├── assets ├── update.js ├── update.html ├── create.js ├── view.html ├── create.html └── view.js ├── requirements.txt ├── config.json ├── figures ├── see_flags.png ├── address_to_go.png ├── challenge_type.png ├── exemple_cheat_monitor.png ├── inspecting_container.png └── challenge_type_Dockerfile.png ├── globals.py ├── utils.py ├── hooks.py ├── .gitignore ├── templates └── red_herring.html ├── models.py ├── README.md ├── __init__.py └── LICENSE /assets/update.js: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- 1 | mnemonic==0.20 2 | docker==6.1.3 -------------------------------------------------------------------------------- /assets/update.html: -------------------------------------------------------------------------------- 1 | {% extends "admin/challenges/update.html" %} -------------------------------------------------------------------------------- /config.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "Red Herring", 3 | "route": "/admin/red_herring" 4 | } -------------------------------------------------------------------------------- /figures/see_flags.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/see_flags.png -------------------------------------------------------------------------------- /figures/address_to_go.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/address_to_go.png -------------------------------------------------------------------------------- /figures/challenge_type.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/challenge_type.png -------------------------------------------------------------------------------- /assets/create.js: -------------------------------------------------------------------------------- 1 | CTFd.plugin.run((_CTFd) => { 2 | const $ = _CTFd.lib.$ 3 | const md = _CTFd.lib.markdown() 4 | }) 5 | -------------------------------------------------------------------------------- /figures/exemple_cheat_monitor.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/exemple_cheat_monitor.png -------------------------------------------------------------------------------- /figures/inspecting_container.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/inspecting_container.png -------------------------------------------------------------------------------- /figures/challenge_type_Dockerfile.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Isotech42/CTFd-RedHerring/HEAD/figures/challenge_type_Dockerfile.png -------------------------------------------------------------------------------- /globals.py: -------------------------------------------------------------------------------- 1 | def initialize(): 2 | global IP_ADDRESS_CONTAINERS 3 | global PORT_CONTAINERS_START 4 | global FLAG_LANGUAGE 5 | global FLAG_PREFIX 6 | 7 | IP_ADDRESS_CONTAINERS = "127.0.0.1" 8 | PORT_CONTAINERS_START = 8080 9 | FLAG_LANGUAGE = "english" 10 | FLAG_PREFIX = "CTF2024" -------------------------------------------------------------------------------- /assets/view.html: -------------------------------------------------------------------------------- 1 | {% extends "challenge.html" %} 2 | 3 | {% block description %} 4 | {{ challenge.html }} 5 | 6 | {% if challenge.get_container_address() is defined and challenge.get_container_port() is defined %} 7 |
8 | The address you need to access : {{challenge.get_container_address()}}:{{ challenge.get_container_port() }} 9 | {% endif %} 10 | 11 | {% endblock %} -------------------------------------------------------------------------------- /assets/create.html: -------------------------------------------------------------------------------- 1 | {% extends "admin/challenges/create.html" %} 2 | 3 | {% block header %} 4 | 7 | {% endblock %} 8 | 9 | {% block type %} 10 |
11 | 17 | 18 |
19 | 20 | 21 | {% endblock %} -------------------------------------------------------------------------------- /assets/view.js: -------------------------------------------------------------------------------- 1 | CTFd._internal.challenge.data = undefined; 2 | 3 | // TODO: Remove in CTFd v4.0 4 | CTFd._internal.challenge.renderer = null; 5 | 6 | CTFd._internal.challenge.preRender = function() {}; 7 | 8 | // TODO: Remove in CTFd v4.0 9 | CTFd._internal.challenge.render = null; 10 | 11 | CTFd._internal.challenge.postRender = function() {}; 12 | 13 | CTFd._internal.challenge.submit = function(preview) { 14 | var challenge_id = parseInt(CTFd.lib.$("#challenge-id").val()); 15 | var submission = CTFd.lib.$("#challenge-input").val(); 16 | 17 | var body = { 18 | challenge_id: challenge_id, 19 | submission: submission 20 | }; 21 | var params = {}; 22 | if (preview) { 23 | params["preview"] = true; 24 | } 25 | 26 | return CTFd.api.post_challenge_attempt(params, body).then(function(response) { 27 | if (response.status === 429) { 28 | // User was ratelimited but process response 29 | return response; 30 | } 31 | if (response.status === 403) { 32 | // User is not logged in or CTF is paused. 