From ab461ad161e66d6a35e2e0ffe2fc98346f9f6547 Mon Sep 17 00:00:00 2001
From: chest
Date: Fri, 14 Feb 2025 13:19:23 +0300
Subject: [PATCH] feat: regen forensic_task1 flag
---
.idea/MadokaMagicaSite.iml | 3 ---
app.py | 10 +++++++++-
func.py | 7 +++++++
static/imgs/task1.jpg | Bin 0 -> 10614 bytes
templates/found.html | 4 ++++
templates/index.html | 2 +-
6 files changed, 21 insertions(+), 5 deletions(-)
create mode 100644 func.py
create mode 100644 static/imgs/task1.jpg
diff --git a/.idea/MadokaMagicaSite.iml b/.idea/MadokaMagicaSite.iml
index 697599b..51d2aed 100644
--- a/.idea/MadokaMagicaSite.iml
+++ b/.idea/MadokaMagicaSite.iml
@@ -9,7 +9,4 @@
-
-
-
\ No newline at end of file
diff --git a/app.py b/app.py
index 8cb1a19..5e9bb47 100644
--- a/app.py
+++ b/app.py
@@ -1,7 +1,8 @@
import werkzeug
-from flask import Flask, render_template, request, url_for, session, redirect, g, abort
+from flask import Flask, render_template, request, url_for, session, redirect, g, abort, send_file
import sqlite3
from random import getrandbits
+from func import *
connection = sqlite3.connect('database.db')
cursor = connection.cursor()
@@ -53,8 +54,15 @@ def sql():
@app.route("/found-me")
def found():
+ session['task1_id'] = id = hex(getrandbits(45))[2:]
+ session['task1_flag'] = flag_task1 = f'C4TchFl4g{{{hex(getrandbits(45))[2:]}}}'
+ task1_flag(flag_task1, id)
return render_template('found.html')
+@app.route("/found-me/task1")
+def forensic_task1():
+ return send_file(f'/tmp/task1/{session['task1_id']}.jpg')
+
@app.route("/decode-me")
def decode():
return render_template('decode.html')
diff --git a/func.py b/func.py
new file mode 100644
index 0000000..d91c5ab
--- /dev/null
+++ b/func.py
@@ -0,0 +1,7 @@
+import os
+
+def task1_flag(flag_task1, id):
+ os.system('exiftool -all= static/imgs/task1.jpg')
+ os.system('mkdir /tmp/task1')
+ os.system(f'cp static/imgs/task1.jpg /tmp/task1/{id}.jpg')
+ os.system(f"exiftool -Comment='{flag_task1}' /tmp/task1/{id}.jpg")
\ No newline at end of file
diff --git a/static/imgs/task1.jpg b/static/imgs/task1.jpg
new file mode 100644
index 0000000000000000000000000000000000000000..465896dc8721804db489c12c304cb5625a266c57
