From 34182b992942305da8257a201b3b11f9ddd79c85 Mon Sep 17 00:00:00 2001 From: chest Date: Wed, 16 Apr 2025 19:33:47 +0300 Subject: [PATCH] feat(web): path-traversal task and flag accept --- app.py | 19 ++++++++++++++++-- static/imgs/cat.jpg | Bin 0 -> 23725 bytes static/imgs/flag.txt | 9 +++++++++ templates/path-traversal.html | 36 ++++++++++++++++++++++++++++++++++ 4 files changed, 62 insertions(+), 2 deletions(-) create mode 100644 static/imgs/cat.jpg create mode 100644 static/imgs/flag.txt create mode 100644 templates/path-traversal.html diff --git a/app.py b/app.py index 237b0a7..139c9c3 100644 --- a/app.py +++ b/app.py @@ -83,9 +83,24 @@ def websql(): def webidor(): return render_template('idor.html') -@app.route("/web/path-traversal") + +@app.route("/web/path-traversal", methods=('GET', 'POST')) def webpt(): - return render_template('path-traversal.html') + flag_task3 = 'С4Tch_Fl4g{Y0u_Find_4_littl3_kitty}' + if request.method == 'POST': + user_flag = request.form['user_flag'] + if user_flag == flag_task3: + return render_template('path-traversal.html', flag=flag_task3, success_flag='.') + return render_template('path-traversal.html', flag=flag_task3, error='Ошибка: неверный флаг!') + filename = request.args.get("file") + if not filename: + return render_template('path-traversal.html') + try: + return send_file(filename) + except FileNotFoundError: + abort(404) + + @app.route("/web/ssti", methods=('GET', 'POST')) def webssti(): diff --git a/static/imgs/cat.jpg b/static/imgs/cat.jpg new file mode 100644 index 0000000000000000000000000000000000000000..8216c40bd7318f78963ef30e7ca4523d4e3a4459 GIT binary patch literal 23725 zcmb5VbyQo?^Dmm>S_m4P1a}BhN|6$R2Y0vNE`=6rae@c;7I&AnxD!for-BqH6iR_o z3KZx~zrXu?_xHzrZ>={c+2?a+&zU{5&smebXHEXD{@nynYN)8I0Pfwp2T;QvfWO-~ zAax}r8(n=J6?KF%wgUjbAp&3tPZR*~^a}9PSB0^gnwhf`ZUXLMkN=RJgTK#zq5o@( zmAY8|FWCj5|Et9RHX zn?I~REJbYq0CN3*|Nia%KRk_o0HEao06_Bg|L}OF0RSK=0D$=)y#F(&K6ZX~|51mB zZE>8O0D!Y90D#;K0HB`5>aqAwAGY~_@r@nZ#f-Jp8+$loeRIUxtd6zU0U(S;P=F{v z3?TLQ13(FYhl~5~gNKWUkB5g(Ktf1>C30dCA`%L6N=gcHiu*un5Dk!up6WgYEi)}W z0|OHi6D17`8w(>Fh>?l$pOSlc`1l0)1Z0GSWQ;%xAmjgU`a1*w65$ZvyTrW*0pI}d z;R5gd9l<&Pz`@17$M^o**?*UK_y7VzB5W_izaA|8Kb_d8i-Yyz?>c}C_Z|R;5|$foHD$juoH&+0K#o>1e!-z%2v%QoIsRezZHMXo=39#GkH zV_uQmK3J_^?oCInA(_}~>CyA?qM|)XFIN&Q1+%PgLd5n2%Sm~>RVuTPgoknRZUPcC~|V*1p#LzKYc7>q05W|`@HXEnd6u*6CWW(lJj$iQ7qm3_~>p9(RXsV zCOfFFkV-0ISs(h$Re#E-T&!49q%8u?qbsc&ZnHnz*}eXy^%O4z5kFW&o2jZzJ@czL zDV+8GOCe|nWha?RYU$}+YWXiA ztIz2TVKP^JVT=-Og`XAOxnF4~x#dwV=8_qBMC?xmW;-RhnO3h=rGKxkJr!2`SSjJI zpIxPYC@UddsXqp4Y@MhTYv4w~33`9CUA!6t@jQ#J+t$%V^$b!NNu=k_noS_N9*k9kBY4HhTXMwdL3`RWgA zrs}eU@lEvXr_N~n4W&aYTTA4k9L0K9|;8yc{&`=pYc+B&b#oHBYD&9_8&^UCL}05Ix@eT(Q(C2>)sAT^ zdGsm;wJB(_+gxV9n5Y|6fBO0JjPHu&vJ_9n+1gu4kEOS|h>tZdV1j%J9$M9o9hP4$ zy5pD6PnDN@mp1An`q^q5RH~%D3f~2xDd1l<3szWF;QGg5wTW{h%__4hp90j$qDv{Y zoF2u*(VV_FBYa2lCe4GNxdnkz4I}+(WB7WlsJLt9v~Oj4`-=JdhJs&ne9Onjz=qae z-#Yy|pL~)S&yHDgU|hFybhaF|!aufs@YvtYl6Df-LpExCKV$M9{$tEY+Mrzr!i@;$ zMS?9^#_+Id9s_?ONK})06yVEU6#R!cg^{2B_w(qmz71vnVeeYEuDd5&p;euy#(GGz zw#tD~=i2l75DVg*2CpaXK?YuRi8%LLj4X=;_#)W%l9>zVo=n}BmraAe!iHyNW_!4f zkE{=wc#WSD;Se(56knF9PW|bD)L7m|l~MTIm+-vZ-*wKDw~vObypBT`_TQ{zpIN^q zfi_sbrWrQjfGs$d=C@M|DF!QxLb&z|0%GuF^(@T7?SD4Y`3@sA-HK$N5eeH$Z$l{J zw-Z3}5qV#_%TsKD3rp1Vl<$YiF$CkLe*%JE2Zk2EJ(9TjUDM#cw%y0G=Ik=Ht@m+e zQtFfYX_2baSgedoeTA#uyRLYytYo_~eFxn(6wBjpiDvo371hlC74q_J;{nW=315IN zoMFD?Mwn$b-T9v2mgP{zuatzThcX~X3qg{nN@))-s>7S;0+m^K2m5cSK+Sc zF{L)Y5@!r`7d6F}ias7Q%L3kSzaU=`8Z9zru%h4anzuox>V}&~-#}B^=Z3OmP9_^FUKDOgx?$;^J*HM!MvlRGw=CA? zRQ?2R{LY$^)Ka;b+}GPxX0$qw+Ki?m{0x)`1}**WAy^1T^u#h}DxOhv1Qb=-me+j^ z(|)$Izjl`4Iw&_$Yuqlrgz+FYVobNHF@<*5?0Hr-1Zo#a);y7@I8^DYb&&Rm4S3!;V0Qn&OiV1Fx4A&9C+F?->%ngan>EH04Z@#cwEW@~S4Jrn zxl2SA6}?~D-Pg>9<{B&>O0_Q-1&tc5s|1-DuVk4oAFid2j%T*Cf9`P&GnfeD(7#Aq zCD2x+^Q)~`;z_^C`6S!Z4@%WRO)oOZ6_|U_)No_+f?Vn}e;Il23opNg9Jlh6>X|__ z&R<%TR?;mCuH=rM%LhrlHmYHgUKs`-eTH;S2b9?XEkeRI=UmI5ly-R8SxLPxlQgyN zG4J@kj0hKQvawmBD4WSR7Jp4s-pv@F2O)CA%Rjbn8yUL#x)NG)wrg3JtQxTQTSpLa z&9Wn3A|E+nn^}aroOTjrv;?Hpu3a9V!{opJ$(lH+shu6`<+!pZVcs~e&F^lpw!EEH zk;->0(bHdNe)cZ0yJRoOytz_@)1)(ltzdlFT<_p#H!Ls)t@r<%?$ieUTkuqWi3fO5Q)IOuIcT1S9 zuVXBzQLkxjULz1O@Md=r0d!uv((1bKFiNa-up-}Q{^EFw|N=FH4tSL8a{+%7KD@m&5SB=$$d zp!?F=o8MdoUwxn;a8f(~6|?4amkw%fmf64^*dER88dG_28RWDI{0!Bpx+I1wYFH?m z?(%^$V%1DU0edR1%o>0F>Z|)2KJ~)H771iJdrDUGmM<2@Bfcp3d zF66ya`FlI6loKE2;M60&g1qr5DNO8+ezDe#TDeBeKkL@C$XU#bRX-wCC+n`8Bonm; z>OY89snQUQq>@^wWR3#87oJ&3Ub8PX*TpC6-zPJ-l*`#yls+7_^tJjlLQKSN$!=+H zzM8_mmCj6)O8se4j>Y*NG2n3qE}kmRnDSBkDc}6LdFWrjS_=2q@~X<74Tf#`oS(<$ zKR*o%O`~2I82gx7s=q2Re%84Ve8k#sK+ zt+C(S|ll?(fBsuB$BUx^U_O+(F$IJTaK#n+{Q$57xy3vs!Yy#X2j`SacA- z-1n}$@y}C9XRIkjOh(hBBjR@t11t&xdsCua49=w%9<|gSW(gS%fCi+eO6JyHhPPG) zewF)#2jykArwF*Gmlc%X_b6zWPN~;<{`+N&P7l(g;Nm6Euj~+~rH*{xxkO@_Its|%+y+ZcQtlYf(*4xu1wg2(( zeSvySJsH9=^yli$Z>FD1o+e*w1$v$tK6}rSkOTJc(Xa@&K5pDaYA5D~SvC_?e43v< z-nk`xSKLGTq5_@vD1o15bl&)vyS(%6OZThqA)Y_t!XUlu^A!&A$iDz&a57F3P~$FO zCF_b}@lG@4tDuO&90>en-}#;owLlCO6%33 z*!!a*p^jMTqhYfLrCn=^ON(KJlOdA2Gfg!6$r`rS2DG>%a z^F~&0Glnk}x`q3=de8sxWdCv$8=Q!rX)AvAGAk_TYvC=ZZE)ur{ZaZjl*OmtVkgX| z>Fb|LV`p#XrYxeFu=|18T1WL{;$@^p!lu)0O%{P>CgcsvjSNe58a>Cb@7gWS&*_7g zTRf_xXy1L=`E$d0%WR5A38$j8Y*CH%itOL^h_)_#+npj(?q`(7o^RoQM?z-Nsm@0O-l!dZj&Fm{PDn{W8~b6ii& z`4u4*2v6g^?3~{FUcHKgg=8_9?VUemfL>;ehcAX9u}}S<1`8eoXLmWs!