33 | return response; 34 | } 35 | return response; 36 | }); 37 | }; -------------------------------------------------------------------------------- /utils.py: -------------------------------------------------------------------------------- 1 | from mnemonic import Mnemonic 2 | import docker 3 | import tempfile 4 | from . import globals 5 | 6 | def generate_flag(): 7 | mnemo = Mnemonic(globals.FLAG_LANGUAGE) 8 | words = mnemo.generate(strength=128) 9 | 10 | # Take only the first 4 words 11 | words = words.split(" ")[0:4] 12 | 13 | # Insert the header of the flag and "_" between words like "flag{word1_word2_word3_word4}" 14 | flag = globals.FLAG_PREFIX + "{" + "_".join(words) + "}" 15 | return flag 16 | 17 | def create_docker_container(buildfile, flag, port, challenge_name, team_id): 18 | # Convert the buildfile (which is a string) to a new temporary File object 19 | temp_dockerfile = tempfile.TemporaryFile() 20 | temp_dockerfile.write(buildfile.encode()) 21 | temp_dockerfile.seek(0) 22 | 23 | # Create a Docker client 24 | client = docker.from_env() 25 | 26 | # Build image from Dockerfile 27 | challenge_name = challenge_name.replace(" ", "_") 28 | tag_name = (challenge_name).lower() 29 | my_image = client.images.build(fileobj=temp_dockerfile, tag=tag_name) 30 | 31 | # Run container from image 32 | container = client.containers.run( image=tag_name, 33 | detach=True, 34 | tty=True, 35 | environment=["FLAG=" + flag], 36 | command="/bin/bash", 37 | ports={'80/tcp':(globals.IP_ADDRESS_CONTAINERS,port)}, 38 | ) 39 | temp_dockerfile.close() 40 | 41 | return container.name -------------------------------------------------------------------------------- /hooks.py: -------------------------------------------------------------------------------- 1 | from sqlalchemy.event import listen 2 | from CTFd.models import db, Teams, Challenges, Flags 3 | 4 | from .utils import generate_flag, create_docker_container 5 | from .models import Containers 6 | from . import globals 7 | 8 | def on_team_create(mapper, conn, team): 9 | # When a team is created, create a new flag for each challenge that is a "red_herring" type 10 | red_herring_challenges = Challenges.query.filter_by(type="red_herring").all() 11 | 12 | port = globals.PORT_CONTAINERS_START 13 | if len(red_herring_challenges) != 0: 14 | 15 | # Get the last port used 16 | last_container = Containers.query.order_by(Containers.port.desc()).first() 17 | if last_container is not None: 18 | port = last_container.port + 1 19 | 20 | for challenge in red_herring_challenges: 21 | generated_flag = generate_flag() 22 | 23 | # Create the flag 24 | flag = Flags(challenge_id = challenge.id, type = "red_herring", content = generated_flag, data = team.id) 25 | db.session.add(flag) 26 | 27 | # Create the container 28 | # Get the buildfile of the challenge 29 | buildfile = challenge.dockerfile 30 | 31 | # Generate the container 32 | container_name = create_docker_container(buildfile=buildfile, flag=generated_flag, port=port, challenge_name=challenge.name, team_id=team.id) 33 | 34 | # Save the container in the database 35 | container = Containers(name=container_name, port=port, dockerfile=buildfile, challengeid=challenge.id, teamid=team.id) 36 | port += 1 37 | db.session.add(container) 38 | 39 | def load_hooks(): 40 | listen(Teams, "after_insert", on_team_create) -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- 1 | # Byte-compiled / optimized / DLL files 2 | __pycache__/ 3 | *.py[cod] 4 | *$py.class 5 | 6 | # C extensions 7 | *.so 8 | 9 | # Distribution / packaging 10 | .Python 11 | env/ 12 | build/ 13 | develop-eggs/ 14 | dist/ 15 | downloads/ 16 | eggs/ 17 | .eggs/ 18 | lib/ 19 | lib64/ 20 | parts/ 21 | sdist/ 22 | var/ 23 | wheels/ 24 | *.egg-info/ 25 | .installed.cfg 26 | *.egg 27 | 28 | # PyInstaller 29 | # Usually these files are written by a python script from a template 30 | # before PyInstaller builds the exe, so as to inject date/other infos into it. 31 | *.manifest 32 | *.spec 33 | 34 | # Installer logs 35 | pip-log.txt 36 | pip-delete-this-directory.txt 37 | 38 | # Unit test / coverage reports 39 | htmlcov/ 40 | .tox/ 41 | .coverage 42 | .coverage.* 43 | .cache 44 | nosetests.xml 45 | coverage.xml 46 | *.cover 47 | .hypothesis/ 48 | 49 | # Translations 50 | *.mo 51 | *.pot 52 | 53 | # Django stuff: 54 | *.log 55 | local_settings.py 56 | 57 | # Flask stuff: 58 | instance/ 59 | .webassets-cache 60 | 61 | # Scrapy stuff: 62 | .scrapy 63 | 64 | # Sphinx documentation 65 | docs/_build/ 66 | 67 | # PyBuilder 68 | target/ 69 | 70 | # Jupyter Notebook 71 | .ipynb_checkpoints 72 | 73 | # pyenv 74 | .python-version 75 | 76 | # celery beat schedule file 77 | celerybeat-schedule 78 | 79 | # SageMath parsed files 80 | *.sage.py 81 | 82 | # dotenv 83 | .env 84 | 85 | # virtualenv 86 | .venv 87 | venv/ 88 | ENV/ 89 | 90 | # Spyder project settings 91 | .spyderproject 92 | .spyproject 93 | 94 | # Rope project settings 95 | .ropeproject 96 | 97 | # mkdocs documentation 98 | /site 99 | 100 | # mypy 101 | .mypy_cache/ 102 | -------------------------------------------------------------------------------- /templates/red_herring.html: -------------------------------------------------------------------------------- 1 | {% extends "base.html" %} 2 | 3 | {% block stylesheets %} 4 | {% endblock %} 5 | 6 | {% block content %} 7 |
