From 60aa12770bb49e0190457c0e70edd5d2e4b5f21c Mon Sep 17 00:00:00 2001 From: Yan Date: Tue, 3 Dec 2024 16:05:46 -0700 Subject: [PATCH] fuck --- .../web-overflow-client/_0/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_0/server.c | 1 + .../web-overflow-client/_1/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_1/server.c | 1 + .../web-overflow-client/_10/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_10/server.c | 1 + .../web-overflow-client/_11/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_11/server.c | 1 + .../web-overflow-client/_12/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_12/server.c | 1 + .../web-overflow-client/_13/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_13/server.c | 1 + .../web-overflow-client/_14/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_14/server.c | 1 + .../web-overflow-client/_15/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_15/server.c | 1 + .../web-overflow-client/_2/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_2/server.c | 1 + .../web-overflow-client/_3/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_3/server.c | 1 + .../web-overflow-client/_4/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_4/server.c | 1 + .../web-overflow-client/_5/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_5/server.c | 1 + .../web-overflow-client/_6/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_6/server.c | 1 + .../web-overflow-client/_7/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_7/server.c | 1 + .../web-overflow-client/_8/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_8/server.c | 1 + .../web-overflow-client/_9/server | Bin 18016 -> 18056 bytes .../web-overflow-client/_9/server.c | 1 + .../web-overflow/_0/integration-web-overflow | Bin 17848 -> 17888 bytes .../_0/integration-web-overflow.c | 1 + .../web-overflow/_1/integration-web-overflow | Bin 17848 -> 17888 bytes .../_1/integration-web-overflow.c | 1 + .../web-overflow/_10/integration-web-overflow | Bin 17848 -> 17888 bytes .../_10/integration-web-overflow.c | 1 + .../web-overflow/_11/integration-web-overflow | Bin 17848 -> 17888 bytes .../_11/integration-web-overflow.c | 1 + .../web-overflow/_12/integration-web-overflow | Bin 17848 -> 17888 bytes .../_12/integration-web-overflow.c | 1 + .../web-overflow/_13/integration-web-overflow | Bin 17848 -> 17888 bytes .../_13/integration-web-overflow.c | 1 + .../web-overflow/_14/integration-web-overflow | Bin 17848 -> 17888 bytes .../_14/integration-web-overflow.c | 1 + .../web-overflow/_15/integration-web-overflow | Bin 17848 -> 17888 bytes .../_15/integration-web-overflow.c | 1 + .../web-overflow/_2/integration-web-overflow | Bin 17848 -> 17888 bytes .../_2/integration-web-overflow.c | 1 + .../web-overflow/_3/integration-web-overflow | Bin 17848 -> 17888 bytes .../_3/integration-web-overflow.c | 1 + .../web-overflow/_4/integration-web-overflow | Bin 17848 -> 17888 bytes .../_4/integration-web-overflow.c | 1 + .../web-overflow/_5/integration-web-overflow | Bin 17848 -> 17888 bytes .../_5/integration-web-overflow.c | 1 + .../web-overflow/_6/integration-web-overflow | Bin 17848 -> 17888 bytes .../_6/integration-web-overflow.c | 1 + .../web-overflow/_7/integration-web-overflow | Bin 17848 -> 17888 bytes .../_7/integration-web-overflow.c | 1 + .../web-overflow/_8/integration-web-overflow | Bin 17848 -> 17888 bytes .../_8/integration-web-overflow.c | 1 + .../web-overflow/_9/integration-web-overflow | Bin 17848 -> 17888 bytes .../_9/integration-web-overflow.c | 1 + 64 files changed, 32 insertions(+) diff --git a/integrated-security/web-overflow-client/_0/server b/integrated-security/web-overflow-client/_0/server index fbe103e7d32d9e6dac0a1bdbf9c3d7860bcc9c8e..ae01492a3a08ddf4a717d4254ced550b64975b1a 100755 GIT binary patch delta 3486 zcmZ`+3vd(18Q#^ymW+)hEa@a;Tas;>@~|Yoke%A$&O+gsk^urvC^bd2!