nyupcs / pcs-sp21-lab6-server

0 stars 0 forks source link

exploit-main #43

Open aathiramanoj opened 3 years ago

aathiramanoj commented 3 years ago

-----BEGIN PGP MESSAGE-----

hQIMA7KtScPIyW/lAQ//UBlBp+4CS2Qx6re8pC2pT5mq7ccP4WohLKDe4fiPIhdq ZmWEJSfQbKlkX4Qfi8so4tSI6sr1FzT1JB1PvV2bl1fZz7UCzpIEQQR1mm73ju9F H+Fej73lZgx9VevLmsOV7vMUVFXWJGoNLcBGSCEVH4aWbi6VsMuSXjJkupx8u3A2 ne5MPznsb74uA5D13M5u2aEqtH0pJw4ZUorFluz9dT83DaFlDNU93/Gk+yhVsnQy zKAMkARWyw8Xq7vbEBK5AjhJcdTYk3/PZq0S82/k6srOMPjpT+CGKmwpahlAYT9p Jw3NXqp781qSaACOucY/5LHEAz2D7u2P5L1VY0X+DoMhN+vvCOiHUbunbm7nKnXY hg8JAkDIHQasOLK4WC0QrdmuEG2sZm4xrHyzEIHZxmCl5PthYVVFaKbX4u6TUTMd rJb0FjzI/h3nyMuTFh5kOS3PZHjLPKjVdLc1yLGBFgzZFFHrPD9jhOW8GPILp08w hmYFf4tq7+RZXIf9Voc82pF/Qod+kzP+sKHEF6WM5dGEYEq1POnRv8cgHmJLfCxm k+njFAGQNheTXsyMRptUaQ2ous23GBEMbVVoA/4szzUa7CA9Jb77pe6MD+1nChPd HhFkCVrJOEmDwmugGPqf+sHsNFnjmmV4DA2u+hVRFnTH5Pq7Dy8ePaa1f+8UdgrS 6gEJUvoHsW8qYKmyEcxsllNFDBd0jS7/7Jexk+7gjaA2eDa7Zne8QLNSdpjigI+z dDe+t13V7CoyOk1hRQWHwau2OZDssrOfj1YfOQPe23usdzP6jfsf9xoSxennrOcv 2YzUk8pLLhjCSqd5xK7rDIrD7Hdq2upwNJOJ97vddytibq1AOgsXOBseJAe4u6QW T446SHx1bvpjXXNhqKJUanS4Ux/t3tqEgs3f860Z7nZ+vsdt34mqb4ulnnQDTPoG eunZWCkid7lrUYnzq+1O2Mwc+pJIZqv92xHcAMo5zHzy9bIEz0PlvOERNfH3F56l BHJgeuFDMFKqa6VvRkhI3C4oGNFxbQhVkSRPBr2xI6l+9zwOJx5KZ19gBmmye7PV qD4uH7bnI9mcJxs/PIfpUFT+u1D/4DQKKLb5RsyIS5YCMVidGU3RDxiqEDjFRvfI MkZa9HdeocjmzHBxDk/nWnG0SNYn1hXTn6ezes3TQxbZ2wOBienDOYdJ+7vr8qPK m16tibUFtuexNjq9XBJLNe3qtclCO+O99MKaVnH17PdBDkBh4EOfMfq2ryC1u/he WMPmDjC3SYXkerR8GBZ2HnQZLBIw61y9dZSZCK3b6XDVG+ijKudoUT2X+6+y3s5V zad16L3L/YnrS4aMrPv3Wrv+rw2GTuJ+FYUXHCWoz8RMZR/huV23lkSUEHndS3zY AokGbCAXBSYrbH626N0MzBtMRlpIzlzjl1nejcCxdYFNMwu9zGN9bpNz7AvCrz0g 8sxfY18OjKa0gtwDDSV9+6JuAYtKgPw1aokP1RoOgS22/a6DRkp0driIqMh2cJ37 q2WoPubYvOzzmjP23CT6fKFGGbsCUTo8WukM4bbR8wO8hHUr9ANf2uHYrQvU9wY+ amdFZzGAIymTGy7MCtAKEUod/xkOBpG/71H9Ooy5cu9QLhbkOtEsoeXyILHxFYcI CR/Pv0FqNwdPCmbKxtNvbH2YOrKs1glPoPfm/eZ3AEF0TQc6W57Rvs/IY686gVjq Cpp4+tp0JPErlC4m820I0BU3VGzT8lqFDtDDzhfRRBUEIlfRVKmH+G55eW77dwxA uOL791UTYH6c67i05J1AGrmEALGeK87LQnuU5eCvv3wWMWKWvwejcKhLneBzMxQc rHWv5k1hBdqPRmPOaXX3IQ7j0eC1uljm6ubFcxSwzwh7ZAZiN6JMEuPj5QsxqwiU dMqr4fV7jReBganT8mpdbden8NPK63O10e5GJwU1JEYtskxaTAeodN+3hwjnza28 pQAsb3KalE9VmgStIEaHxEE4Rw99urP0NWg+Wo1g6gxqrU4LbcfHYonsUrnyxOif uFCMzirS87UA7p2BVDoBksTpGMxJ6N97fOPiyVVhYnD+j9s4QuZU4unCEmIa5H26 DopLLRp3mTLkRYTOk1HSFfm+6get4DLG16C5AG0FHk+ge6UzO0IagMYUtfYF/HBi QsV50PX69LYD6ibvvnW9JDXWcAN0fVLvh7qvfOpMLIRzJn8HCpcICyXI6Vlu5cni 1dCc0VAepPNf8OT4skHOlQyzaGLWGPnzhlqoxevGya5IQW+yE3NbPXgXs0JUMymG RszW38qOXzLUBDIdru1CUNUcxOu5FF8WL6pdyEcw3FAVi3y5oyVyjPFBdjGVoNMx /yofWoyqfjaD7OOZnwe+ZknlbzptlQvZZ2aJhll1aHimxoIglZbSe5FmNpbARYlF JZfkmyZvDlrzDq972O+RnyUQqM4FvpZgNAjPoAwhDedDH7OuC/sDYiQloB0N/SNX swX8QXapkFHPlDFxzO4+aQwIG17Lk3MM+7DVi3ae8oWpQhoL75+vLHxLMil8wRFS iSgIQ34KPTkZLtW/DKgicGhwEGqU2m0eCI+ym4tjOIJB4oXyR0m47cu2yfismUms nfJa6ZarOwqqgam+XP9vKArRpf0i7wy6lJzoWzoYVRpDT0j1EXNo/ZjWVMNGy1Qo zEHHAgTko7PYVwIUZ/B7L8bHuXlxqjy2L8Lxp3QG0827R7SASdal2FG+OPBLrTbv R6hP4QcXq89Yv7IEkHqgvBnv7auYVggGKENP5HX57ms5eycY74CFPGmkNK3MPxEI hBqKeikQwFZjBOSjblYur7RBM7n++fD4M3raEG1HMTse8w== =ow1m -----END PGP MESSAGE-----