8 |
9 |

RedHerring - Cheat Monitor

10 |
11 |
12 |
13 |
14 |
15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | {% for cheater in cheaters %} 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | {% endfor %} 35 | 36 |
IDChallengeCheat TeamSharer TeamDate
{{ loop.index }}{{ cheater.challenge_name() }}{{ cheater.cheated_team_name() }}{{ cheater.shared_team_name() }}{{ cheater.date}}
37 |
38 |
39 |
40 | {% endblock %} -------------------------------------------------------------------------------- /models.py: -------------------------------------------------------------------------------- 1 | from CTFd.models import db, Teams, Challenges, Flags 2 | from CTFd.utils.user import get_current_team 3 | from . import globals 4 | 5 | class RedHerringChallenge(Challenges): 6 | __mapper_args__ = {"polymorphic_identity": "red_herring"} 7 | id = db.Column( 8 | db.Integer, db.ForeignKey("challenges.id", ondelete="CASCADE"), primary_key=True 9 | ) 10 | dockerfile = db.Column(db.Text) 11 | 12 | def __init__(self, *args, **kwargs): 13 | super(RedHerringChallenge, self).__init__(**kwargs) 14 | self.dockerfile = kwargs["dockerfile"] 15 | 16 | def get_container_port(self): 17 | try : 18 | teamid = get_current_team().id 19 | except: 20 | teamid = None 21 | 22 | if teamid is None: 23 | return None 24 | 25 | container = Containers.query.filter_by(challengeid=self.id, teamid=teamid).first() 26 | return container.port 27 | 28 | def get_container_address(self): 29 | return globals.IP_ADDRESS_CONTAINERS 30 | 31 | 32 | class CheaterTeams(db.Model): 33 | __tablename__ = 'cheater_teams' 34 | 35 | id = db.Column(db.Integer, primary_key=True) 36 | challengeid = db.Column(db.Integer, db.ForeignKey('challenges.id', ondelete="CASCADE")) 37 | cheaterid = db.Column(db.Integer, db.ForeignKey('users.id', ondelete="CASCADE")) 38 | cheatteamid = db.Column(db.Integer, db.ForeignKey('teams.id', ondelete="CASCADE")) 39 | sharerteamid = db.Column(db.Integer, db.ForeignKey('teams.id', ondelete="CASCADE")) 40 | flagid = db.Column(db.Integer, db.ForeignKey('flags.id', ondelete="CASCADE")) 41 | date = db.Column(db.DateTime, default=db.func.current_timestamp()) 42 | 43 | def __init__(self, challengeid, cheaterid, cheatteamid, sharerteamid, flagid): 44 | self.challengeid = challengeid 45 | self.cheaterid = cheaterid 46 | self.cheatteamid = cheatteamid 47 | self.sharerteamid = sharerteamid 48 | self.flagid = flagid 49 | 50 | def __repr__(self): 51 | return "".format(self.cheatteamid, self.challengeid, self.flagid, self.sharerteamid, self.date) 52 | 53 | def cheated_team_name(self): 54 | return Teams.query.filter_by(id=self.cheatteamid).first().name 55 | 56 | def shared_team_name(self): 57 | return Teams.query.filter_by(id=self.sharerteamid).first().name 58 | 59 | def challenge_name(self): 60 | return Challenges.query.filter_by(id=self.challengeid).first().name 61 | 62 | class Containers(db.Model): 63 | id = db.Column(db.Integer, primary_key=True) 64 | name = db.Column(db.String(80)) 65 | dockerfile = db.Column(db.Text) 66 | address = db.Column(db.String(80)) 67 | port = db.Column(db.Integer) 68 | challengeid = db.Column(db.Integer, db.ForeignKey('challenges.id', ondelete="CASCADE")) 69 | teamid = db.Column(db.Integer, db.ForeignKey('teams.id', ondelete="CASCADE")) 70 | 71 | def __init__(self, challengeid, teamid, name, dockerfile, port, address="127.0.0.1"): 72 | self.name = name 73 | self.dockerfile = dockerfile 74 | self.challengeid = challengeid 75 | self.teamid = teamid 76 | self.port = port 77 | self.address = globals.IP_ADDRESS_CONTAINERS 78 | 79 | def __repr__(self): 80 | return "".format(self.id, self.name, self.challengeid, self.teamid) -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # CTFd - Red Herring Plugin 2 | 3 | ## Introduction 4 | 5 | The Red Herring plugin is an extension for the CTFd platform, designed to provide a new type of challenge that promotes fairness and prevents flag sharing among participating teams. This user manual will guide you through the steps of using the Red Herring plugin effectively. 