf4mjp2HHeeWLdBqYZMhWujp7XSuTqzPDvvgJalN+M3y8VFOJU4zrxvMrYxu8sP G901t3YZchKfGkGH8hkh6YvugFIlbrvhM8Xm5WNeUSc/friDuOF+Ud6AI/+9OsZr MfMGkzB19cvk2FuyGOjsYXB4LxBwurmlxiprAI/F6OSAvSGVAnmwxro/QK4EXjic xIeK5uyRJCxJ8fLhVz8UYkJ7dCrit7Gop5KD7V0qjl/+sqaJYGy6nI0Af7VBA9+Y xWqqB9KfxmO9nfB8OCbABpShKDWrGM06/Iz2IaTXBUUsS023hCr8o62rpys1OHN6 fU+EMP6PamFKmGWTEDyfSeiFUIkF88Y9d7oCcu37Uf7UsXGdkEQSy1h2hu/tnE8D xc8KkjmyCJCyEi3+nTD1K3+DfH9rFnvTGSIWdUwg79e597kCDQReaUl8ARAAtp3G r1yrfzqHCoaqFkClnP/9lvjznCXsYT67820JFdzpfJEm0qwzA0m9hOxQKPaSmm5n RKE42sj81tPKdb1DRRMRscJo8lm4MFi/NhmHx3Eq6sEX3vibeuYf1yITXc4WlRkS K7rBuju7E8sUvRN62uq94SgrXc0pUaPRor2YXfDiVzni+XUMT1kEfCtDfLoX959R NGzytT3LE+z2j7+Q2BdH84jC/ccZ0ctA4KARZZR7ZYCnmh7zXDz9d6DWPAdZQ0vw 9Mbe8297dSgXdXsxBxJF5UjXEv5dkK8k5HSodVhGwCDk4JSXSpmX2SMALjSCrCLI /DK5GiAzAZ4VEGKxN+DsD2JUsvpdR7NFemnorOGaAx7ez5/OfbrDYfxdFM+ZvhQE TSG/elfA4nWf5Fy47exizXZLZLBN8/fa1GAnnEmPYo5clxQN5my3Q5bzwY2HYCUv 54cGHqkDw7HkWGBC3E4ecUQkSf+CPu2GJLkDV0zYtc8eGAD9/7rBjmrPcZ+v5TvN mX3RDg7famJUf1rWBXAiqJTYX0D5q0tCoa1sGFIi07If8ddkQmJUkbDKmFInwaUo brPGA1ibjO8fOS6V5qkszD5vLk4op6se5Auu8SuXR5smii5fll5uPfJWgx8S3G1j lzRI/7s4GgpTSHZIeM3qDKh6sE2FvZVO3yA95LUAEQEAAYkCNgQYAQgAIBYhBIYx klZqF4KfFMj8bKMZ2ZctnZVqBQJeaUl8AhsMAAoJEKMZ2ZctnZVqqm8P/0tUXUhq 1IH/6Wf3aOcTicXjNq4TszsUX2ZeybjNVooDxM+7CMNqalXVYofOwTWXlDrqWoMm 02FKCQ1m/KicHTAT5N4cuewawebgQePbrI/IAM2C/CFQISzPU1MJ2QkXjckBWdrJ ckebogUK73fD+LAWzeXspOyyqHDGJXR91PoY6/g721/2jSzvAfC1AkejHVSV3Vgr CD6KwpfEJ/aWBQs5IAXw4GNO/KLIBvj+SggsjCuF1Cm3HaNvAkvSTLBQ/pT7YfGi 1pOE9zjMu79ZigwwoQ+W6pS8l/UcOuAu9L4th0YFqaeT/WDclTxz9R9AfFjPrVFG aqQp9zysRlv4441uZ0MdxIeAFiRDxevDghK3M4b/ra9nJAla2fk0ij/iuM+f9ICm SxzQtNnpdEt8YSKBIJLIoqIPodyyY71J62A8rdXwOcpmfe9cyJYUjpthwEyPePQE 1DN2UUgUMjJ9o7RIUZjja8jrFM5DF5XIh1q3ySSZ/n77jVaupm8ny2kUhkb0J/co +buE5JlBigCple5hZHrDY6j2uDvlaQ+2sSh6v7uuo03YpmVrUF0Epjv5or6D8YU5 c7J5LQN4tDIJl7/BdwvGzTcU+v3mTkL5cA1KRScNlRcty8byMjQsN4HPKdXCHx/p 0QXdXkFU4HN9OWwsm5nA5UomuZIsOuow3Qef =X6zy -----END PGP PUBLIC KEY BLOCK-----

ksmaybe commented 3 years ago
About exploit-main (exploit-service branch)
[*] Starting service from pcs-sp21-lab6-server (branch '0ff895975bf20c1233991128be75afbddf7b0049')
[*] Failed to start service
#1 [internal] load build definition from Dockerfile
#1 sha256:f25f382abb226db6067fda47b6d9f869300f4e21f8478a23072080bd436d61c7
#1 transferring dockerfile: 303B done
#1 DONE 0.0s

