From 0f60d8fdb31c664a7dfcc51a54371bf7e75fb221 Mon Sep 17 00:00:00 2001 From: GitHub Action Date: Tue, 30 Apr 2024 10:43:44 +0000 Subject: [PATCH] [GitHub Action] Update challenges in README.md --- README.md | 1 + web/shodanql/README.md | 24 ++++++++++++++++++++++-- 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/README.md b/README.md index b998d4a..5cb78ee 100644 --- a/README.md +++ b/README.md @@ -79,6 +79,7 @@ Although some of the challenges may run as is, it is recommended that you have d | [Arcane Nebula](./web/arcane-nebula) | koks | | [Cross Checked Report](./web/cross-checked-report) | YetAnotherAlt123 | | [Microbuns](./web/microbuns) | koks | +| [ShodanQL](./web/shodanql) | sAINT_barber | | [Underground Watch - Part 1](./web/underground_watch_part_1) | sAINT_barber | | [Warriors Tech Shop](./web/warriors_tech_shop) | sAINT_barber | diff --git a/web/shodanql/README.md b/web/shodanql/README.md index 3019830..cbfd38b 100644 --- a/web/shodanql/README.md +++ b/web/shodanql/README.md @@ -1,7 +1,27 @@ +# ShodanQL -JWT forging with JKU header injection +[![Try in PWD](https://raw.githubusercontent.com/play-with-docker/stacks/master/assets/images/button.png)](https://labs.play-with-docker.com/?stack=https://raw.githubusercontent.com/cybermouflons/CCSC-CTF-2023/master/web/shodanql/docker-compose.yml) -DNS rebinding to bypass a localhost filter +**Category**: web +**Author**: sAINT_barber +## Description + +We found this website that seems to list all systems OrionTech as owned. +Can you access the admin page and take the site down for good? + + + +## Run locally + +Launch challenge: +``` +curl -sSL https://raw.githubusercontent.com/cybermouflons/CCSC-CTF-2023/master/web/shodanql/docker-compose.yml | docker compose -f - up -d +``` + +Shutdown challenge: +``` +curl -sSL https://raw.githubusercontent.com/cybermouflons/CCSC-CTF-2023/master/web/shodanql/docker-compose.yml | docker compose -f - down +```