aathiramanoj commented 3 years ago

My NetID is am10245, Aathira Manoj, and my pub key id is 0B5C504BF8D78211

aathiramanoj commented 3 years ago

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGAkEKIBEAC/aIqa9WwGFIi0lTR1kjSE8GmoYQRuLOp/UWdrdhiF5cKolWRm dszW85ZsLQkH9LzroItMhVKfTAD72G9HT7Xq6kQaBSv3OGgOQlin44Ytxt3JXeQN Xbhg0PFzpObb2jKeSJ/837zfxrqwiS24/sjcfTaNFmKpXxc9OVtaRB22uXHQIhVI d7jzLtMi3l8nxhW1y1JlZPTscbXkEHO0rDbtWl5WP2tIn6XfIHati1e30QA7SrfV oyad3gq/IjKV1CeedW2th3V9CmEXYnMXkvXmw4SPsY42AdYLaQfrDYClxZQishY9 CuR1nlqpFneaal4BnDKDbWdTePydFBHmdadBYEhEUicWf94DQEpLuloHg+/PCmjv W8o2QXsLZqhfk7gc+/JxPnT/b6jUyBV9FK5Ca0jtbSa0df/JlrgCvUEP5tdfpfb4 AYjiGQ555ie67sjZZTByJMomsm5+WynPI6uhF+j/9yFrE2IvaKLIA4MLu669vnLw 78vYJ5sc+6SF7o5hFHhjZP6TTzeCjgkXZF2gx3N3Vrl5jJ79crlTTfLjCkeMHF5/ lZv+Lst8CUttsd41kcOQ7baEJGnd/nUyMAuFbhVU9wADfO4DRg+bD3vmUO2HNZ/r I1sHF0l1iYMOO42jGkzc05nT9YmRfOuDc4RPf9tVkIj4zBrVPtdYZmtIkQARAQAB tC9hYXRoaXJhbWFub2ogKHBjc19sYWIpIDxhYXRoaXJhbWFub2pAZ21haWwuY29t PokCTgQTAQgAOBYhBL2uX8xORVypPH5E3AtcUEv414IRBQJgJBCiAhsDBQsJCAcC BhUKCQgLAgQWAgMBAh4BAheAAAoJEAtcUEv414IRseQQAKDcGCMzuX4ETJQQ8kpD TDmyhtjBFsbI+q02sbfrfHZb9MmYI1I+ffMf3GJUSUbNMPxWRiIXQK/dVCeZ/2KQ cQi7fTAus8VFKMnkpWWZj0cSjpOSxxx7B/Z21smbmQ5nWo6sCD1ZlH1CFJJ5wjcV 3qdcBFMc7I/qnoDFzgIjWOgxLi9Yx47B5ajHccoTxu8pcU9j/0I8ys7SZEF6KL5f 3+a3MWRRPLGWJOHraqICCHgcdATSn7+h2nQQOS0XUfKc83urSmXYzX/W6XZucZRY 5arGmfBa9WLYMriDutYth46wuYlqIb3FaCk2UbinKirYdjUZMFieK2wKMbUpszNw 19+kmCoVB8Q4081lUfyV+ruZCJzqIJfse9Gk9agS5/GzmtGsB8cynNyCosoSGr8t c1ACGJKIZXCM8w/Uz41U4X++yNZCXfHWlKUPsgwHD2eCUfoMhc9/FGDYKluUgawE lZ/DA9pTxoD1rA3+9LN+/eU5FgtSCGt6ttpDreybWnMRQ9zYKromhOQpExvY2e0q 