=vG4S_~mA z#jbISYBZSqVcLYG6VE`W?T{4X&NO%e$W0oPHV>zz89L=*Af1XL9P?d#vW)zDtLCq}!RQ@Zj*!V0emG0oXO<5y;Rk_r-e|3CcZo?LG9fR*~C z5d*iDH;|cn!2s!D=bvmZhFYS>QMHLu;~_qsd~9CLyX@ z>HU9-rj()y%=(qKre`ib5&6NsU*vyMm3jWkt3L`#%X8s}`mef*P%}L^LOi6ES_s43 za6-R?0$kDy^oCmh63UH!8ig%}?J(3}fKT)`dQ$c5RO^fIk--lEqtoa>K@ark@}SEY zp#Oz_42x@MIo^k21Y5 zl374?kYk!^Wus+_+LHfWGa)*X1+}ISErOjUA;*n)x;UX55zib^1v0VL!D}V~&Y7}v z0vgl+=Ml{|XXl6-Gy`(X0@NY8NQ0W79?=bmMl@&^Y((^BM4L5eHoSu9dx*Ab(8=&V zqGO15X;3TNM|4(JcFwCB)COf)0yH6dRD(KT1)_TqjcZUR#1MTG(LoKG4<`^!B08i& z3*dT|Knr`Vlio5sZz(oi_7QSZnRcajhUK?3dtE**)y=EY7mCt#Y|2(zg{~IN+FbWs zLT=?2-9>xjL-y*2>=m#sugKo&7KuF2Z&90pgGC}y>=ke@uQTubOzfj2uThTvEAgD7 zDDN2m0=2eBr_aByDADj(`_3_?#VyBjrcWlMuMlJ9Sal;FIyqMVZEO-f@UqRTQ^w$w z&5@JK9W~6c9xmHT>i&Q-?W0`cU=B)nxx_%0DiL6jB^V=jHlCF`!$WfP9aMgt!A&69 z7t;4&zkLQ>1#jB(AMHa@bRdyCrYM~qO&1lV4+q5t)Xg1t?kURE-FVpK*ntSTJHumg z^kZbK0E?sKkqtcR7)CuvU&0+PGWsKWSnhC3)g0RJrPu=QSi)j2>9DKLjuGq%2jN7I z936NAheQ(XKm`X3IxOBMjFda#EtM0IGqsU*7&)`b!lK&a6m@RlSwfw}MuZ;ZUEm(x z!-ad$=CnhLV6QrMcbt4UMb7;ad7qZt%E^C2^3n@Jqr$Aqai%$EKF}|$raT6}dCLWmx zv9WfCfKIV!~q>eSfsq=PK6euHJzsr{Z=MMH0>lo!5`+M$6#1X~LgPk4c&Q0XrOXx+pE1$8>wT?FK_%k}L{#4D=j$tmi zEhV^_3*v0f&C)0?zz-KHKK~`fO77SJ-U7$88C--X!(ny62Zm6E4}$0Y0ca{Hqpk3> zf*HI1ej88X&Lr8zPV=vk+_#1wp0`;R$LhOLJmJAU*9?RQbz~rXh9&Z;MOY=SB6m$R z{8u>^9+ac~o#A93d+*E94{)4Ekkb+0!DJUR*=Lw1R=ttSev8Szdt0f)Wlx^O#Aj1m zK0$Fa%6d-u8mDY$l%HdliDOtr-%5NPHWvzOLulagvwqHEMBipkx{V(p9R3rGv1sz=uT(Lhv9PZSEe7wteA!KOnj~= z3$XniPGlXnrT7Bfi|q^8p27AIl$R_twk8!N4jm;WM(41i9EI0Pf`x2(NO-d4C%RBh zhQ8X6ooONk2)&K}9Y9On^ab#iPSwr13y+l+(=J$5I?we6o>JV^@xoGNH+FNhx4%>{ zS(|O5>e`lSMX;9n%ManFi4~Vx<=cI#`K7xo;s2K%37^hoRfI7Q_l0#B~Pn_y_faRuL~t)4&oK zLhTy?L5;~X>WP^Iz*{cR2-bG}Boc?keR(g_4x}XPR55c?TepmXA_+U&P zSq9b$!IhrpgI+t%PpS}bY!1DEo4ciAd--7M0-TOy-##7oMN;dS#=R+A1XrcsWvUm` z4z=Bw@;1Y&NckJUTKcf2#7c&sztT^Wa06=-c&mi@>1%K*kla%r zY~$ON#wX)`6EcN7Jb5qTl&~qaRSEcJda>$LS2_`Hq{tG+Owm~|ExW5vv7DN{kDh@W zvsco?usAqRXK}+z!EH1S)*1ob(`)?nAbg`{B|aao@mts0MO8@6U3{7iQmp`%TA8lz zm1;K|rl{9hQJlA6enV(wg|EU_-TQj|Cfe(n6QMeyhaZbR>*)+Ga+>{8z=A0z`mMv6 zqG}DNvPlFg`OSe;iUpun3YsG+D*`*D;CTAQ@k_+Y9_W{L;n1Z9zcrmaLssrP3T+Mk z@!vUJc^u8lhCep=%<1!S2tIF^NB;v-$Zt+BZW4Bcg63r=~lSH%54 DPuoP+ delta 3298 zcmZ`+4N#Nk9eo{%@X_mxFY?n;tf&w50k7d*qUk@h6U~I;PbpNFdQ4x#rUH$#RDW19kDE zF>)_j6TRH0SjDoYQ|^;;pWKMldX?NQfP>UzFh`=y5!MXH>4%09ha5BF@JWpk2yol& z|Id*`90_Pu+tc1yYu@l?g?6{*?