6 | 7 | ## Table of Contents 8 | 9 | 1. Installation 10 | 2. Creating Red Herring Challenges 11 | 3. Managing Teams and Containers 12 | 4. Monitoring Cheating Attempts 13 | 5. Troubleshooting 14 | 6. Support and Feedback 15 | 16 | ## 1. Installation 17 | 18 | To use the Red Herring Challenges plugin, follow these steps: 19 | 20 | 1. Clone or download the plugin repository from [GitHub](https://github.com/Isotech42/CTFd-RedHerring). 21 | 2. Navigate to the CTFd installation directory on your server. 22 | 3. Copy the downloaded plugin folder into the CTFd plugins directory. 23 | 4. Modify the variables in the [`globals.py`](globals.py) file to suit your needs, as the flag prefix or words language, the IP address of the Docker host and the starting port that will be exposed and used by the Docker service. 24 | 5. Restart the CTFd application. 25 | 26 | **WARNING** 27 | 28 | The plugin was developed and tested on a local machine running the CTFd application locally with a Docker service running on the same machine. It is not guaranteed to work on a dockerized version of CTFd or with a Docker service running on a remote server (specifically the creation of the Docker containers for each team). 29 | 30 | ## 2. Creating Red Herring Challenges 31 | 32 | To create a Red Herring challenge, follow these steps: 33 | 34 | 1. Log in to the CTFd admin panel. 35 | 2. Click on the "Create Challenge" button. 36 | 3. Select "red_herring" as the challenge type. 37 | 4. Provide the necessary challenge details, such as the title, description, and points. 38 | 39 | ![Create new red_herring challenge type](./figures/challenge_type.png) 40 | 41 | 5. Specify the Dockerfile content for the challenge in the dedicated "Dockerfile" field. 42 | 43 | ![The Dockerfile field](./figures/challenge_type_Dockerfile.png) 44 | 45 | 6. Click on the "Create Challenge" button to create the challenge. 46 | 47 | The plugin will automatically generate a unique flag for each participating team, ensuring that each team receives a different flag for the same challenge and creating a unique Docker container for each team. 48 | 49 | ![Checking the flags created](./figures/see_flags.png) 50 | 51 | If it's the first time to build your image in Docker, the plugin may take a few seconds to minutes to build the Docker image and create the Docker container for each team. 52 | 53 | ![Inspecting the Docker containers](./figures/inspecting_container.png) 54 | 55 | When a user goes in the challenges page and click on a Red Herring challenge, the plugin will show the address of the Docker container associated with the team and the port exposed by the container. 56 | 57 | ![Viewing a Red Herring challenge](./figures/address_to_go.png) 58 | 59 | **CAUTION** 60 | 61 | Because the flag is provided to the container as an environment variable, your challenge must not allow competitors to read the environment variables via command execution or by reading /proc//environ. 62 | Verify that Docker is running on your server and that the Docker service is accessible to the CTFd application. 63 | 64 | 65 | ## 3. Team Creation 66 | 67 | The Red Herring plugin dynamically creates Docker containers for each team participating in a challenge. The containers provide an isolated environment for teams to attempt the challenge without interfering with other teams. 68 | 69 | When you create a new team in CTFd, the plugin will automatically generate a unique flag for each existing Red Herring challenge. It will also create a dedicated Docker container for the team associated with each challenge. 70 | The different flags for each challenge are stored in the CTFd database that you can access via the admin panel in the section "Flags" under your challenge. 71 | 72 | ## 4. Monitoring Cheating Attempts 73 | 74 | The Red Herring plugin includes a "Cheat Monitor" feature to detect cheating attempts during the competition. The Cheat Monitor provides an easy way to visualize and identify any cheating attempts detected by the plugin. 75 | 76 | To access the Cheat Monitor: 77 | 78 | 1. Visit the URL corresponding to the Cheat Monitor in the upper right corner of the CTFd admin panel, under the "Plugins" section. 79 | 2. The Cheat Monitor will display a table with information about teams that shared flags, including the team IDs, the challenge involved, the team attempting to cheat, the team receiving the shared flag, the shared flag content, and the incident date. 80 | 81 | ![Cheat Monitor](./figures/exemple_cheat_monitor.png) 82 | 83 | ## 5. Troubleshooting 84 | 85 | If you encounter any issues while using the Red Herring Challenges plugin, consider the following troubleshooting tips: 86 | 87 | 1. Ensure that you have properly installed the plugin and restarted the CTFd application. 88 | 2. Verify that the Docker service is running on your server. 89 | 3. Check the CTFd logs for any error messages related to the plugin. 