<6E@Na>p1}e37oIYw z_SFe#Po9t@8^*_JE7~@i*9lmelA*Qa-{UQNDMuORlx0!P6;?xsg&Il=Xx~aqe{lMC zU`{G}(!2fV>1{vDC;M;fb%usJUZTN#2@opohsN=I6|W9ANfO?zf3Ya?bcN%Y)X}+q z{raKKMj?IY)n+ztm#6DKK>@yh7uZ-_d0@JVNJx80;JrNfvOAd8N!+k8{jQO?_?5uE z_!%dM@dD^4i>|g zfQZs4Ld74`a&Qu0_qIgX9q&DSoWFo3E^+?mlDEJ_W@tlG;;}#TG%U9qIf2>XK=D#n zK;IGSEjX(eag?V3MbQ#f48kIJ7+D#|4E689nZ(Ox)>0`SClLPB;$2Qb2+Tz$sT&tF zg$D@_ZbV~U>TPx9Qwed%4YQ`6BkX*~AM<-`?E^RBJ7!`hSsUKIn@LrDz#{%)dA;LZ zl)_KjZC~kJ)d*Qe0TRK}!teGBuCWftq?D%*oxS&WzoI8yuE6&^dHLvEGX$$rR)5ZB z##NweqLLqq{{;|`fi?&jhE!Ex<##d)srOXcP23VoZ_;x2W)AWDzjDR2g%kdm%eY?a z&ESV1cR29&4HQoI?`VA#@E%a_l+c&o&L9h9{A2{p9WD<@stfI(LY+J1&-=dp8aYT$ zjWgMOcKdo0smDh&k+Kel2tbBt%(!0_eJNHIq<*ukBV#kSqlaEdt4?b#T^J;x1)n@j zaTZV8@DoL1DqXp9;GtCZXUFN0y=R{$okn-8W7^iBkz&$m4GE%=ZF=alv>UqqF=N}^ z43l4{olICWs5l<)zbG+(Xq-~}FweQDZ6hOZNv6v55c(j+jB}0btI~1PsXy~L#y6pLh_dOVl@IXi5geu4ODcqEaP@iqo5w|Lx z$8Bozl*<2BOM)6yzAw|Lv2y37ozw7tSCmv#pVd0^dL&XPujVg6$w^yPJa3VuN_P*b z{Nzk1j(#<*)Zs0&pLE*@YQsLP~`0I(LEyO+ljb?i?b9d1Yc|Xh^$q=~17_ z1rgTcUKYH7@wPnGDxNaA7Vj2c&HnXa)J)zgFJ?Q9^2uV=r0n<&?1=?&pfNkhiK4}3#hN-^cPD*pRE|!OxOJSeT?toyV&7{> zDu*JbZ~@V1bA~lp!j+#6pha-ee5mx7RFkbj9c=p{@}u42*Evr2IsK`+A6BU_*MYZf z@V#7?&A;{Q)F*9uSXQM-9+LK!K*YFXsJf$;r+Kn2z_dlQr$2j#2Wn1QAE0x9@1T)Ew4w*IES;I~wpxaU7}*gI|9{9q!1OwRxzS zR@_m>rGk~)d5!^Q#rVmOz~7ektSP*Jr_y}1hG}J61DSdXxK65K@BL^}oT2)x?;tQ# z1Y^Ztz|{4L?O+ts=GX*?kw$Gfpfq4JV2)8^SH@=Ct@NwIh*hmJ>KC6)avqtK+7Gr_+A424-nMqVrmk(CFv-R6|bivYuwJ{bM##%fHRiz0aB$D5cyTLWB# zn8B+=CSZJJnvIA8+z9BgiQnfnX74 zsAOl|A*b!ws;KZsW<>bMA0T85@50VY-)ymj>aZZfhEx4Y)i z>z2+3L9)yd7g>RCSYtcoy+WS!{r zQ|4A1`8?h_b=CM-@jR9;>5Kb?oQH!^gt(~WX4}CLwLv1;eR+}E^LGA{)j8=5l;cz33CDTVO~g0Zvu_z0 zrD3M)RR+-6o8lNqw~v9BKAIt65OEb4zX8j(tRc*1N9c*v9=O%)Jtdq#ay%=T$j@8W@I%_8SsMn z+8dv(A(AkfPOlwQIvmtlIOsCx542b;A?TDnEkE;5jQRb_gYTq8Z3j~pTU{i+_e%1M z>W#Z|PKad)3yHvU;%BD3@2`SqP^6r)(r=!5qh|O!4MZ5$bnpZrXR%`Gk{bq>Ri{(J zML#P+rsMvf^(Lz4YgDZ&4<1}g1T$C&v8Gmm>Vq(7ZmsOrVLf>sdCi62Ak9L-x-)A+ zS(1+#mZ@;3IqO%Yq3_A`2eqnNzJtpw`>&)~Ao-Xkmin-yE1?Ja4-|(iN>Gd}xP9hY zR5ikTPwtoX!HF>0?`KZu* z$=Ohk#ng{^LTHM?sb{B2mq)eM0d4O%JELRP8n4|5am48Te{5TrNY-2)Yu&&(3%>7U!L*?&9meZEAi%jBSgeD~iX| zmZzvLYuPRZn2w5gQV=QjuwkNC+4F&$-dcPd$CDzVz~rOU?Y*K~+_LD_JW+EqB!*AJ9zfHE=*zdNY1*e6nebs9(k` z{2`mu>u*9Y_Xo=Q5P2I4ElG>PReF&!qFs){X^Bup3h12$VlfQN_7p;AIDH#>j)|IX9IU4UAr|TJGzE~Km z55KFwdxL!P%x9oniR?*w992g~WxRd>i7~y`>u*Sl&9K~cL?#MRT=6*P-4d08xJAIB zd$T^Kdkwpm0DDYs!<6JrCQ1_aeNJm5>Xct%M`ST5aF_&Va%)c5T)~=HQ{b#?bk`fz zy^Z4^xYe^Y$1#V`Q!E-ff0Gl`F5W%RGkbUKe7b&tG0S}E?xe2f2lbb!()H)*=qe^? zGFW-7M5f#8X765V+VdvmEz3ia%3x|0>|#&zzW!a+YmQpjv!mrOLREnDRPE%iXoxkEO~=MaOXH2l zO!|UA_2pl{t(3vuBdCF3FC@6!tS(72Tpws0+JkbhZ%$56y!>vXn+SP~#!GtYc-IG0 z`)5OeGB^Kht*YiY^>uBir8BxEDd8uL(64?yigU4S_*Hy38`-7X_Fn+-J9c4fVl-?} zmcx%oM_0E+u7pOveGc`=`k8knX2^e{6|O)pU-aur52-#mrBBnNVQOBdg>2o?