6/4BcNJpBqQdeNUCokUzOZ10dU1fjkSihz3MxizlIBmSTXIVyAslSgFzXwzwz7BU eYNTliWfPs4B9FyAQs4cnvtROtZdiZO4DCHfyC/B9wB4BaYx5JLzVERJhCwov5P3 l/eMtLD9fG5cSMoN0dn1YZ5EuQINBGAkEKIBEADPu1Oss7y/DB2iwE1x6fQEPXUt iv+nXRBw6O+azvm8cfSYxK6Xf7yIVMq/JsizZXeRCTyrpWcE++Z4TrdWARjn7yy8 Dl7kYBC6dcUCV6xv/MXYOCjNBEpZcLJ9uW94XffJZXUC77tiKAzMEUJdHdUwzeU1 Z1tyElPW4FI7BhFMACyGPvr5ZJkGUp0Ykajtqs6TUoyruB+C2gpLbWmVcGqLvGWN S22ly6u/jEAs+VvABKmou1/kS2ldBpk9R9CBZYdrGSxHFbZ8Glx+uX8k3SBsCOts FFwMppz1tC7XalrJXxVEyhk+eop3UyVs0+rpeNbyAKA/nuQ2JurMirmHSRDevCRU gKxzzbbZu1UuEI6spERXflf3nWipF+eyBXpzyppdTGdAV8Lo5pRuy1ZvCdJNmb4L rTe1CD3rqJaDMmlx+9ZPnFM4TkhmXP8PuKCX6RuNXl7cPhGOMrBZ0s/9rZckArIS Qr9O8riZK8zQIlEQGhZ9NtsdUOHPwTKZoSkWWBT6ivrcXU1ExKsGYFRyDfZJ3Zvz QPWRE5vv2fJyaQ1pc6cXnjmEe09FRxq7D1U6PWYo9D2C2bv8y8TSv7X8GK/fTmaw lmdwkEp+9pbwoo+lroERZ6WRnC4x87qPu+jSF7oZkCZDmXx/Yaxhh+o7hOVTajET fkSkpuvBvdNhrrwENwARAQABiQI2BBgBCAAgFiEEva5fzE5FXKk8fkTcC1xQS/jX ghEFAmAkEKICGwwACgkQC1xQS/jXghHXZxAAlg17WSasF0XmxIe7VOqJnUQZVvlG 165khJCtY1uChA0DC4zvE+VX9W6mV7lYkIzwJsdn3WClolzT9USS7oUh2snUNUIi tf10Fo7p08/8qjky1pREb1OcyboWZO7cPWd48GsfP24gGhAGvKPg6O/FwApRlGg9 +N/8vHeh6cU9jdsEioIvjdVdJyCh2fxLHczVYeKaDMJmTMFu4hdq3GARD0MhcFcd cmqeipSBVQpqlm/usZB7P4bJkUPkQ3fJdmoWHw9lWm1pzqmACwbaN1aA8hMgbRYR VeblGksIw7CljFWePHD2Gjmm8JEPYSZnODmTgB6xwPc3gOWY3T8ctCI8I9jjX79G vszJFmsUxa8+F/oYKUgYdUGuOS9Xt8Yk+65MJ0tOOg8WjgZu9e9RK08eUibnxyWe ewWgEFGgqCoSu52W629dhRBCLIjRkIbEqo/srVjzDATGnhWyzP83Wu/eQ6e+qtQb S9NEY7aqQRrprjH40pxIQ+/7z8odnK1O1vPciJSrybOtrvTYfiGRIyjnpB7YNY+3 M1M0Ejdmv3ZV+Fb5V+EE/le51jW45BduiJ/wgdWhZ5D2iS69/AktpeypiQPN4uzf AgUR0eu89Nr2u1O71EVXBR1dxaKVF1kfAjpj/mRmR5ZmNKo5zZUGgf2ni11XesIy M2EUK5V9larWH6c= =vDfv -----END PGP PUBLIC KEY BLOCK-----