90 | 91 | Feel free to change the Python code to suit your needs or if you manage to fix any bugs. 92 | 93 | ## 6. Support and Feedback 94 | 95 | This plugin was created in the context of my Bachelor's work and has surely some bugs or can be improved. 96 | For any questions, support, or feedback regarding the Red Herring plugin, please contact me at [isotech42@gmail.com](mailto:isotech42@gmail.com). I welcome your input and suggestions to improve the plugin and make hacking competitions more engaging and fair for all participants. 97 | 98 | ## 7. References 99 | 100 | [1] [CTFd Plugin Docs](https://docs.ctfd.io/docs/plugins/overview) : For all information about CTFd plugins and how to use them. 101 | 102 | [2] [CTFdOnlineChallenge](https://github.com/XuCcc/CTFdOnlineChallenge) : For his great work on the CTFdOnlineChallenge plugin, which inspired me to create this plugin and provided a great starting point for my work. 103 | 104 | [3] [Docker SDK for Python](https://docker-py.readthedocs.io/en/stable/) : For the documentation of the Docker SDK for Python, which I used to create the Docker containers for the Red Herring challenges. 105 | 106 | [4] [Docker Documentation](https://docs.docker.com/) : For the documentation of Docker, which I also used to create the Docker containers for the Red Herring Challenges. 107 | 108 | --- 109 | Thank you for using the Red Herring plugin ! I hope it enhances your CTF experience and ensures an exciting and equitable competition environment. Happy hacking! -------------------------------------------------------------------------------- /__init__.py: -------------------------------------------------------------------------------- 1 | import os 2 | import json 3 | 4 | from flask import render_template, Blueprint 5 | from flask import request, jsonify,session 6 | 7 | from CTFd.models import ( 8 | Awards, 9 | ChallengeFiles, 10 | Challenges, 11 | Fails, 12 | Flags, 13 | Hints, 14 | Solves, 15 | Tags, 16 | Teams, 17 | db, 18 | ) 19 | 20 | from .hooks import load_hooks 21 | from .models import CheaterTeams, RedHerringChallenge, Containers 22 | from .utils import generate_flag, create_docker_container 23 | from . import globals 24 | 25 | from CTFd.plugins import register_plugin_assets_directory 26 | from CTFd.plugins.migrations import upgrade 27 | from CTFd.plugins.challenges import BaseChallenge, CHALLENGE_CLASSES 28 | from CTFd.plugins.flags import FlagException, get_flag_class, CTFdStaticFlag, FLAG_CLASSES 29 | from CTFd.utils.uploads import delete_file 30 | from CTFd.utils.user import get_current_team, get_current_user 31 | from CTFd.utils.decorators import admins_only 32 | from CTFd.config import Config 33 | 34 | 35 | PLUGIN_PATH = os.path.dirname(__file__) 36 | CONFIG = json.load(open("{}/config.json".format(PLUGIN_PATH))) 37 | 38 | directory_name = PLUGIN_PATH.split(os.sep)[-1] # Get the directory name of this file 39 | 40 | red = Blueprint(directory_name, __name__, template_folder="templates") 41 | 42 | class RedHerringTypeChallenge(BaseChallenge): 43 | id = "red_herring" # Unique identifier used to register challenges 44 | name = "red_herring" # Name of a challenge type 45 | templates = { # Nunjucks templates used for each aspect of challenge editing & viewing 46 | 'create': '/plugins/'+ directory_name +'/assets/create.html', # Used to render the challenge when creating/editing 47 | 'update': '/plugins/' + directory_name + '/assets/update.html', # Used to render the challenge when updating 48 | 'view': '/plugins/' + directory_name + '/assets/view.html', # Used to render the challenge when viewing 49 | } 50 | scripts = { # Scripts that are loaded when a template is loaded 51 | 'create': '/plugins/'+ directory_name +'/assets/create.js', # Used to init the create template JavaScript 52 | 'update': '/plugins/'+ directory_name +'/assets/update.js', # Used to init the create template JavaScript 53 | 'view': '/plugins/'+ directory_name +'/assets/view.js', # Used to init the create template JavaScript 54 | } 55 | 56 | # Route at which files are accessible. This must be registered using register_plugin_assets_directory() 57 | route = '/plugins/'+ directory_name +'/assets/' 58 | challenge_model = RedHerringChallenge 59 | 60 | @staticmethod 61 | def create(request): 62 | """ 63 | This method is used to process the challenge creation request. 