=qUmf zLIThWz8p^YF8$zvoX7&7Cn?U5exX2j`BLmEPJD;=+e%L5Vrby&ChedVE5_Odqnje* z{65;Gyfg6;?;HVIXIv&^cy$hGz}XEu(nEisL8yDIG+a`jOUmCln?JXXhcHHO9H#*8 zoUXg0c>?*_hJyPDPkAriia43EYVPz&%pHC$&o0>g_Vzh@LH(CctG~N zkn=?U*pCa<74MpT&##sY89d-sGuJ0EeKvR+<TxTPUi@7 z6*GbJZpnUw^WNME!^)0+LMGC11p|2Pg4^D=ON*mm9aIclKY;4BeP8(h-Dj#k=&ppvPra9qM)Y{85b4pl&lsL+CwD_iW zDBA~{h<+;mx=bTxb;^4w@x%4e^!w=$Y^66=}VNU?mk-6jYz5Z&X?o0AbtCeIJPZ2aWCX#M9*%sT@T{*XM63yj%;E{A5_ zaR}?YeMx`(2$8|bwR(|LXE&k2Or$f_#(&0@^8TuB88f!NQFD;k(VJKF(n)1PZF-Fh zvKJbK&AH-l+=jXh;^^R&LlJ7e$1{mwOm?9muqowgo$@CI3-&fnp&VrI?;XtQ>gtXk z=Z%#UUE5S*Hz#$$oWWSTnFv+xo}Wxq20KI*cy#-q@4yYBS&>=Ci~6Ir1id2ESIq)L|fppgO&5n;zps^-?g z)oCP>8>5NSyyO3nVU40&i-MdP?!&4__WBI?9HJ^vTvCE zxJIr%Tt8&=zli~Kk`~qZr&X5`{h$o5}6_wA#XUY%IstKvC4et7u~?k zy`*pPM-~n@fYe{bV8v?RdID1Xz0dWGI8jH;%y-()xgO%j7$PNTwk~`&X_y}ub`|Sg zOxM;+FX}1NN(V_l!4seSEME4dP+<3X&LI`91B%-DMlDAul)&5Ig*E=Z;HBm4-VIUfWIk_c!n@{h(y7gsaOID0 z4j)8`Na>k(rOsW`e`Nlg9VVYCM7BGTV=t|><(EjOX0MQUw(pZ7r^MjDW-8S9EWqy= zI9~0La%wHCbp17{rK5SwAVhyUMC9R~~)dyI>H^1A*lcvKKSs2+!%uOiIeA>w~083`0{W|<}J(DAH| zYj~}9k|+lwe+M@dF{zIEc$Z>A%ZMr#JNyOU`znF?rQ;3cEP(-LuC z^sUSur=?}hghtWj?KqrLh>yGP2dQba*T_awLY_(W#l52CAY?Q951@{>9z5x|=!Vw%W7zewT@Kgypa7&vBMk6I8uTG1H92A7&3x z&7E{ro#(QCR8()HtBHVlj_)qBxcb(c)ih}$hF)Y6B|gANG`b0dbyz=cMQn2A8|nf} zUVktFk@7!2+aZaS2>j!=U0wYuAWUWb%`4kq=s~jMGFMC8ytHf($^aHu{lSC=VM=sf zjAiO|yjOZx{E#bS(NiEnosfO~9`YBH#uuA!Qdwgu0r+SvJDH&|^bGS&YH2KGRBzF< zF8MiD0V6Pq^>Mckyr$t|X)HSEF4|khJ*>mG{i%efVdSg^)UNfJ>iH`EZQQ^aS)qaVj* zTg21R0nKm(W|-T$k~@400Lr53+PIW>Pb+zXP^oG0(SF+58=jWV^0XA!)Gr2ynIgwl zzoO1Ou|~O~<1sYO5mtkJgLJqP+Tug!a{oqnA({65zK_@$HA{68VQ^LSnMUV71&;@d z@}yl*xi_(c7^&DbI_wNa!i>C=+k`HbM)hX<2v|+}9I=Maro^<#U@a+O@z(2Xl%$*f zH!qO`b-~FMzPgU6c+JPynHx2rOgp>J32MJz{ui*^$hT?oEQ6TXCHtj&r0X`Ds;V~1 ztgF9B?5A^#apKF1oV6GsXIkFv-~!7_>!0nNhNS4vorSXN&qglChfnY z%YQQWK(H94qMn^^#0h%|x@BqMfONotV!=?OqTM8f^?OBRN7Rb4rUP8*jaaAH?uj;W2bwz! zRmmI80j{2>yavCTN*k^SO$rg8M%f3e=G=Ud7Yl&-o$H@ItKjpN@zGS>UT_QP z@S^+4U%<~SYQ9QtIlqn5LQ`v=hja$=a4Aea<8Scyx(LdGeT`g4%Cj!2rU-K%XU}?& z%W6!kao#+yS?fnq7FauthkLp4AKFa;T2hj{PBjddiW`bx246ewoZ93TKgvMld?tqk zEH(&DF4s?Q=4iN*_4Gd_*&_#_#y005_?YPJRvY*=*ZDNFT?(u`9L7aqFy4aSmdRCyiC6Q@*ZbqAQIg2CjCvUy`xSs$B-G+lF!?tG8UlT z0=>}W(=<)1YvDTLR~=6& zKnf}InL$;TI4;#_;CcM*JZ*i##(wQw;!c#2;>s)svC8dqo?ZW(+W9KX25rL3g(k^9 zH<#dNZ-*F=MsEqU?aIYNhmx&qD;X)IjO%K`uq-?d;Ra-6>e`ZqZdcL~ z+6QT%4OB>M2t;`YE?eHFwVkMlEvre5ld~v)+XW#8r;Iox->4KYA*B+zvX{*no{Qh( z-EA8}k#Nz)NZ50dE6WirkH{wba17I_xir56v-nJ4riLHV-c9GeuN>J%~h7@4p$wbptVH}!`yM9hGy96du8G*iy-r_h@Q{crf)Z86;Sq2(CvN&2zHGtq`}yN3Rksv8mxI$Z|_w z<|8I0AMcp-gb}Ghm+lnJm;Usn1JYCE(n>in8XSd3V@*dMC~l*|LbICM63=PDOfRYw zQ_}uo89f^b1mfL(en}Y({XztTGSXv8TCqbE8bGOp&~v+3Dt8tSyFt0^-Q$6 zLY(7Hma)}2aW2TD{3!z2RN{Oq;-@5m@#j!h&LK-lZ-|M#q2uaI%ZKe~75TVFlyUo8 zY0(hYW}BzQRK!r)*_Wvc(L8Kuuwtl=EZK9|BT>h)J;ZqOHRv;qy`$m9t3|r1stTIe ze77{s`3KZYvsnc|m9J$(9^fUkQMTin)K)k&?;~WZIw6Fw2mHWgu!Id}Vjmzlk!8vt zC`L^M55LRJ^OlGf-%2Hl*S1CDQE}m+0u#{13A@FNQ=AE2(uvB=E{!