#2 [internal] load .dockerignore
#2 sha256:4a433003949125f9db0fefb7781b0643559dd80b3468f7e6e397957ec887859b
#2 transferring context: 2B done
#2 DONE 0.0s

#3 [internal] load metadata for docker.io/selenium/standalone-chrome:89.0
#3 sha256:beb2bf66ef313fd2e3aace2d303a1c73abc80369b025ce6bfeb4a2cc5920b54e
#3 DONE 0.2s

#11 [1/7] FROM docker.io/selenium/standalone-chrome:89.0@sha256:beb559d9a8fddb3cc154122598a527c6fb00f19751577974013924a209431f91
#11 sha256:cfa7f2d3a3cae72a7b4a2fd6d9e3fe6bf7d6c6a4462d83f9fadb5866bd1543d1
#11 DONE 0.0s

#5 [internal] load build context
#5 sha256:19efa66fc437715a31a2f510ae25610fa4b9ba135a11d4b84ffd4b61ea4a2255
#5 transferring context: 99.32kB 0.0s done
#5 DONE 0.0s

#4 [2/7] RUN apt-get update && apt-get install -y python3 python3-pip
#4 sha256:1f82db4cdd0345e13bbf91421a58803f0de60b2a8230a42c43c8a09334118de0
#4 CACHED

#6 [3/7] COPY . /app
#6 sha256:356000a17b2c4aeba7851bf577816dc8d93079fd196515e1c579c776fd74650b
#6 DONE 0.0s

#7 [4/7] WORKDIR /app
#7 sha256:e7a66f6372ab7c446ff0901cfe3677efc65a63254424538b484f20b6751548b9
#7 DONE 0.0s

#8 [5/7] RUN mkdir -p /var/ctf
#8 sha256:2bcc6165e50cfbc8f0bc76e24b1d16f5661e9d4c1fc42befa7d07e6cd45b296e
#8 DONE 0.3s

#9 [6/7] COPY flag /var/ctf/
#9 sha256:93f8f6035599125d0b8bebf85e9c2d1224b4301f3f9c0fe0b7949aada2908a6b
#9 DONE 0.0s

#10 [7/7] RUN pip3 install -r requirements.txt
#10 sha256:6e5ac8f805bf0b335434afdbbc12790cb4e7e3acf01d1166841811e494b94ab9
#10 0.992 WARNING: The directory '/home/seluser/.cache/pip' or its parent directory is not owned or is not writable by the current user. The cache has been disabled. Check the permissions and owner of that directory. If executing pip with sudo, you may want sudo's -H flag.
#10 1.130 Collecting click==7.1.2
#10 1.172   Downloading click-7.1.2-py2.py3-none-any.whl (82 kB)
#10 1.232 Collecting Flask==1.1.2
#10 1.244   Downloading Flask-1.1.2-py2.py3-none-any.whl (94 kB)
#10 1.302 Collecting itsdangerous==1.1.0
#10 1.311   Downloading itsdangerous-1.1.0-py2.py3-none-any.whl (16 kB)
#10 1.366 Collecting Jinja2==2.11.3
#10 1.378   Downloading Jinja2-2.11.3-py2.py3-none-any.whl (125 kB)
#10 1.461 Collecting MarkupSafe==1.1.1
#10 1.470   Downloading MarkupSafe-1.1.1-cp38-cp38-manylinux2010_x86_64.whl (32 kB)
#10 1.542 Collecting selenium==3.141.0
#10 1.553   Downloading selenium-3.141.0-py2.py3-none-any.whl (904 kB)
#10 1.686 Collecting urllib3==1.26.3
#10 1.696   Downloading urllib3-1.26.3-py2.py3-none-any.whl (137 kB)
#10 1.772 Collecting Werkzeug==1.0.1
#10 1.781   Downloading Werkzeug-1.0.1-py2.py3-none-any.whl (298 kB)
#10 1.857 Installing collected packages: click, Werkzeug, MarkupSafe, Jinja2, itsdangerous, Flask, urllib3, selenium
#10 2.331 Successfully installed Flask-1.1.2 Jinja2-2.11.3 MarkupSafe-1.1.1 Werkzeug-1.0.1 click-7.1.2 itsdangerous-1.1.0 selenium-3.141.0 urllib3-1.26.3
#10 DONE 2.4s

#12 exporting to image
#12 sha256:e8c613e07b0b7ff33893b694f7759a10d42e180f2b4dc349fb57dc6b71dcab00
#12 exporting layers 0.1s done
#12 writing image sha256:ba12ef6b31efde6ff5c1c6b474de44e8aa9dafcd746074ffd7dd2c2df811eaa3
#12 writing image sha256:ba12ef6b31efde6ff5c1c6b474de44e8aa9dafcd746074ffd7dd2c2df811eaa3 done
#12 naming to docker.io/library/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049 done
#12 DONE 0.1s
docker: Error response from daemon: Conflict. The container name "/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049" is already in use by container "8091eae6427042a587827ed4ffe9bb129700b81cd8917e1bf7ccecbbe79645d5". You have to remove (or rename) that container to be able to reuse that name.
See 'docker run --help'.

==========================

[*] The exploit did not work.

ksmaybe commented 3 years ago

This submission has been verified. Well done!