^o0EGf$kj+-}(m`&7A>Ote~>9LXXFsGcy)3TIVY zXgAzYndmL4e2tY5Dvp6ev1VwEX$3)TrhkyQ-4fTJHbY&Enf{ga)X8X@1*f@GIIJ$9 zcVS5F0xv3?V$Jldq`DxfY7jes*j_jq8v-{L|yJWA4U-phkqO_BD;X7SAoWWQ)_}X+C-h8Kx5&X zh;Bo)PJwD5h-f#WO$sy~&La8_qCZlgiEtayDMVjZph=J!Z-R{YMBVEO)BsN+T8-$N z3N#J&Bf1aKw-snQ{1(xZi2hlDn&BUajv;zgfvx~uf(a565_Mq(n$bU%kNxt8`X$kR|G1%*!p~AujCz}o2*X1mE31Zc zu@a46hd-uvr7o_axB6$1Yb?-51uJ@q8ir>)JaUlhfFf1zXlg4kvgg1WpULIyH1 zRtT1~;aemG%U{GQJOuBg*}3FJ_&61bZ5g?(#1Pfsat3gM#$z$GYXH3-b@le<%~jk(ju`!Jc#*Un@iV zz7YGkOnjTg{)EG!x;pRTP&f%MGD2YZZJZJb1K3UJa5r6V--VGv=U`j$a^%;Pk<}Qv z+MUIsItD5Fq{?h~KSKYjdw_4z(g=6vq1SAL9+T01;r^2NT{$Fd`-1o_rTDNc{uIUE zSr$JZ5f34RBNr^sxKSxClEf<~^Ot$5a-PS19^DBfb zaMNs}=Rm}T?X=`4UZ0f?5l^sTuD{pf;JE6~;oX%v?H2q+UfPNJ&vBe!=d64Ti82+= zMznLV)zj5EHnyB8_ta7fZTJt%0VQ!wCY(r2{8-AW&O5Ty9wpJ`BOxA7|~m&|tN4g)?x#YNXG=t5#d-b^H}N zgDNtB8gh=c*a@@Igf8{TN3%UJX?2twV!_fcFaM3|VEGm+A^cMt10V6V8v`@^Rz9#$ zD+Ha@2ydy*TNFB`G-1~?tg|)X%^9*aKuto+@3MfxDf^SJIA-Iw-WJ7^Xc+SeaM@qZ z+kuC%25;Y>}dKvW~K@m^t%MJll6naZho+rO)A$c)T^GX8=n|3}g_7id}RBrm@5YyGk_I3;XJ2i+$0JnH_$5>K%Un{bD`e59YfD}U4|;7Pco9y6I-Rgmzh9cCiJ(I)y4FW zmG7c3$i?&v>l!E*=HP@c-_RE;Yx<;0_PD6Yk!fAa@5iRs;8gA0DI--*KEir=-y+?U>PWrsI!Rjo3(( zOc@|Z>J_fRe8*`MO{Pw@ZCaZF`J)XJ^=Q(dtxd4C89OzVB<;*m(Ey?)ioSmL?HxRI zy2I_h{d_;4?|ygRclRwL-Sl9T_ShEmWQl|oUK65UacJ4k4bnUXB+{Y3dklSIqEicrV!!6Yo=OQt>xkl(1Kc%ENS`wP`tC0qs;Un~HhQRLxl?c#D2yp33LwR6a+i zAfjn-{XdWTghxFXv<=x$o`2%k#(R4$#s9gIW2ju0bE~jV1K-zv#h!;glfe<{QJl=@BZrFdur_UQJ(NR1BurOl>i6ibUzUxkZ04|r2-DOPmogg#9c z^rU#{e_;@H!wP3Vt05dz)G(f6gEgr(7!h?~OwESv_}r+|!GY8_QlH=ZJ^TY_S}$Bo zbHR98F4aJWKF7?WWsBOh@H+-VG$b7=^+B2kEqWotfq1gm;20v#6`}&9VXcAR=mof< zH)eQMs180s)Mzkfh$=J{G7JJ#A-YC|>Y*CZors22Xgcgd^eCc@D%1#XAbJ7OHWfM_ z{*34hqCG0q4EGQ%N;hWwRE1_kak>B-5$#o>R@j7SH=;2WYJ(`E?;<*^LKnhmM8^;v zQK7kTJzb!S`pxs+)4giS*MH_FWKv%IdH*uguc&eRLR_lJ(ZGFK?m4w!FD*k;6J~9u zqn41HnR$1xzw4p?mWTSAV0%`crOhD{X=u=-G($)7L?T;C;7C?i)+dkQ7)@FAQsm$9 z7iC%gAmvX`nf>_E)%RpM5}N5~nUR|uQZ&OipOAq?