@Rb?zLN`n2z! zJ{p3eT8DI;q9nc{GC|!86SfJG>_rpkj?zf$IdX96VG=cUEy2=WYXG=Lmr& z@fMfu8&1fRPz#+#!yz_9r1+r1$iN3?OlVLJP6%TcL6C!5Yz^h|=o+JTf|6GN_gunH z2;O?8r$Wi=TMBmL4f|hmphs(_(L$x_o1dcs+Qq(;)$BV~si(xxW)5@P^he>Um@(Z6 zmt6wwTp!L*s{aL0rrT=FSqbeUG-BT6BlO`C7?j&Go(TuZZ0B^mM>e9dR7+Y?Z}2*6 zwXeT4*(0vS9md3djgqBIir-I#m+;FoQz}+NbZ)=HFiQAC-RkN~1+xsp1e!$>8QTJSlT3MB(!$)LQoNqR8?epHgG#HLKXo~ z561j@&CD)c1m;!R1kDYFrTKQWY8cz0BjIxb+=L4FU=E-h>rC-EWL7ks1m3wyyzKAF}?)Y<70#(x13?yEV5>^|^0 zmCOtAO($1T(PbSx&Xd(%FAH=pIkAM4>JCWLLy09q674`nonX$Z`T$!7Vo~-Hh}Hv5 zGEoD$F2O{c0g6q!wFYFS0=Uu9FQXr<5QV0qP;y(pM5&^Dk<*fr?c79$Z}-b!W5#I4 zNbSVsXmt|xZ}j?@=08UWKFs)=AzQv;QSq=O{hjUrL~OQG8qN8cq;gyi28z-R`E&7-KWXv>kh550N!tu)w*G12>HZ=T^-54>KW})6i>aiIrkX ziRIGDixI~Q2+u0DXI+e!V+cs|Ueq30B9|qK%AR>U%D&16wL-u6MCrivi(2@N2#c8J z3D=(Qi%}*pIT9mm#F$N)nSlfnN$#uEf%f&a)K54}PqfJAJ6bdC;&=wzSGD4U9T4q` zNyDWPb`){da`OzkAV*nr64!F8#fi8%WBwng=6;KspZZ+V1C8Y5ah2K$R$_^_@)CMu zB9!*>%0%9q2A13s0`~5NE@ef~!93kL;nXN)Pz4A^CDuhs=q5!z8>g89_UC|ddinYF3nA+cwl5(7>_;>mjJl1hDXfg_&Uakbq-7fc?@Y1_aI zWgQ1~mxPXk7xw0xvm@fq)2Romd5$jx+Et^Y4>#T8VS0?1IpPuaxkP)nd;)ngKHKO& zl=azS#J2I}RZ89wGml)E(yMZ(Uc>L+K>3tf_d8WqRpM3V;@@l8dXjJcwx8nF;hD=H zggs*wYt}zyt7~DUOnpZ=C+!$z8aKj23EP0Nnsd1-3^Lsk#7LX_s%(xS2JA?cf*t=b zBuSC8y%X&vZwR(%m-68-d&CIdBIIx}RT%^7wf8{F&XIFfv*(gsY8blHr?s|EsfPS6 z9uSOOmidj1?4et1>y=|w8_7#c(x+&R3NFc0IS`7FrolwIF)M-u!8&kOWcZN--QIZ69-4ZFLoaGL@PwvVBRIFiH%ef0kNhBd*Q%HyEtc~n3#>zP&8pk*PK0DBiWjH$rd#X~=I1t`$%!arLg$6Ge8$b}HMxE*Hz= zKvI_yDe{by;#iSZkeA}D-q0llCuj4h@TmxGj-ydSxg5@`(bZj?a}T`}NuQ-KmR7=0 zOl4gA24+fH5h-TL$J#L&?c$gRCj-gnhKys0qK@cl@QcyQ=n{{84OnVucaSR$mR54Z2fjMzRn|CVO{GBxZ?^I0%nP3y9G0O6n5gqJr2cg2Td{y3Pr4bxNs2u35 z1hYqPx#tYSV3y<|RMiiP;;vY&bHtaDu;d8_ zsjM!nICKKlnYrdrg2d~+G-)G_nAp<06}tif0v5_bs6Me|YXu=4YCjT~#w4Vgk5djY>DCUBuqjGiYwMq%)V0P*<`ypqn5RC5dEzN*QMP zFDtltD=G-R<%n_%nP96QRZQd9HPkd4iC~nM6nMm?w1O;R@>(fy{&II}$oUfr-9kPM zso2dAv3T#EE9nVONP`zyDmm+2bkyPs!A;u9X<77;DfGF<6qBVqj*Bu+b-H<6h37GK zBY8}{EO}!dx_O1I@tj>Lv`Rtw9LDVEEMAJ2vM$<{Z)n<7M8otr&0UtRQl*!&vIu4= z63K@cUeyrTz(XCS+u%y&K|G0#3sf+VR#xxU*wHn}?P>L@NbQIF?g{TvL9h_6ea{_c zm&xFf^q3@~YiObk&XWY&YcA5^jdjfLX_DCYeyg)^CpYx{w=4rWumwZ`9#9h3U88J7 zd{2(d3K_zV)=(tgHXj`5?xOmrfx91h{tMqiIi8>9b)vmCBrJWjoYNE-mV|3}5Mlh$ zU~S$o;Pk~cs~gRT2Z!G6~QqO)QhA8IP)dj_$sYW-JF~N-obtz0enEd5Bu*!yD8?pKz^} zILk^=tVeITlCwM~0ZW^E6LMwPM27HY%*>YdNgVK8DJfTpK9&d%P+PyGN@OKZQlxaQ zNq#OaAt(aP&p$_bwWEPeWmorAn@XBmC+&OQ^0m8?i1PTCj5LyPI>!ve#(pME6SqeT z4pNhd@j;>^!{fYMHHVp$b)sf-OZDa2M{)*SHA#DNV{KY!