64 | 65 | :param request: 66 | :return: 67 | """ 68 | data = request.form or request.get_json() 69 | challenge = RedHerringChallenge( 70 | name=data['name'], 71 | category=data['category'], 72 | description=data['description'], 73 | value=data['value'], 74 | state=data['state'], 75 | type=data['type'], 76 | dockerfile= data['buildfile'] 77 | ) 78 | 79 | buildfile = data['buildfile'] 80 | 81 | db.session.add(challenge) 82 | db.session.commit() 83 | 84 | # Check if there is teams that are created 85 | teams = Teams.query.all() 86 | if len(teams) > 0: 87 | 88 | # Get the last port used 89 | last_container = Containers.query.order_by(Containers.port.desc()).first() 90 | if last_container_port is None: 91 | port = globals.PORT_CONTAINERS_START 92 | else: 93 | port = last_container.port + 1 94 | 95 | # For each team, create a flag and a container for the challenge 96 | for team in teams: 97 | generated_flag = generate_flag() 98 | 99 | # Generate the container 100 | container_name = create_docker_container(buildfile=buildfile, flag=generated_flag, port=port, challenge_name=challenge.name, team_id=team.id) 101 | 102 | # Save the container in the database 103 | container = Containers(name=container_name, port=port, dockerfile=buildfile, challengeid=challenge.id, teamid=team.id) 104 | port += 1 105 | db.session.add(container) 106 | 107 | # Save the flag in the database 108 | flag = Flags(challenge_id = challenge.id, type = "red_herring", content = generated_flag, data = team.id) 109 | db.session.add(flag) 110 | 111 | 112 | db.session.commit() 113 | 114 | 115 | return challenge 116 | 117 | class RedHearingFlag(CTFdStaticFlag): 118 | name = "red_herring" 119 | 120 | @staticmethod 121 | def compare(chal_key_obj, provided_flag): 122 | # Get the actual flag to check for the challenge submitted (the function compare() is called for each flag of the challenge) 123 | saved_flag = chal_key_obj.content 124 | 125 | # Compare each character in the flag if the team id is the one that is supposed to solve the challenge 126 | curr_team_id = get_current_team().id 127 | 128 | if len(saved_flag) != len(provided_flag): 129 | return False 130 | 131 | result = 0 132 | 133 | for x, y in zip(saved_flag, provided_flag): 134 | result |= ord(x) ^ ord(y) 135 | 136 | if result == 0: 137 | # If the flag is correct, we need to check if the team is the one associated with the flag 138 | team_id_needed = chal_key_obj.data 139 | if int(team_id_needed) == int(curr_team_id): 140 | return True 141 | else: 142 | curr_user_id = get_current_user().id 143 | cheater = CheaterTeams(challengeid=chal_key_obj.challenge_id, cheaterid=curr_user_id, cheatteamid=curr_team_id, sharerteamid=team_id_needed, flagid=chal_key_obj.id) 144 | db.session.add(cheater) 145 | return False 146 | else: 147 | return False 148 | 149 | 150 | @red.route('/admin/red_herring',methods=['GET']) 151 | @admins_only 152 | def show_cheaters(): 153 | if request.method == 'GET': 154 | cheaters = CheaterTeams.query.all() 155 | return render_template('red_herring.html', cheaters=cheaters) 156 | 157 | 158 | def load(app): 159 | globals.initialize() 160 | app.db.create_all() # Create all DB entities 161 | upgrade(plugin_name="red_herring") 162 | 163 | CHALLENGE_CLASSES['red_herring'] = RedHerringTypeChallenge 164 | FLAG_CLASSES['red_herring'] = RedHearingFlag 165 | 166 | app.register_blueprint(red) 167 | register_plugin_assets_directory(app, base_path='/plugins/'+ directory_name +'/assets/') 168 | 169 | load_hooks() -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | Apache License 2 | Version 2.0, January 2004 3 | http://www.apache.org/licenses/ 4 | 5 | TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 6 | 7 | 1. Definitions. 8 | 9 | "License" shall mean the terms and conditions for use, reproduction, 10 | and distribution as defined by Sections 1 through 9 of this document. 11 | 12 | "Licensor" shall mean the copyright owner or entity authorized by 13 | the copyright owner that is granting the License. 14 | 15 | "Legal Entity" shall mean the union of the acting entity and all 16 | other entities that control, are controlled by, or are under common 17 | control with that entity. For the purposes of this definition, 18 | "control" means (i) the power, direct or indirect, to cause the 19 | direction or management of such entity, whether by contract or 20 | otherwise, or (ii) ownership of fifty percent (50%) or more of the 21 | outstanding shares, or (iii) beneficial ownership of such entity. 22 | 23 | "You" (or "Your") shall mean an individual or Legal Entity 24 | exercising permissions granted by this License. 25 | 26 | "Source" form shall mean the preferred form for making modifications, 27 | including but not limited to software source code, documentation 28 | source, and configuration files. 29 | 30 | "Object" form shall mean any form resulting from mechanical 31 | transformation or translation of a Source form, including but 32 | not limited to compiled object code, generated documentation, 33 | and conversions to other media types. 34 | 35 | "Work" shall mean the work of authorship, whether in Source or 36 | Object form, made available under the License, as indicated by a 37 | copyright notice that is included in or attached to the work 38 | (an example is provided in the Appendix below). 