* added mysql docker image

* started login php
This commit is contained in:
david 2025-09-17 13:29:49 +02:00
parent 0d6e29b1e8
commit 0b086582b6
5 changed files with 36 additions and 11 deletions

View File

@ -8,5 +8,3 @@ autorestart=true
[program:apache2] [program:apache2]
command=/usr/sbin/apache2ctl -D FOREGROUND command=/usr/sbin/apache2ctl -D FOREGROUND
autorestart=true autorestart=true
# [program:mysql-server]

View File

@ -1,6 +1,9 @@
FROM ubuntu:24.04 FROM ubuntu:24.04
ENV DEBIAN_FRONTEND=noninteractive ENV DEBIAN_FRONTEND=noninteractive
ENV MYSQL_ROOT_PASSWORD=39gknzLD
ENV MYSQL_DATABASE=app
RUN apt update && apt upgrade -y && \ RUN apt update && apt upgrade -y && \
apt install -y \ apt install -y \
@ -10,7 +13,6 @@ RUN apt update && apt upgrade -y && \
vim \ vim \
supervisor \ supervisor \
openssh-server \ openssh-server \
mysql-server \
sudo \ sudo \
cowsay \ cowsay \
php \ php \
@ -59,7 +61,6 @@ RUN chown l33t:l33t /home/l33t/user.txt
COPY ./flags/root.txt /root/ COPY ./flags/root.txt /root/
RUN chown root:root /root/root.txt RUN chown root:root /root/root.txt
# 22 port -> ssh, 31337 port (suggestion) -> vulnerable webserver players need to find using nmap port scans # 22 port -> ssh, 31337 port (suggestion) -> vulnerable webserver players need to find using nmap port scans
EXPOSE 22 EXPOSE 22

View File

@ -1,10 +1,24 @@
services: services:
db:
image: mysql:8.1
environment:
MYSQL_ROOT_PASSWORD: 39gknzLD
MYSQL_DATABASE: app
volumes:
- $PWD/config/base.sql:/docker-entrypoint-initdb.d/base.sql:ro
ports:
- "3306:3306"
app: app:
hostname: srv1prod hostname: srv1prod
build: build:
context: .. context: ..
dockerfile: docker/Dockerfile dockerfile: docker/Dockerfile
container_name: "ji-ctf-dockerized" container_name: "ji-ctf-dockerized"
environment:
MYSQL_ROOT_PASSWORD: 39gknzLD
MYSQL_DATABASE: app
ports: ports:
- "22:22" - "22:22"
- "31337:31337" - "31337:31337"
depends_on:
- db

View File

@ -26,15 +26,27 @@
// add sqli vulnerable login functionnality // add sqli vulnerable login functionnality
// ?? // ??
// profit // profit
if (! empty($_POST)) { $servername = "db";
$name = $_POST['username']; $username = "root";
$password = $_POST['password']; $password = "39gknzLD";
if (empty($name)) {
echo "Username is empty"; $conn = new mysqli($servername, $username, $password);
if (! empty($_POST)) {
$name = $_POST['username'];
$password = $_POST['password'];
if (empty($name)) {
echo "Username is empty.";
} else {
$sql = 'SELECT username,pass FROM users WHERE username=' . $name . ' AND pass=' . $password; // sqli here
$result = $conn->query($sql);
if ($result->num_rows > 0) {
echo "CONNECTED" // do redirect to upload page
} else { } else {
echo $name; echo "Wrong username or password !";
} }
} }
}
?> ?>
</body> </body>
</html> </html>

0
www/upload.php Normal file
View File