@BDf8+<>5puViA7cV;!I zm~JY^rYnjY6|5t zLB1AIBrAs~??;Y7RzV6UF|tkr;@7~1eU)(+WOE+f4VcW0Zm^VU?Gb~Yc{_JsbTpV) zk3g*l+DCI3rzMzt>DZI@naCr}6F3&FoH30I zbWEuH-7=w0-=_5qTcJ5Tu+RR zc=dGIBrX+Dy0JnKgi#P$Odf9;ZvRqtj!&Vq|K84XPBG1-_(*L!hRv`v#o!bDj!ee! z9=e}s)9RFF9kSPWF81Xi0bB^j5;lmS?T^$Q$^BK^bxO5Dd4TQ5*#ac;ywGJJa4hN> z^%YAV<^4C7nU}JJHn{D1cpC%tlsEaTR~1+MwC#|0-1LJ^W4scGvWe*UE~-*3Vil!` z?@_$(8;ODgIc8zD?U_UC^rmk@QRKt~Gw`s4di7b4ft+}l7F8~YJc)Z!Ltp9yo2S4u z%%hS$8u@7TOq91Xk34N9n-Dtcq*C%`mUJAM)(LY?W?r$If1=}#OekRF`TR%L#3~)` zbL{5I0*;JbbpDDC&?p!j_B_I#sat07;KESq85^w#vSZ-RlK=aq9ujZHJ z=Cl|a$bVhWL`oPw+v;pL{lr(oG{-41M5lH%t{M@;#hf5oMyY7}A?k{Eo!=~!#x6m6 zgc{@?v)9eyVimVP$YT>381IfBn`)pTGRVRUHlXQ-oV;7N_i^^XxL>j!9n*acd?diw z!oE7TnMX$8QcT0)C7eKCOY&lm)n<=C$e6a;-bD*I`$^Oxy`(Xf0l;?3Qup5Z%b5NAG=?(JlO(p;ko8@0K@61r3cmA`1FI-l+pf zOd_5jeq_#>x=T?KcQp6O;+^&LiZNJz=?ZI9(fw|Qjug-qQT6bB`KdQ`s;ggFQ0h3@ zf*=cUBT>-MO7w|TK>NcZ66^7*X3eYn-}FK(l@7> z7-Y1!;umvk?0sD~}kqx{SiSh>>|fKLpB&+6ZtL z_z|m4d32>l2M1clr_*h=#ydtz4Jj_}za@k@q|`>cM9=roe1_Wc?K`avE;Gqim4LZ7 zXN3`dMq=LtMLs8TJ1JQ3PLKQJv~!#PuPV+xo(b>&J-PTuJaSO-Kv=}cBE-O9-e#>5VkJ(k#vgK=^!2`Uw(vbRE2dY z?(Eie>F;V(+R?Z+D$K)TZ*8=HxsYRGXcjpTFD~1oR_!Dz5t1(SDw4`~q@0dg-=}Nv z=lg0wP@eqmnDfR7#b@qZ==zB}TKkjYT$|}_HR^A*l4piKtmwGu{{^m55= zQL)$2DQ$b*pRd2auGT95dH$;v3;=*;A|S;efODa(W4d;=I=;%ds;*i-D82v<>3Qh^?8n7lU`n*%{R;EU-oyV>i zoWIS6PC^h8@=}Nz^0)6k&+tIw7X1NdvH`g{m=_QTT>`Z4!tIelo~64q=HlZXdpq>N zE&MqaAPN^jE|Q|{2O-U#CKO+eeU3^8_!F^1&ia6enT0O!*+t zgD#Q`)Px<2)Q_ov`$=J_rzjE{hB@fhV!VWHd=|Xk;0BS4k~}V%B?1DZ2x=#(I9CRG zc~q>K=;D%;HY1-P1OF|y8DYx39OdW zQ(lQNiCu^p-?RumUWZ7kf|)HSBkie_|Iw`+B#5Rmm&Hw(sW28B zPm7|v^nSc{w2%N!_xKt9_N^)a$FF`r+#cfzNU5q$g;>2uL@ULNg5X90^P1pInko6H zX8&s6%>hd<(!v%)Ifdsw=IdBe&2fVy8Uz89AewJN0`IEsd7n-Q#zl_H!9o&xfWYY@ z)bJc-by>%I?KSdKTkrY=Om?|cm&8kQ-DG};uZ|O!; z(g>uGDpt3@tgg{m#UK73`~dhD`5+M}cFg~($$w!F^rDKIad#WuOg}idx{rYY4zw!0 zW9byZRQ)fMg41=XC%zxEMAK^udx-?JDoD-6JVLG4m}2l0Og#!7&|j-hAul9~Q`f~$ zO=~uQfpTU6{z>D4LL$!XO)|_ZgW%l65u7tC;*`v+!#K4um~nrKRnKPf7Zot+L#W)! z4%|2ADD}J?&%gqwfi08(bxc?ev0cPekRp;T0w@>NJCG`B6dg~c%gl(vK@rofFPE0vG3kz-FZ&*fvjHpkBFUTi;Smw~jKOFZQwjVaNMvX9;j`pUZi z+%cTNK2o>(U^MB)WBL8^p7hfVX8zaj`ejop+!lW;YCSiM&+)BTD)VI%YZ-&x&LFGCWad9o|m9cYzvW`LD7nBRM za-D6u^7iK4Pws09d&XUns~HeiUA9$)Z8e5}owomAlU3Bl(2hV2U@s(ci>n$*lHrNP z|MFP%*xb?Kh$X_E2{U|AIK)oe-Ibwfw-+M%se~+XX>!?tu&yZJiYR#0)@(*>ZN~mo zvUj-V1KcI<2+2e>%Bwf`=BG6Mdr6pfswNEX(Z<|hS@b{sE`$^9Tzw0)5zCN}c4knB zr5+>t7LWK6?;9@Iwz|L+FW{NTunGIB(lxw?kNyJgbsR?`RfTxGyBVo5Q|=Gr&LI_v zueCg-;dSxr(LoWJSX5Ez&85#p-^G0UJq!c=8bn1RYml! zFtK4}E2xuf=Zw+-sj;-oXrqka67EzFWA60Ag&dC?Z|Ta{9I$+SAZBo**u!vEc?k0j zXlUJ?W}O(2k+CKon~TVXx|W7@yA(>mNG?g;t#>C>ju>J78X7SZpP~xSSmZD*Z#|TJ zw0B8(NNd_KdB@j8&P_A3Nzz@2sD;ye}ytHB|pVL=sP%Az`$hTA?