39 | 40 | "Derivative Works" shall mean any work, whether in Source or Object 41 | form, that is based on (or derived from) the Work and for which the 42 | editorial revisions, annotations, elaborations, or other modifications 43 | represent, as a whole, an original work of authorship. For the purposes 44 | of this License, Derivative Works shall not include works that remain 45 | separable from, or merely link (or bind by name) to the interfaces of, 46 | the Work and Derivative Works thereof. 47 | 48 | "Contribution" shall mean any work of authorship, including 49 | the original version of the Work and any modifications or additions 50 | to that Work or Derivative Works thereof, that is intentionally 51 | submitted to Licensor for inclusion in the Work by the copyright owner 52 | or by an individual or Legal Entity authorized to submit on behalf of 53 | the copyright owner. For the purposes of this definition, "submitted" 54 | means any form of electronic, verbal, or written communication sent 55 | to the Licensor or its representatives, including but not limited to 56 | communication on electronic mailing lists, source code control systems, 57 | and issue tracking systems that are managed by, or on behalf of, the 58 | Licensor for the purpose of discussing and improving the Work, but 59 | excluding communication that is conspicuously marked or otherwise 60 | designated in writing by the copyright owner as "Not a Contribution." 61 | 62 | "Contributor" shall mean Licensor and any individual or Legal Entity 63 | on behalf of whom a Contribution has been received by Licensor and 64 | subsequently incorporated within the Work. 65 | 66 | 2. Grant of Copyright License. Subject to the terms and conditions of 67 | this License, each Contributor hereby grants to You a perpetual, 68 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 69 | copyright license to reproduce, prepare Derivative Works of, 70 | publicly display, publicly perform, sublicense, and distribute the 71 | Work and such Derivative Works in Source or Object form. 72 | 73 | 3. Grant of Patent License. Subject to the terms and conditions of 74 | this License, each Contributor hereby grants to You a perpetual, 75 | worldwide, non-exclusive, no-charge, royalty-free, irrevocable 76 | (except as stated in this section) patent license to make, have made, 77 | use, offer to sell, sell, import, and otherwise transfer the Work, 78 | where such license applies only to those patent claims licensable 79 | by such Contributor that are necessarily infringed by their 80 | Contribution(s) alone or by combination of their Contribution(s) 81 | with the Work to which such Contribution(s) was submitted. If You 82 | institute patent litigation against any entity (including a 83 | cross-claim or counterclaim in a lawsuit) alleging that the Work 84 | or a Contribution incorporated within the Work constitutes direct 85 | or contributory patent infringement, then any patent licenses 86 | granted to You under this License for that Work shall terminate 87 | as of the date such litigation is filed. 88 | 89 | 4. Redistribution. You may reproduce and distribute copies of the 90 | Work or Derivative Works thereof in any medium, with or without 91 | modifications, and in Source or Object form, provided that You 92 | meet the following conditions: 93 | 94 | (a) You must give any other recipients of the Work or 95 | Derivative Works a copy of this License; and 96 | 97 | (b) You must cause any modified files to carry prominent notices 98 | stating that You changed the files; and 99 | 100 | (c) You must retain, in the Source form of any Derivative Works 101 | that You distribute, all copyright, patent, trademark, and 102 | attribution notices from the Source form of the Work, 103 | excluding those notices that do not pertain to any part of 104 | the Derivative Works; and 105 | 106 | (d) If the Work includes a "NOTICE" text file as part of its 107 | distribution, then any Derivative Works that You distribute must 108 | include a readable copy of the attribution notices contained 109 | within such NOTICE file, excluding those notices that do not 110 | pertain to any part of the Derivative Works, in at least one 111 | of the following places: within a NOTICE text file distributed 112 | as part of the Derivative Works; within the Source form or 113 | documentation, if provided along with the Derivative Works; or, 114 | within a display generated by the Derivative Works, if and 115 | wherever such third-party notices normally appear. The contents 116 | of the NOTICE file are for informational purposes only and 117 | do not modify the License. You may add Your own attribution 118 | notices within Derivative Works that You distribute, alongside 119 | or as an addendum to the NOTICE text from the Work, provided 120 | that such additional attribution notices cannot be construed 121 | as modifying the License. 