GIT binary patch
literal 10614
zcmb7qWmFV!^X}3eyQC|%%Yrn5NQZPRwR9~F(g@NG(nxpbQcHJ(N{7-NN-0PPk^*vl
z|L?u$-miDg@6&JQJTsr>%skILE|PhIsgCz8w&&Qe+?HC8wU>q3m@>$t3(dKz{0}9
zz`^1}0m4
z&LW_#8zCc*O9#;Xx|LVmAVgUhC0MU9+eY6C-nb`9Z?|N6$5ss_*7w>mv
zXAKr9(=wB-TXR0fE1jrnotG8um@>azw#wp2*~;i^&oWZp{jO6y
zLPbVHbC#3cT8SkwX(`rsUhTGLN&pfKnb
zkfA=_NiACF+P-Vt+FRO(Xb)6RbWCC031Pa_dCmUPVsNn4&{sP^>D=X7ko)SJ>Fs6;
zqgNN1s+Y4LRw804aUPd|lJdC;vs@6ze|
zwcR^IRX?_VWm7YM#>Vwkt;liN6xqSS>huLL&(9K6NgpRGd+>JA#gbkn0q^#Siu{PH
z+Vif}osD8H!`jjiQ%v-JS|qPlTZW-6(U+PYjd#h&g76UFkm{EKImHwzx&xlk6L11V
zxqH-|NX`(`YD^*iBKUQZvtN#V->M|0&4#tOLan*eQ#tAFFfl@=8{Im6gA8@5?v#r|
zlyAg|9^SI&d-JESIJb804y$?p$k-u!gIOF)qZ(}{MAN=v;W
zEN1p}zDX>YBPmq+-#j_Jzh&VR*2IH~(t9IIKUy?+Lx9^s>9rH1!W=;VR0^%or&9@vhwFo%HRv?SRjc+R
zsq05T1v(*B>cR2)9((u^U`?~(gis52H;L|Dl_7->XS_=Rf!Qj`(3^yAw9z-7fdUQ0
zX;FhZiUDr5S}Y1tPnLGU0we@LcA7Ff%+ocT46NgJfN6JC!mbld$bIX{`vKHKKn68O
z5R^?y_cfGqu;<~h*pgW28M%wm9sA(P=pG7wKDj6lu&$;f#8>*$`Hzp{;_(ewrrp<)7Qjm(=?zb~zyg=e_pqSp1AP0jdgD(=uoY3rR?7^i(*6|2Ps1fqFCG3rea@?@M?#Mv)r6oK9GR
z@r6CfP9({mK&_+v)Y19pk*278rqO%pVjd=zTOH>sY~Mcx!~CJj#n4~(XAtzZ@YiW(
z<5+X%=)2bRL&LhPuA4|fd5|0F2p$6+@bcBFG`fbO~ow5EdXj4&YzWkR#czg>^f
z62vCUSuiHZx_$ii2I(I8S{6wLO9y+R@-sD=fq5SJaAq&Pv8x{ZwO@3>7fXV-YM)EN
zE+DR}tP~Q_jw%`|=+Op
zUsdUnVId9;nqawIqCeC`{X@!ENQ8QS#^uFKXZ5byu9%Z&xJb2E>}zB>R+O%yNA*Ya
z{v<@<$)!SI5HtGoN~AIy=Ip(@yyu9b1@1_)W<(*<_>>zhc=wJsm$|WsfOPXzS83QH
z8R<_hg)LE{y_Co@H$wJ9cPVknkiDSRE=t?Uq^zs5qnzcIEFEN_Q#rn=
z-w0bH8I^Z*dKJj=5_L!HtsNa|b09rfh2a(ecY|>$W-uGAcM6-cZ{jCYuh`7VW^>N)
zW0z+;Wr7k=iBrnn8XwHb^KtCAl*s4vYgc%yi(Fv<4bte-=T+_l_6)eC
zK0P^vH$kUoy?Wh=KW$gY^$qPj+Z5FNqqPKwY`U{MorSBnk+nO6A^uEye{=WcD*dE6
zf2n)8k2kh($=+`&CHs?)F3rFg(c+_UrRLZIvpwV!d~{30rLYL``k0bhbmE3lyzN9k
zbWoGX1^!!K<;vUEU)=y#Vskff)T8@2?VRaWFHi1>R|8m*-%~1#GdOg9Ru0ZQx|#a;
zO3b2Lsl5%-_#&Bl@6@K(djzp<(4`881Zhr1?erZMfvJ(g>COnCmQxf9bX0$%di%?=
z&F2voSY&mOKp6eIU-)y60R9>=+hZw>4QpCVv)cE&rO8Apr{MPz)b}+WJN=hj5mZdl
zpb^H5vg6Pc!rga?Xhu;~twhVvv)$He?z-h6VKPKX=7PRpZqn57Q+LZzWxfrdrU0*B
z*Z7g{KEThZH|Bya6|x@1pi*k!v6>L3o`hvBmXcYWavxdJ_OmHjIhlS;dqujljh9A|vA;v_xiF$Ipozm;A6L?^N&O;xApPg54IA)QRuk2apF*`K<6T
zzX_iU6K0AoCd^dU32Yj}oC82VzF!e!Zsd{VJUXl-Z#MCm|NC1bY%JtDra^Jq457!!