ksmaybe commented 3 years ago
About exploit-main (exploit-service branch)
[*] Starting service from pcs-sp21-lab6-server (branch '0ff895975bf20c1233991128be75afbddf7b0049')
[*] Failed to start service
#1 [internal] load build definition from Dockerfile
#1 sha256:bd52e1de420de46cb31e1b027bc4808133f1f4738d90129e7c6ebcd8f711aedc
#1 transferring dockerfile: 303B done
#1 DONE 0.0s

#2 [internal] load .dockerignore
#2 sha256:e5c037aee4917ea90c3304fcd4903a071466111062e1f47161843dfbc0705412
#2 transferring context: 2B done
#2 DONE 0.0s

#3 [internal] load metadata for docker.io/selenium/standalone-chrome:89.0
#3 sha256:beb2bf66ef313fd2e3aace2d303a1c73abc80369b025ce6bfeb4a2cc5920b54e
#3 DONE 0.1s

#11 [1/7] FROM docker.io/selenium/standalone-chrome:89.0@sha256:beb559d9a8fddb3cc154122598a527c6fb00f19751577974013924a209431f91
#11 sha256:cfa7f2d3a3cae72a7b4a2fd6d9e3fe6bf7d6c6a4462d83f9fadb5866bd1543d1
#11 DONE 0.0s

#5 [internal] load build context
#5 sha256:0755a6ea9979aeb34c9ef34b1d8d8b3cf6c644338cd14d6561ec492365e36695
#5 transferring context: 99.32kB 0.0s done
#5 DONE 0.0s