$d#hy^|smE{49l0|ro8*bl~<6(p>gpWF zp)d#=TBOL(?=U11?*J-TVc2SNZA7Nj8EYz?V=h-StC0CvnTfGFVif({$IXR);=2%f zP&djge1w1Ag?5_-ngmPPsXMdc-h?>w5%KG4aT^!^6~*i4#Lp(geF)*m-noeD)Z%&*d)TtfuFj;IaT*!U`IptuD+t+P$R^OY;i}E@bd)b^M@)}P z(#)ChAd9s#wzurT_qP?zxL|*ne)z>c$qgsbaIG3{+C0X6j1!tc_PyzTw>@8@8NCfp z=M=VHNKwt;_H7&|+BwZ%>{)J##}LKA{au|`uFU1$3ACcS&u_88)rM|v_#+xdf1u=P z=MC<#J>hUScZjpOQl#=&hhH-E`067bOSz#LT)Ec8<=hERh7(G_heyy04}$0YVc3{k zOxxgxxyxGrHibK}WsJ14?cIywfvtS=yw9>YT743o$DKIl)}hd_h75%+u|z(*2CMie zYPUv0f03f0VJR}$6&f309|9@zA;x(UHJ!0$=5_;f`(0*?ze zHAoq_FB5WxRcBchAG7;{Ei@Q7&|mm>9XsVik0Y|gXlSrpi*WF1-p`}6WkYWV>k_-0+S z`X6|#2EMU6@^PSkb>voHeIPPZFGY(lA-t|`={@wSkDncfkMhEF6L=lrQ_eT3y>Z`j z?r-njxpT|5Eks(sevQZH_BqSErRi|gwHC%*(;JGe%koK_+t>|RX0Pt(xGW#Q_5!v) z!SA$jayz!Uc)E6D+l}odY>z^qU`eqFy?9Vf zYST>Y)qC+*gc!a(r4(X~lO+4cWH|1*yB5nA3|2_N{x5H#N96^(PuMag?)fo(Zil%4?PFRiXC(@ z3>JILWQC|$FhiAc5UAT>j_F0E$L=_+gu&;2ih7~l?VvZ{n0p(DCD{?3AT@v5%0B$M<&A99bwd7sCg zypcZ0$-+p?C4xOU&j+m*oL`_sz}T!>fe_eJvd=f1xNawz?8BK66ii^P2UnS}I(g|% z5XoKTA$#_9CGq)6S}hzK=nqux)-6yj&!V`hZgowtp~PL{F7JQ4`Z?O~ToI-kqJ@`4xA|NucXE#XUxEcw zO!Syl{}JGpey}`FRFRZ IiYwyyA6~X%jJ!?Jq_e7rw@FQaSCZDK;mtBQPDPV7$+9NBRyaf7GsRt;6L$raN*uz% zF6aM?NRkl==rz0YuAg#iM*2Nlnu=dNc;))JjdjzfPQzhMv28VmS{fWFB*&}-NLnlXt>QbV_*%49XiBrv_gPDugJBEdoM46? zZ5f@0VXYUcP`NkVO3y2*ONy!iv15q60H@NU5Xkr?+|DQjqppAw@aR^V=5RD@6%VXz z(-R^P4K(X&>1z0iPJ|!p3~)`C1%J|I8;UmtkVQxa{sdS=?*gJ#Dl`o|dJ)#?vkj68 zO^2@``Xr)FDpUs%M7t5)t3os3JfiO)`dt;84WA%7h3LyFbOo%=6rmt9+i+5an&8Wb z)+73J6`BV}5Iv0O+bT34-bC~)qJL1KR`@HTaYR2>p)0|VB|>&qwjrTH3kGJ~^J(8V zx^y>73ArslG&!)=_y%2vwGif5j-!r{J301y*si&+y*||*7&q;w@VYtIVsr$EG%_5u zGc!_*Mz(wferN77FFuTme!$!)h5wZ}B+K%<+DT~6+gQ@PD9ho{LdTH>`G7-;7^+tg z5?hU2DYE_mzC}``<^-C=FuarJd?*Lm9kZNy$AHX2&h&C-6Jx#rf~Dxu5f$?njOpae z8<|SX2F9#Jj?~rovD6hBm%{I2SGyU!4_YnTX&la3*3#!7Zdti;3`OCQgkwRLyE>oz zyDZ0Wlx&2<+>wrsiE@0Mq)2ZIy1POPQurfO7@#b_XiYa~U7EjN{%!6!gN}(01vr%N z2sU!)@E5p`a>v&h_Z0!V>gt@vu5b`l=#j!BZ{v_i0>CNe!