z%g%olEkrfl%9>=rlI;_=b4oLzxpZ5%R@8ODFAX_^@#@MBEaE&T>k6~11!8dgQD(zK
zUPU+L)3zPiBFjht)9#;mKc|g+aLhGu`S4?8r90=6(FwR?tXzy0^h+^B7US$sT4d3&
z5u>I=bsHtd}rv-zS+7Yi!#rhTQE~p
ze8(LMq$#A7s~u*+FD#F1rtS+{*p#95%9pTmF6UlcL`omH4S>wh&?;}9b0b%~*pPQe
z!=3%=fu+Z(Cv|JB#1u`j+wq)XhV0ZgXFNGwR!RiPxj|wp4VD}%i3K{UHBL2V`JMzO
z%s1B*@&VahZ`Jh>mjWDB
zPXgz>vTxa&uW17AmP<%2$6rJBwV#(Nryy1079FA7EGKYQZ2!o2Jg3F2(T{SlRe-|{EkCK|d>)1EgxtKX_
z*0B9l;g-{!>oGVG^~ovd6-*IO45`%Kf?oZ`GNs0VYeh;DS>o?v35(()2YeR_HD-{UFolV4uo@#?
zC5o%DN;@<0Coj1?grIz9Op32g=gz)vtKku_^|zplNYx|(+-cuEYS!0c49ME)NSrdc
zzFPQ;_xBNSae2uQ=f0Ja%6NCfR~x;2OFwZ*^eMWSrh->ZVbkNXA0e+hl6Zp@Nj1YRy7
zmE`%|=^Om^cD92vKDK(AYMG4&%kM4Il_G#VAa!MbfG;GN9
zBc<4m^)5G$hH@yHSqr%FZ@KllQri>+CP>8m=axp@=y^c&ad9qW18BuLGw9;deyB0K
z{t4)y*3)(AN`zZR$I{zF>5k`yjd5>BPcY7dd3k$aBRQGw`CH7xN5CD&t{U7s6m;#p
zxQf`{Ud<1X(N?3`2GYb3CeFT`X&bHbZu&5vqeEwh;@hNf5Z=2#knEgYonHya2;}8<
za8-vJz?h)PDQEYQS@8K8%TVv`Ffs%^;p!z_BtpOZNj%#}#DimwZaRczAdu<}7cH`6X*Ej1bsXsI(7P>(m?1YKn?
zGEK04=J;&8?UOTp2Tuipipsd0af7*76ctS>jy6xfmlRO(wSp_KRyPwqp$o-g;g{iK
zfT!#BmN{1DNSXeKTR2v7c0+n>NfTdhcO(c{QfQvZuBYzkW;z*(w>np4KMx(*e7DUV
zeUonNVJ|mo*nk^IJT^#)=d@9r>EQR*v?R*aWpf751YjrvnZOVCkRn$>^UXYenEjK{
zQB<3|?w5ol?z4tcly9BoXSk!?cEexJJcN?V&z{eq#uN}X#tiN5Tk$I@PQ+eScbU>1
z&LKd|NTghAHgDU!qUw~q9D%!foxs>yjFPIVrb4UoD{5k6H~hvmr`}V-+g^UOeQC~0
zdV=HJmK{-{O>dEdV~eq>|2O0-gO@&|UcfDeoEm|&Dxsjc9pr`$*ifJ6J_mDKg!)2l
zRWj3ox-Rp{tTaE@878lOy#4gmlA?~WiWsW`S!{}+WT9^m)g{%q!KdQ~)xwW2teu~k
zn@qB<(c#G}myp)jKLTvQS0W#RR)lEBTp_pws{Q2py#5E31aCE$sT-t03<{FtPv)|y
ztDM`4!?RT6>IzuCDyIkZvru37rpnv0F1)RpsWmmq3VX$&Bz0Jm_mPVCFOUq(NVLmV