-n|8h;1#tH zrQ$jCRSa8asBW?Q-r4Y&2u}&F8*7| zb+JKnxmu^kWhB!WiEya;oN1%{b1OTJ)`Cy~OxBF6tppWo@56mTN`Lv^R`CO6(hpQw zO#D1nESc|2*wMk)qLVse|1iURBaC*ohl+@PmF(DNKPXEYtKCY@a+}U`g{igvDok^a zO^o_cvXzf^c<0K!;;DYr)SR#HF|EH{HTn~d>k-eZ8L?Q}7AK~h8sR?#%-mA?=`J;R zvZ*Wu@70OvckcLQ=+30@)+z)OKX}l}Bfje2bIwy9$Va=`A1&sr5^zDcdHFANZ1~dk z3CMwc&T9Lx9ir+jO1KjK6jt~R3uzZ08oQG8(TGuwzK0w-d8(>dW24G^&$$dw!cSfJ ztnEU8kq58dty+iXo~S22{}gXXc3aUP-I>Jl{oE5jO~xrVXtIWFMHgX5v_Fe```+(x zu<%#1w&`TOQVYw!ebO#*oxS3ltZ>v&^zbF_IwY9A=uOrV{-gvi*$1FPEq!TYqNC_m zJ_H}^R5z3a2REoI7C2~;Ro+s&v#k2JU1gN(rO))6&=J^H=fXQVk}=o9cY2li^Lg`B zjvd8|BCAt=HYER@wUy`Cu#H2FT>^7cGyNy6fhaYL>?R(Yf48G!lSbF5;09~KK=Up{ zhCR3wkhV>hwCz53^3?VOBoT3gH!@q*ODspuAEeu;X_=_XS#b8ek8CcmyUbHu5APl_ zMQY&AA(>6km0eK{iu|iW(S}w3uVu^iuIFJJtcSHxO?>iSK$u>Ud6%#Y$4Pa#sd30g+i)SDDK(rY!B0?lZF}%`!Y0(qW%Cj2;X{`4bv;K&h_u72r z9i}WrmPv-ini1dhQPQ^I*nwc&L7lqBC>Y+!a_BRaUy>If;`&2tqANlRr8_C9MIO2& z`EcBBy9^AEiTyZ~Smmn;*-4G+{R7JI8Gra9@UbWu`2t_qIs+5kk|+AZxe34x!HC@j z8`B?-S_RP7WbFFzI|q~$ZHH18YGoQ~odBu9Xi)Z?+WsVZBB&8Jqf0%ZhEYuxBNEa; zuU^S5(G2i8989nY8Hv4iIy*~Hl|kXCjBYgQivCgj;yPEQWq|M(pgXtaXyZt`;4xKW~7hu-q-B-hTfIVYL9cJ6=&H) zJ`K0g#SR7Z6^&N3Jh12l5K?DPw$d*SmVWE3JAkRtUe5MKC-wJeHWkGxJwA9VVAc} z48&F>7#OOD9T{rejai1LKxKk9jphueC7rd}%S8?N{9JII{(#m9`!nM~)pJ=;Bj}s> zigLTp!3^|F(KYaxKwNyV(2DWgM)|!v>oA8=ZluSQ-Q?a^8zklX=cEXf&%9lTrl$Fq zTIq~LDv7i0nHe`5Vt~YcY$Tmz3cfIPYRih38Uxx&TpC=$5 z0Xx)LRhi30TuF{n6^kmZheb-e0I%6JQp?WVt;F^R^$gIWU=)6a*_QjyZM3^sbG_`R zU>;JYN|y`=TPh*aMZWl)TF51k-)KZ^hop zSYG;K=|rM;d-!i;Y@6~420*;R#8#_WMWV;$?Ty%b9ZrTJTcV9Q3~d)HkJ%Deou{Bt zSk^JVRPEx>i9R{b)w}gJukRGk_1Rt2BWV>gz^GY!V)`$jS=4K-3f_1cNU>%IwfQOS^ZuscHN!#B z+Dx1$rJ;qd`J{IDp)8ZRJxL*s3u)J;;`+5Bq@OyoU{<=QgL}+)=$#F44r08;G_l{C zh-!l%kq^d|^$82E7~=#$?jA*S7tVliowC+3;#+NxSDMPKw|$PxJ_&X#2aOAc&b5cE z-%$9;I{S%q%RP@~^zL>-qQhQLiZd>`-IwIen;5TuhctOtT}S zw!Ut((;TSuN_iX-D!wFQl}QKQ;Mw=YW+{D5^0!9JSh@u`Q7DbEnw_?^77T1aP=bYa z+oK|%ui!mXClc$lN`pkO+Ae7UY@6Cw*?xFlwGe%kIf{)njg1uo zOpC5>Fv!OiYo^SgqDFL7VV?B09D$Rcdt1a-lx0XoH!X6(Nqy)iAz0{~TYz!t?>+&2 z=d+c<^0QX*KJ=#m#p#VqvRl!Bg_sgAyuc|71N~faDKxT6*A~GV++5>pNxqh}j)T9$ zI%e;v1rjd<6qbH%`piZeI?6vh2h98+pa=A-Gp*ZT0p4*b@E35jZykqQJTw!`ojXCe zFDdn`VC5Y=i3xGaEl#h>1*mE>Q3*BkN@370Oor!_K;g zyzo0fJZYz%Q0P-v(z}pAI>k3iWO*FfU->C1jA+6kA#b) ze-7wE3X!n}zW6}or}PtKGY*d!jV)07%*W6NUf52#4jP>|x&^M@Srw?xWlg6!fXat6 zP~Ri$*lb_lHTHE^z1>>4F8XK9gV&o&zNC0OS1}7~2pmwf!!L7p`r?K==52bx_4?JJ zdWc{qALWWQZg_~sJPJC2}R+VilNCR~zVXhHc zYZ_!xQy$4UMlHj;E}TM?vG5nqx;-N;wZo6mU=e~mOoCpMc``q@9&u^tDb!iF(ff^I zy+J&*yPt2;XbmYhZ5!X!*HuI)^+YNo>}aK__(Eo`#xx;J*B}=DQsdqYmF>c9fGJ>_ zDQhF=TaT&bhT+62s9s&oX>1jA3rJKb`H8VAI%qbYeTEE-GKE}*8w($~bR{X~-Jj*| zk^q8t=1MUk6grtXv01s}`5D=9h3~?qyld~gj=*hcMJi(LSBU74E)|XHBw}$qM{y`Z zd`(||l6s7nZa!y3pr&9N9-;F6hYLC)eknXp2@e3Np+opjove9%k;_|xQ%|37)hZB- zbCUe(-JUhZ-8g*DkzVE z($K~pUl${=K=w!P6d;_9*m+yE>(!qCzBR#@NxY4WlD@Zu1NXHsZ_$?