Skip to content

Clarify challenge 10 upload target and test with real scp - #128

Merged
madebygps merged 1 commit into
mainfrom
fix/ch10-remote-upload-clarity
Sep 24, 2026
Merged

madebygps merged 1 commit into
mainfrom
fix/ch10-remote-upload-clarity

Conversation

@madebygps

Copy link
Copy Markdown
Collaborator

Fixes #127

Problem

In #127, scp didn't trigger the challenge 10 flag, while running vi on the VM did. I reproduced this on an Azure VM (Ubuntu 24.04, OpenSSH 9.6):

Scenario Flag triggered?
scp to ~/file (the command in the issue) No, wrong directory
scp to ~/ctf_challenges/file Yes
scp -O (older protocol) to ctf_challenges/ Yes
scp overwriting a file that already exists No, not a new file
vi in ~/ctf_challenges Yes, with 4 banners from vim's temporary files

scp itself works. The instructions didn't say that the file must be new and must go into ~/ctf_challenges/. The hint also suggested just creating a file there, which skips the upload.

Changes

  • README + verify hint 10: Tell learners to run scp from their own computer into user@ip:~/ctf_challenges/, and that overwriting an existing file doesn't count.
  • Monitor (ch10_remote_upload.py): Ignore vim's temporary files (.*.sw?, *~, 4913) and show at most one banner every 5 seconds.
  • Test harness: deploy_and_test.sh now triggers challenge 10 with a real scp from the local machine, and test_ctf_challenges.sh just checks that the flag appeared. Before, the test created the file on the VM, so the upload path was never tested.

Not changed

This PR still awards the flag for a file created on the VM itself. We weighed checking that the file really came from an upload (with auditd or a process check) and decided the extra complexity wasn't worth it for this challenge.

Testing

  • ./.github/skills/ctf-testing/deploy_and_test.sh azure: PASS, 28 passed and 0 failed; resources destroyed afterwards
  • ShellCheck at CI's warning level: clean
  • Watcher logic tested locally: temp files give 0 banners, and several files within 5 seconds give 1

Learners who scp to ~/ instead of ~/ctf_challenges/ never trigger the
flag, while the hint pointed them to create a file locally instead.

- README and hint now say to upload a new file from your own computer
  into ~/ctf_challenges/ (overwrites don't count)
- Monitor ignores editor temp files and debounces to one banner per upload
- Test harness triggers challenge 10 with scp from the local machine
  instead of touching a file on the VM

Fixes #127

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 8bedb36e-e2a4-4e1d-be3b-922b69a777a9
@madebygps
madebygps merged commit 6642625 into main Sep 24, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Challenge 10 in the linux lab triggered by local file creation

1 participant