zi{HY!oWS1jry6`(J-May96>S?fUOjueY+^wqv&l){E%L&GRMqq=G?yNNv9WqsG9uC
zx{Z`QseQ}4rs<_d@(7rh(m+bMw4`~{`ysrWCMqXpB@gwVKeVKJO#f?m|F$TJK*xKB
z^6HE4kAPrYniuTcqu<~sZM<1UIry3S;8!GEqY>C{W8!gsjWK-B((&Df_%w9iPCAx$
zakge_yG(CVqq<(rCT+81hNOG&XFz4db~Hsx;R6eA2w4Uxkqm0WEHM~l8XTeqeXt+-
z#wos4r^LyMCe}DJRG3<4kVn9rmW;1Q3Mk0l8l&B&G}GHLMG)_d0Il!ot<+$oYbOzV*&=+
z8!t2JR`3)$rMRW3uHvd~J1KSZdjwb-z^EVKaAgJwv%_*WU#6r4DDveV3l)&1$gY~2
zXYCNy_e*}h>aT9XgS>D#{A3StTVLK#|20;jnvHohbxtc>?-)Zu0j6#q=iquof`2|9
z!JA)Vz!efFxjP}d3#b^gQ`refUnO~XU@UiWUTsWpm3k9EIgRZX#YlF$@RX>@KmAUx
z8>71lc|4nDTM*8m84NqR;zKA`Bc~Yxgt?=qn68BRcvc0Nz9rhne4nsLVHF0
zSoNM7=D_Z{vf`mrI_Z&!aT6Sm4_`RH6YQbRX`y}TWUYwl!M}@?Pd5Vln+$f!ITfa@
zbSAP$4-uBKyD+y`d{uX+5{!>MbhYsI=KgGCsooyk)OWcRvW@)S{(NTb?qsKKmKZBc=RSN!F?MkHospOvRFLNJM}CBPMlO(
zOcr5C)`0h9IFXJ(a0Tykp+W9w6$(%wAhwp4^)lj
zr~Kj&*ilgEterQ9>OS*J%wU9rc~I+Eu7Pt#0Rh6SV?i7_-}gQCV?B(wS)O3
z$+kb?aoxwe66Sv2tm8+(j?NaA!^&@x&s{0k8|;<~3V7Z&`wWg%S41H1J)?!!Ek+(`
zcnai2Mak@v*MjEoX=VyfMeV2C2Pxj1$5wi_j
zw+;FQ>7WZ0Wet8cd8V0v8I;GPQ>gsyYT{wzaz~$Z7(M-pE-ue;PH>_$a19ilWMZcs
zB<35OPGxj7b6jghrF%WvE`+4ZJg5Z^MOaekQzr*qllKz^A$7Tl$8M&&{(d|NsVX5A
zPJcPu(yC{pk#ae?q-z%`SeaC>A1U6)Vp4cDhwQg_1oS^hc)Ami${FuUyd0Nurrf$>
zzEyvaaQ>rsvUGaG=Y#&!Jr=YR>jvX3??HX-sbp1e@tuJ
z@$)n>szx|9N9K^@sFHGwixSerp@rL?i9qf|^`ro&Gv4Rr#5Ov9AryLL%c6awCu(nF
z3g;URormz@8F_dyJqM{^FBl1_U`}?ehZ^}{xeMlhI-pYsb9tyS*%_ntilWx;NO_ud
z2D+ibRf*s~6*vKh?xeDBS@`44$;DnC@tltfxBetbrP!jzu=ybKHQE3~R*@XgV&Qnq
zHML;71GG}K^ZvrssTqR_0N@u@CP+vf7|9}#-Ac3w#V!z!t)!A<$zLnk0G(hC5|->Z
z`MTBP@Yxr{CM=-k_pf5hi@iE6S?5lhOxODbiTtkKH5pu7He|IOsVDsvOGw!G=D%J!