$OV9^9TPHp# zzH@Ia6VsfI8V(}j{8MdPR6e#^;GGWI%VDUQgOl{#l|(OY4k zY{%)N{)4ovuEF~*ur7{m?m#*J&r$lP?zfJpg_zMm2+*6jc(sVwqTyA&4MBNoex~gE z+3RhGI`?doCodePW!N0$s2i4tEd*=jZQBNPkG)gPigDff&y^*9$-0aA@iJdHSFJwtoVf8_f!}TtF`(=I}b*Af?Xa1v}&{wcd7vQGaj8m za$LsWEHKVsUd=`x2I(L5k@g0-1N}TdY}R5^{nx2=W;~=mj{d24qTVg0H-t!8ssHds z`C}kxpLoA2GUy_pw-p@6Tku|A&V5mi306*CkCit&eS1Y06i!{j~e zQqV<1TR;x?AyDQ$cXC;;!$;jmPS08_ijG+2?tJ!xhi5G&rWu1wBc+I#SQBr*5(3&v z6W!i%k!NGFhRQh%qb3o;C}&R~9;rR|u=WYj*f>X&)!q~Z{RL!AWbf-tyrc*Uj0QGf z(#1DKM-ZjWvs;2O@gapnvR-OSiTlVVy(n@lcR%msn2Im;uqwCRJ`d)TWw83!k*d*O zn&%er9iw@y+{`zf_Y7H~I(;p6C+7%VPXOF)TK&*)#kToOofh&LcX%#o9Y)*eGpf(@ z`=&a|!AG_^Dlaz6`~CtN63djH_RNQ;+G~^r+jJDos2B`ki}r9CB$2L_9x!MpgNHpo|0zvc3JWFRIY2-7MqhUf(y?8tPKsdk0+BZ&%-H1iyk{1!fn5 zTie5^`HuoxHZNO7EpItkG)?OqC`|8|)>hRK?YHV_U0}bOerY-=o{{Y0I6+dy9^?8V zBjQ=69#!6m)Y6-mYOznVd&t*AthFj$#b8w?n60y>XU-WGw#`#hILd!IR1~D#k!{(b zpjoX371?FxcRPBg*`~};T@~ZJpQ1xV`%w8T>t-x1!)4BO1)MMsB%@&+PJ4ulH;i1w zy%zLgW#d1w+nWL%xi_0w)twbVK>#OI7_>e!boR4UXE} z2~HnqlC{Z%M>1tpYL)jC_&a)xTfEX8RNau)HE2M1pngdsuF|X_9ILAkYO~Xicm(p( z!`a~|vS}3Qd|rGf#dCufCyU z?XI>;2mS(HD+zwZ_#3P|Fx;>wv6^>EJe};U*LwdScVK~us!gdLK4opqSeO3d_`aIz TDbx>VCa1vtCkA@*@2md<4v^HI literal 0 HcmV?d00001 diff --git a/static/imgs/flag.txt b/static/imgs/flag.txt new file mode 100644 index 0000000..78159c6 --- /dev/null +++ b/static/imgs/flag.txt @@ -0,0 +1,9 @@ + __ __ + | \/ | + | \ / | ___ _____ ________ _ __ ___ ___ _____ __ _ __ ___ ___ _____ ________ _ __ ___ ___ _____ __ + | |\/| |/ _ \/ _ \ \ /\ / /______| '_ ` _ \ / _ \/ _ \ \ /\ / / | '_ ` _ \ / _ \/ _ \ \ /\ / /______| '_ ` _ \ / _ \/ _ \ \ /\ / / + | | | | __/ (_) \ V V / | | | | | | __/ (_) \ V V / | | | | | | __/ (_) \ V V / | | | | | | __/ (_) \ V V / + |_| |_|\___|\___/ \_/\_/ |_| |_| |_|\___|\___/ \_/\_( ) |_| |_| |_|\___|\___/ \_/\_/ |_| |_| |_|\___|\___/ \_/\_/ + |/ + + С4Tch_Fl4g{Y0u_Find_4_littl3_kitty} \ No newline at end of file diff --git a/templates/path-traversal.html b/templates/path-traversal.html new file mode 100644 index 0000000..e27541c --- /dev/null +++ b/templates/path-traversal.html @@ -0,0 +1,36 @@ +{% extends 'utils/_task.html' %} + +{% block content %} +{% include 'utils/_forensicsidenav.html' %} + + + +
+
+

Посмотри файл и помоги решить задачку, но будь внимателен, стоит проверять, что происходит при нажатии на подозрительные кнопки. Флаг в соотвествующем .txt файле

+ +
+ +
+

Введите ответ:

+
+ + +
+
+
+ + {% if error %} +

{{ error }}

+ {% elif success_flag %} +
+

Вы прошли задание!

+ + < Вернуться к заданиям > +
+ {% endif %} +{% endblock %} \ No newline at end of file