Conversation
- Give every flag its own random suffix so one flag can't predict the rest - Rework ch8 (real SSH key login), ch9 (private DNS zone), ch10 (only scp/sftp uploads count), ch11 (flag only on port 80), ch13 (trace a cron job's short-lived output) - Close leaks in ch12, ch14, ch16, ch17, ch18 - Close port 8083 in AWS/Azure/GCP firewall rules - Update README descriptions and verify hints - Add shortcut regression checks and new services to the test suite Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 93529270-84bf-485c-99ca-0109bc533d3d
- Move the login-banner reward plumbing (challenges 8 and 10) into setup/external_rewards.py, including the ExposeAuthInfo sshd drop-in, and have ch08/ch10 use grant_command() instead of hardcoding the path. - Let challenges declare their own apt packages via PACKAGES; system.py now only lists learner tools. - Add CHALLENGE_DIR and DONE_MARKER to helpers.py and use them instead of hardcoded paths (ch10 previously duplicated the done-marker path). - Keep a single CHALLENGES registry in setup/challenges/__init__.py. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb6ef7ff-cd36-49b9-8051-47b519236889
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb6ef7ff-cd36-49b9-8051-47b519236889
Nothing depends on it alone: every readiness check also accepts /var/lib/linux-ctfs/setup.done or the cloud-init instance marker, both of which ctf_setup.sh still writes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb6ef7ff-cd36-49b9-8051-47b519236889
systemd-resolved starts before sysinit.target and network.target, while ctf-dns is a regular service after both, so Before=systemd-resolved made two ordering cycles. systemd broke them by dropping jobs at boot (seen: resolved and network.target), leaving DNS down after reboot and, depending on which job was dropped, SSH unreachable. resolved doesn't need dnsmasq up to start; it only forwards ctf.internal queries on demand. Add post-reboot checks for ordering cycles and a running systemd-resolved, which the service is-active loop didn't catch. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb6ef7ff-cd36-49b9-8051-47b519236889
Follow-up changes from review1. Split challenge-specific concerns out of
2. Drop unused 3. Remove the legacy 4. Fix a boot ordering cycle from ch09's Testing
|
Why
A review of all 18 challenges on a live Azure VM found that every challenge was solvable, but many could be shortcut without the skill they teach:
grep -r 'CTF{'without sudo found 13 of 18 flags.What changed
-type f(the old command printed ~9,000 lines)/tmpEnvironmentFile=, not visible viasystemctlNew VM packages:
auditd,dnsmasq-base,dnsutils. Challenge 8 is renamed "SSH Key Authentication" inverify listand the certificate.The test suite now includes shortcut regression checks, and the reboot phase checks the new services.
Testing
deploy_and_test.sh azure --with-reboot: 41/41 before reboot, 9/9 after, resources cleaned up