zR%EvZ#LZ#4s0^9q4NVXNO?-`Qb^OV)zK-v{If>`C5mvT-C)Z%4_Ozq#YqHg#0rU}&
z@bY;GQ`I}?Hq@~+co<)7m(8RT8l{W*yjpLc;LiyvAh5*V&YL3HE_^pzg8s}{F1{IdqDojv{6Zn!2$}3OM1@qCz9aR4nw9Td~(JT16`94B&irg?42MjrT
z3A+EA1I-j?4k3;o={-O}vMQsi{DOh&-I
zrqkL~*U*t$xvV5vTKh9x0=CSv5-6+w%`dx9xjLvyMhG;n+F1DpF`yG<&EekO09)Rz
z+dQC>HWt|4*cRfTT(C%GgwfBXt18Z@V>(|)a0OP=E}6t7tic^bkn=`8p9l=Ez9CF7
zzT{%mzOIyyfY=A{Z$k~{a{~)SAkrqC9Z$&5aGR>Kd-F#em`0!JA>1Y+Uml5e{U&Ll
zy7uHUGLA848KbB`k599;j_^iZ>g<)m#dm7^ZmU{Pst^K>vQ8Z#D(|8_bn<+DOp_~8
zo<7i3_qo~z>MCt5u&ID8((Ef*?)hKnb%kz>DkRJ&15~}feM5Mm9R>GaSd=+0^&s~$
zIfA1zwRFQgPNNsCZ-sPzW;FkbUtVwxE+2=Um?H@pBZ@?G>&{
z=#fqxod}5Bo786uY?TWAZ=Z==_(!ZeYkd754o*Li`5JwF4;;>~34v_R*ORbU4kXBC
zR>l_b=9h22ZXtOd<2u;MX}SvQ7!XO0u^LQRgPQo98&PFeuz}z6(TbW*sDQ_Q0gA;lVF$0ES
zIEX=C+RS{{<~8daSi7#WHY%`H=f~Kl!IU-fz}Esbbca@QAZBGX(NRnZ7KO|%O_&1)
zNR|Vlyp`rCwXQYMmhU2M5^P4CR7&bHtkYoTvjR6hvC%sZy7&b
z;_5-K)LTiLpzEI-P#^1qwTe`Lc<=%JjS@WOyT0E2X*xTXg2qV>*gd}fp70!3`pSVtWw|Af0XSabQcg`=5ud?_w+8-
zcK4Yix2zJ;$D(v=sa+8U_)0@z!BOr+x9Bbh^Y0M$8R{p
zF2^0g%%$#kyQM4ivVhy@I*pqQi~%Zdk~8;&XZh?>o0W%#^F?AKq4p6LDl?S)4AuOH
z>WNy#~UjCj#+MFWusTMTO(k#3($m*<$vf~5usCCmT$;q=i($=37Q{@_d
z{CR05Qr$jHDh4&PW=aw_)7`?Cc&1x+m2*arJpmFq_w85}4bj5@QflXsr+3)?5Xo1is`u
zh@91uHm~2XCas?YOYJwA-woA!W894BK4INz{A1f&9syxe{~0fWI8=J{I%SV5?tu@F
zfP=#?Wq;3t9s!{>u2-)Z9Xh=~h8?hlBvM|bt0{B~513=F;8j41tBiu=bC{H~Vc?7d
z7hvOP+`avAZHz_>?9iQ|_VA-c+Sp3M#DKYFCI2*QS{ghpWmK8wBSiq#*+u91oO8c
zcjBx`L=ylvWD`meE0;aYQCpfD!3-+T5;-i~r?tRtJ57>hVPbJl+^Z&EuuUzKIh?C@
zd)Y?}UU7B3DX$Y$e9H`}r?q6JrW?crrHT`RMkf4-qu
zRvET0Lw!rg8X|)eW25u4EU`mfvRaOLBy-^rpsSLzBi8}C>jBUCuBW>1$k
ziZ=+(i1w)U6n(A7YSY&!P3*mQOG4-%5y+?^
z2MHLuWfcdHqy#LKwivIksde!Wcw>3A@jTJh8WYf>&wk^^q740wIKN?<(^;(DJx3~w
zv^yivh$=kTw-)9hBPa&UQ^qHTq`J}+rwIn-s=yx;Heqfj9@99&
zVPn@ZF`J3Y-ArI(yv3d4sgy3u)wteYjpp>+f9(fwXP_ZM;m5}36!O?%)2s=(4*?oS
zEU%l&_Ivd^s^O(oF2&IWkmhg+=5!~#u>>b@Y$6ITozUKygL;YDB#O}sLB=)NMqF7z
zd65WK*hRuCBWzB9#;xHU4x>ssg5iPhQZD`N{=&*n_`>A8DT1}0Y3WML5+v&PYX8wX
