Redesign challenges for unique skills; fix hints, docs and test tooling - #133
Merged
Merged
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 713688f7-85cd-404d-92fe-f94163885359
Update setup, hints, README and test solver accordingly; install bzip2/xz-utils for ch15 and restart systemd-resolved for ch9. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 713688f7-85cd-404d-92fe-f94163885359
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 713688f7-85cd-404d-92fe-f94163885359
GCP resets the VM without a clean shutdown, which lost the reboot marker. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 713688f7-85cd-404d-92fe-f94163885359
Nginx's misconfigured listener on 8083 is only reached from the VM in ch11, so no cloud needs to expose it. Full test with reboot passes on AWS, Azure and GCP. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 713688f7-85cd-404d-92fe-f94163885359
Move connect, capture flags, verify commands and finish steps into GUIDE.md, add a quick start to the root README, and simplify the AWS region steps. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d7ca812f-6f5f-4846-b188-475430b77721
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d7ca812f-6f5f-4846-b188-475430b77721
Make nginx directive edits fail clearly on unexpected templates, centralize learner artifact ownership, scope history-file ownership, and clarify the cron challenge description. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 80c0c0ee-bd2b-41fb-804d-9b865e59da2c
Collaborator
Author
|
Follow-up from the challenge setup review: commit 9ea3e65 adds the agreed cleanup.
|
- Align challenge titles across README, verify names, certificate and test script; README table is the source of truth. - Add a module docstring to every setup/challenges/chNN_*.py. - Rewrite all 18 hints as nudges that point at concepts, not the exact tool, field or flag. README Skills column is concept-only. - ch11: write the broken nginx config directly instead of patching the default one with replace_once. - ch16: five-link chain with a relative ../ hop and decoy links to a fake flag; README says to start at follow_me. - ch17: three users' histories with decoy secrets; the flag is in a curl header, not an export line. - ch18: test now reads the label without sudo, matching the learner path. - AGENTS.md: document the title, docstring and hint standards. Tested: basic run passes 28/28 on GCP and Azure. AWS and reboot not run. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4703c39f-f11c-4c63-b095-09708ed6ff8f
Collaborator
Author
|
Pushed 53bd408 with a round of review changes. Consistency
Hints
Challenge changes
Testing
|
Collaborator
Author
|
Draft social post We just shipped an update to our Linux CTF. Want to get hands on with a Linux lab that will test your skills in under 9 minutes of setup? That's the longest deploy we've seen. You SSH into a real cloud VM and work through 18 challenges using nothing but the command line. On average, the VM is ready in about:
Want to test your skills on real sysadmin tasks?
Free, runs on AWS, Azure or GCP, and you finish with a completion certificate. Think you can find every flag? #Linux #CTF #CloudComputing #LearnToCode #DevOps |
Track deploy, ready (SSH + setup wait), tests and destroy time for each provider and print a summary table after the run. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4703c39f-f11c-4c63-b095-09708ed6ff8f
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reviews the challenge catalogue for real skills, correct setup, accurate docs/hints, and no bad practices. Each challenge now teaches one distinct skill and tool.
Docs and hints
verify/src/verify/commands.py) and README rows for every changed challenge.Challenge changes
Acceptedline to find among 50,000Failedlineschmoda mode-000 key pointed to by a world-writable configvault(password login disabled, flag printed by ForceCommand)resolved.conf.d, resolve host withgetent hostsEnvironmentFile=, no longer insystemctl show/catbzip2andxz-utils)blkid/e2label)Test tooling
.github/skills/ctf-testing/covers the new challenges.deploy_and_test.sh: after an AWS stop/start the public IP changes, so it now asks EC2 for the new one.test_ctf_challenges.sh:syncbefore reboot (GCP hard-resets and its root fs usescommit=30, which lost the reboot marker; reproduced 3/3 withoutsync, 0/3 with it). The ch9 solver also no longer matches Azure's owninternal.cloudapp.netdomain.Testing
Full
deploy_and_test.sh <provider> --with-rebootpasses on AWS, GCP and Azure (28 solver checks + 6 post-reboot checks, 0 failures each), all run against the final test scripts.Also verified by hand on a live AWS VM as
ctf_user: ch8 password login is rejected, and the old shortcuts (cat,systemctl show/cat,/proc/PID/environ,grep -aon the ch15 archive) no longer expose flags. Broadgrep -r 'CTF{'can still find some plain-text flags; that is accepted.Notes
main.tffiles. The nginx listener on 8083 in ch11 is only reached from the VM, so nothing needs it exposed. Full test with reboot re-run on all three clouds afterwards: PASS.commit=30). Not addressed here.