*ssUxeu9A=g@)5W#&#b zvmTib`wAJWV~AoLJNG7zAoRaFy;^r`9{Q{n=oKx#OZS$$0>wxoXOvA!;pLF{@Lp z*v}BM!40cOFMx~_+hZ%u9-CD*5$Dq~H_&Hu2}1p6@cUKnqi*~}FRgX+XV_1qbCz#| z$X$sdL_3G}`@1^h@#Rce)G8^ovNYH!t?)?!@b4MH ztUX$VVLFaXk)!PG%)&Xwp5nRhSMt3k4dW#`khFUwG%Aph(1$D!FE(J2sAq6E^nnx! zjY{F+uFzDBeW#`HRUCMZGOg!X*k5CeSR3<1){nE?j?@g}BogcH%17~Kn!14b$L4w- z<8=-xk`qkwG?%=^C1Xr-?^9V$SdbUKoOlcC)tC1_8~a=)T=^CK+G zvpmcm9;Tm#89<66dqkz%zN}-jj(v;k%DAqN=?)_WM?c8w)6inK3*~p=nB793h9B4+ z8^-V}G>9q^Lk+pWYHWvDZ&H``?1R0%Fll$Kf02=uPjT>x`bfPr@-jwxNjI|G{>EqIhh9WBt1)&8r(pHdifZU?PvzPaubSw4#q zKfNW(Y|CDsmSxt*6|^VO9-5KmDYVbrmgQ_bsCVLatwY;6C(HF{>+wb3i}niIZnVAy zjDxlgnv2#@9ULz*+uRrn7fN~DSk~dMXG)g);mx8Vn-zPGq9XMaV1xjsCu*ke;lENb9O9y>Kco5xH0;grWg?J(%^nsmt% zlkFON+F{P)Fhz9%rN!2_2nUml>b(KK5%9iJHjXi8%0wIb z6u!F95Ir%1vs|PBEG?QW5{1Xhx7tQc58~$F2+kqb2Y)R0+TyMUam+*lQ-z3kq+o?b zW5MV_Y+03-NObUA#dpg4legE@NZ7F^kQ_38AMQ-zg+Ok@;>E4_HS&R~fX_KDk4ci1G6%qx{V+>JmAQtS#PS8~by z({&ziA#Fg~ z)Ix=X0B;0JP5tRy)34m>*?oB;;5DW8{%SI59)psgS8q&ak`Y>ietjU>3P4}bzm#QB zJha%;4imwnm`QD$y{1%ljGDMF3THNZm;RHqn>l(p3vO;M)u*!E2hQ59bPU>Rz53Kz z#-Xp)ua}Afib8_xwf@Yd_4k0QZUdaGGs51wGJR^htk75I&rQ7XUQND5B}4w>(At!elSwE ze^SGH$(9&+pJJ1Wzscf+y;_hTCKIhy&GAauOD#r23GW$dILiRX=>_9N0Y@haI647g zRipF&dDJF6YC)%N%>F_B@&3G?j?R_an(X>jXBXGy96STBsJ~{*N1w^y2yu{hY9I`= z!zuMD3h;4d_#|VKY8AYc$ZAdNlRLo!`elaHRFY#WW|3 zrR7o;WN7CaS+s0XTXJ5|5uzgLP^Asfd}!5LGVF*aixqkiaV!yJAPs93{7!3uD_VVq zM}cbKQ$+PTeTJYwQz1iVfoeqS6{r?!5N$#dyM~DIB9Et3eF^C;qY| zNoQ030#(_I7c74$N#WpBN9&Z-VizMB-r0l<<{?*%R5akB6C*X>!6x1hN3xysq$x@2 znB>gs8OU^SW+rD=GUgWeJiD;^59l|^{1sz5IdeE&_UU2FLga|u4VT64U`!03#i5om zcrEx%E9rSSXj(|u!@H)O#e*mc563fc^zN>;S0!l>qht~Ga>Km`l60*TPoEe$6hd=% za7qk+jEZ$&Fc;2m;;fU%dQ`rO8(wGf`D%FHZ1-1isObrAE;p=V+|N`vRCm`H4uwHj z(ISS2|A--xcn4668Ai+o=UQZnUD1}Z8D^D|S&hu6$_dtN{b}(4r^GX#5Fb^F+qwAfC|*4y-jERYBZMP+W+Gmx6c@osu4>elaKoZu9)A5IRqYy~RSwR`Z~+@iJ% zDT*1~yNBaMx+eL?zQ;}RD55yHueNj&~o52RHJ=^8w4^NX_rjdE9|xZX6DdsK{{e5=-PW^;pHPp>|_9 z_%|^U91+7q-NDg8_976&A7Pv)P}3FN!