z@jCc1Q<9_fi)x}g*>ALm_m`oAoMPVt^C&v??`q+|e~IHybh^QFCdF5CfARlA6<;jD
zP5J+A8_(YN7y|SvJdGB3fv)RkAK()Y^IsW(q!)P#gHbUAz6*O*cl_-RP6O+A&EaA#
zC6c-ZvPa&CytWcmJq1#K@6mwpz(YSLebYVW;f)aeJt+;`X5h+{Lro$ibl!A9QnX~!zLE93Q!BHJ#1MMI10?HuN!ts@?o|3kE7bA1
zm4ium?W1%I**{q@9mhlfC%b(T9G(^92IEI}E3VYO$~7S{gZv_gjQpvLxl_n~c1HaK
z1iGYRPktMSvoAhV&yONP2@oT?1dfPYc%qMB-=}VM|6#qJ`%ofMS7s~M(SjL~Zm9MM
zXtEr6lf^1G=;I_K!1}O?9I<{OO&m91N44R)h{a)dt;)`bIYSM2_Ga3ad9<+#6Urn5
z9qkpKrIh0vNd$iclBrQ6v!)CsPe#(*w8|3m+2Jf@I`|)$okn_9WB8#Z>gnL|
zbj-goIP^m{uAo0gzw%GRIn}oo?8?&7AO{N`1_#)3QPTYS+S^}rf+)e-%1qFewg7Mh
zs>4`atF>pTO*rWAQCTL22{;2fhiq_=9buTbL{67xSA4|r|-^o24E-#0l!j7r+%0_P7Uv(L`%@?}v0{O@6Zr)wj%
zjAYL5l7xgos0`A??jUIsMmbj>R?uMhluhQ9-4cTmv(|(K@azc(%K?`{G|wNKnLyY|
z8(r6`B$UO-Xzm({G1Vp)HJ7h$W861Hf8f_|iG9Rmr?UG#EpDS;#1?Z1V~>S#(k^sL
zO3Xr9VFbEXojoz9U#g{a+@!?3s3;esd)k1V7vHBTi6toJQks6J8oT2Yiy584CV#Oo
zf>XIi5D__zPfi$Wbx^cs8zD5)DU_L%MwDu>*Gn(RGyuS~go=^i{!H(oS^hEEGhXoK
z9D}Pzaf6|HoFYqXLOeOn)n|QIidEboCqn>w5)79ESGREF~XvdxvWBI$rW}>jf!PuNw;EIZo2feF}O-xFea+*
z-ThsFOGHL7g_1TJTT5S8jepBiW4~32cK1kEfkD@2mgC{>&W)n|d+J62ixz}lCkaOw#frq$UreBTRm~j+`u!zHQ0p8;uRz@LXaB*H!
z&kJHo5_Yxv{Blx!C~2!U9_4lURWZ(7q4ZpJ2oq-<#;JA6cN;PSolNVMCyM^4!-1bBuJwviGv{CeY
zmrP=E5J+p0GDs>s?Mszt{;HDAV4JG;zw;PhJxaG-h3r5bWJQsJ*SF^PF|3lSFCGC_
zuO=P=9**~R6mQ96G;Va%o;T4^XYE>>$P;l@E2BvU3dw0*3H;JVKGqDh%2>)eOxk{M
zzhaT3;4u{-GmM!Gp?)Ad4N`Oy`~}(B$mA#tMRETUgi;0uzqkr6uRws3f~w=0s{a5
literal 0
HcmV?d00001
diff --git a/templates/found.html b/templates/found.html
index e7a638b..d5af1e5 100644
--- a/templates/found.html
+++ b/templates/found.html
@@ -1 +1,5 @@
{% extends '_task.html' %}
+{% block content %}
+cat
+
+{% endblock %}
\ No newline at end of file
diff --git a/templates/index.html b/templates/index.html
index f987b28..e5fdda1 100644
--- a/templates/index.html
+++ b/templates/index.html
@@ -50,7 +50,7 @@
Если вы используете Windows, то можно рабоать с
Виртуальной Машины
- Good luck, have fun :)
+ Good luck, have fun :)