122 | 123 | You may add Your own copyright statement to Your modifications and 124 | may provide additional or different license terms and conditions 125 | for use, reproduction, or distribution of Your modifications, or 126 | for any such Derivative Works as a whole, provided Your use, 127 | reproduction, and distribution of the Work otherwise complies with 128 | the conditions stated in this License. 129 | 130 | 5. Submission of Contributions. Unless You explicitly state otherwise, 131 | any Contribution intentionally submitted for inclusion in the Work 132 | by You to the Licensor shall be under the terms and conditions of 133 | this License, without any additional terms or conditions. 134 | Notwithstanding the above, nothing herein shall supersede or modify 135 | the terms of any separate license agreement you may have executed 136 | with Licensor regarding such Contributions. 137 | 138 | 6. Trademarks. This License does not grant permission to use the trade 139 | names, trademarks, service marks, or product names of the Licensor, 140 | except as required for reasonable and customary use in describing the 141 | origin of the Work and reproducing the content of the NOTICE file. 142 | 143 | 7. Disclaimer of Warranty. Unless required by applicable law or 144 | agreed to in writing, Licensor provides the Work (and each 145 | Contributor provides its Contributions) on an "AS IS" BASIS, 146 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or 147 | implied, including, without limitation, any warranties or conditions 148 | of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A 149 | PARTICULAR PURPOSE. You are solely responsible for determining the 150 | appropriateness of using or redistributing the Work and assume any 151 | risks associated with Your exercise of permissions under this License. 152 | 153 | 8. Limitation of Liability. In no event and under no legal theory, 154 | whether in tort (including negligence), contract, or otherwise, 155 | unless required by applicable law (such as deliberate and grossly 156 | negligent acts) or agreed to in writing, shall any Contributor be 157 | liable to You for damages, including any direct, indirect, special, 158 | incidental, or consequential damages of any character arising as a 159 | result of this License or out of the use or inability to use the 160 | Work (including but not limited to damages for loss of goodwill, 161 | work stoppage, computer failure or malfunction, or any and all 162 | other commercial damages or losses), even if such Contributor 163 | has been advised of the possibility of such damages. 164 | 165 | 9. Accepting Warranty or Additional Liability. While redistributing 166 | the Work or Derivative Works thereof, You may choose to offer, 167 | and charge a fee for, acceptance of support, warranty, indemnity, 168 | or other liability obligations and/or rights consistent with this 169 | License. However, in accepting such obligations, You may act only 170 | on Your own behalf and on Your sole responsibility, not on behalf 171 | of any other Contributor, and only if You agree to indemnify, 172 | defend, and hold each Contributor harmless for any liability 173 | incurred by, or claims asserted against, such Contributor by reason 174 | of your accepting any such warranty or additional liability. 175 | 176 | END OF TERMS AND CONDITIONS 177 | 178 | APPENDIX: How to apply the Apache License to your work. 179 | 180 | To apply the Apache License to your work, attach the following 181 | boilerplate notice, with the fields enclosed by brackets "{}" 182 | replaced with your own identifying information. (Don't include 183 | the brackets!) The text should be enclosed in the appropriate 184 | comment syntax for the file format. We also recommend that a 185 | file or class name and description of purpose be included on the 186 | same "printed page" as the copyright notice for easier 187 | identification within third-party archives. 188 | 189 | Copyright {yyyy} {name of copyright owner} 190 | 191 | Licensed under the Apache License, Version 2.0 (the "License"); 192 | you may not use this file except in compliance with the License. 193 | You may obtain a copy of the License at 194 | 195 | http://www.apache.org/licenses/LICENSE-2.0 196 | 197 | Unless required by applicable law or agreed to in writing, software 198 | distributed under the License is distributed on an "AS IS" BASIS, 199 | WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 200 | See the License for the specific language governing permissions and 201 | limitations under the License. 202 | --------------------------------------------------------------------------------