#4 [2/7] RUN apt-get update && apt-get install -y python3 python3-pip
#4 sha256:1f82db4cdd0345e13bbf91421a58803f0de60b2a8230a42c43c8a09334118de0
#4 CACHED

#6 [3/7] COPY . /app
#6 sha256:831e5ef72a266a5181dfad168036c469289bee9113ab1e75c608e8b3e626d88e
#6 DONE 0.1s

#7 [4/7] WORKDIR /app
#7 sha256:207f44957f89ad7cedb914f18150d564c220f407c585a1bea6f1b0e35400be0f
#7 DONE 0.0s

#8 [5/7] RUN mkdir -p /var/ctf
#8 sha256:375fa5ba6164cec3e3cfbaec1a3a8ba6d6221ab5f12c8d2035e0195cbfa6189d
#8 DONE 0.3s

#9 [6/7] COPY flag /var/ctf/
#9 sha256:0506922f5672aac96754c83611513caa72a3ae924f23e0d8d340e3ccd9400a06
#9 DONE 0.0s

#10 [7/7] RUN pip3 install -r requirements.txt
#10 sha256:bc5149300402434fde8da82a074e57aa766e2a5da8bab9817cff6578b5e922d9
#10 1.013 WARNING: The directory '/home/seluser/.cache/pip' or its parent directory is not owned or is not writable by the current user. The cache has been disabled. Check the permissions and owner of that directory. If executing pip with sudo, you may want sudo's -H flag.
#10 1.137 Collecting click==7.1.2
#10 1.189   Downloading click-7.1.2-py2.py3-none-any.whl (82 kB)
#10 1.247 Collecting Flask==1.1.2
#10 1.259   Downloading Flask-1.1.2-py2.py3-none-any.whl (94 kB)
#10 1.315 Collecting itsdangerous==1.1.0
#10 1.326   Downloading itsdangerous-1.1.0-py2.py3-none-any.whl (16 kB)
#10 1.385 Collecting Jinja2==2.11.3
#10 1.399   Downloading Jinja2-2.11.3-py2.py3-none-any.whl (125 kB)
#10 1.478 Collecting MarkupSafe==1.1.1
#10 1.501   Downloading MarkupSafe-1.1.1-cp38-cp38-manylinux2010_x86_64.whl (32 kB)
#10 1.573 Collecting selenium==3.141.0
#10 1.589   Downloading selenium-3.141.0-py2.py3-none-any.whl (904 kB)
#10 1.722 Collecting urllib3==1.26.3
#10 1.734   Downloading urllib3-1.26.3-py2.py3-none-any.whl (137 kB)
#10 1.809 Collecting Werkzeug==1.0.1
#10 1.821   Downloading Werkzeug-1.0.1-py2.py3-none-any.whl (298 kB)
#10 1.888 Installing collected packages: click, Werkzeug, itsdangerous, MarkupSafe, Jinja2, Flask, urllib3, selenium
#10 2.360 Successfully installed Flask-1.1.2 Jinja2-2.11.3 MarkupSafe-1.1.1 Werkzeug-1.0.1 click-7.1.2 itsdangerous-1.1.0 selenium-3.141.0 urllib3-1.26.3
#10 DONE 2.5s

#12 exporting to image
#12 sha256:e8c613e07b0b7ff33893b694f7759a10d42e180f2b4dc349fb57dc6b71dcab00
#12 exporting layers 0.1s done
#12 writing image sha256:9351237aa6fb44725cddd289998259734cba02dd739a709d135136713ccef1b7 done
#12 naming to docker.io/library/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049 done
#12 DONE 0.1s
docker: Error response from daemon: Conflict. The container name "/pcs-sp21-lab6-server-0ff895975bf20c1233991128be75afbddf7b0049" is already in use by container "8091eae6427042a587827ed4ffe9bb129700b81cd8917e1bf7ccecbbe79645d5". You have to remove (or rename) that container to be able to reuse that name.
See 'docker run --help'.

==========================

[*] The exploit did not work.

ksmaybe commented 3 years ago

This submission has been verified. Well done!