`!Z6ZokJYk&3O{?MCMI!wIPxmwog!rZ$_} z^D~n9OtOVbzRo3WO!8A4GJX=P@cZ$nVSAosQvf@-{A`>UG6uJE(FDGgF#HB4sz=J; zR}vwoS#^e0@zFcevg1tF%w?yzY$=o3P=+qP&7LE0BQL-5BQ|g_-W`l%v}Qa@{3#9L z>*v^2%q~!|W7H9D#Ve*|Obj=~#qN|%us+|cWl>YKC|63~}HJ{+M z>i_2Q@W=j!<>9;j)&B5QgBU5fgz%~r3m&3ZZT!p_T*wd6b>OjwPC9z2t$Eir*LSx! zHEr0mfrzVD*SozgucO>kmJYvgJ_BRU$u-3{BC85-md$x-H+`hY>$AyaDIsay|__L>e38s z>pl1@MhtgPE=5@5B+2ekNs7Xu!a|z?u!ESK2;fJa~ zMyk3(qfgTk#`*w%tzay&)BWHrnyd2Nhi8fk=sws{w9M9rS3q)5qlKAR|S{xTq<{Rj{RSP1yf9L z8*iowa_?p$n*^YKx6YGDF%MMveY#Mh7lJ*0-*oy#@ioWFJ{a=1Vd(x^w=tPKF(bG2 z!QNW;^nX=7SscyM!+W(ZUGjV!gD-2B(c9n;xOK_Joq#<79Jo-B6(M*h;7d>D)nqZ; z4=mCp(?APVbv|8k7Y(qd&NqEeJn-;XO01 Gi2Z+TcWK}N delta 3388 zcmZ`+4NP0t6~6bG9~%tVfU%u`jSW>o8e@J8hPE_zz~N={6uOKSq)q{CO+uSBRD-Ui ziAYN6YJoSpQ?_K@k(_kQR5&iy;@-RGBrG}2E8OquOj9>NN*35h)T^0reNU8)Qc-OC?2HQo%~@q(T@ zy^#doi(8`OeTpWDH66T9YCOCVvpN;;mcVgp)SF@~Q_O3E)AVh9*v>g&yGL$>At3Ct z{lADL7LkBPwJ-bdGur6S@2q^eEAdr-wuzKfW&Gl2a74A$oQI*-CP(tgF{&dBv%r{Y zFYSkqRYrPUu7AX82$d(m3rQyENaz4D(L{eQ`<|A4Er}**N-)uPST8XH!{)k4x8Zz@a)5)1ljQJc0hJpts70h2Trj0YN zrN}WG7_%HXVqfEjVxKP}2HwJ<_A~epv>Nu%Fq}1PqfbHDu<5>O6a^-u))h(W>wWYe zk~E65WHX%LjwE!rR9zCZ*#|Kbj-XjKv#~{ z+sL6KU*JB#9p7Nw?+G|mU++8)g_Ed4j~JMI6Q@L?05)R|%;)HAhma}uj(3)?GnQF7AzqClJDsOV($6SSc=(#hYh~*Zmnvzrg&)yukssFKgRlP*VO1Aya<(vRbiY zuOeiIYbGPT01__jfVo&ZeOo?6Tu;l=$dK7C2>#FDkDCj-x8N&!ZLga@!*PPWxA`$_ z;;v``qP^oC?!Mk|cs*0tyB)*r`VY$irQ=$n>~NrC=DTuM_1@qC!{}jK`YyUKpbK>e z6cI1tMS|YN#f=e9aYq;(v(=c9k-y8+jGz`zd4Nad$Dx*2FvwhdRy=K^@OG|)z6Yzh z+q$bTOwZ9d(#@XER9waAV?6iWa=zCjW4ve&lJ-yfrUWwSd!Oau#RjaReg+48?}|a+ zlo*)k^UaO2_p}(eiWAR}m-Q?Q`&*1L+QvM=iU`Z?V9f+BBD#H1>c)p@?gHi?Tk9Cc z>m8RR&ojy6T=E8&Of$)yPbDd8KwjW-^bKrRU+#Ev^mB=j3#_`xs^}@iaYNb2_p>lh z@-PQ@m|+%X1SzuYeuZw&x-Nm~4s%@z*9|e<5v1Vk&$0GAv{)=c=^`An80h2hLyNU? z8s9?aP(?;jLoTouJ7G4O*q3zz5#O-GN2# z*Svw1MltB{BfQsNv?}(@siV#X*kNtKt2AV7frixf-{cQbIB)ag*pO^rYOec4lFnez zPj5&PJGEElC5a7l1?>s6T?>*lhxUn^lBC7E`e8h=?PzpJ`m%t_KPyk1aXHsQ!2RK!azHrNbagqZ@X?GYS* zmVKo7(seHiwP{JJf2y>}YQk7o@MnjjLMttW-G!Tl@Dl7Vw9^s@6xP!wc&E^q*nn@7 zEWF;5)wuXVeM7bfHMokH%?FLcnd!nCixsn6V^srRa#*Mi+8jZLh&fqL^UGV2pr#WoD8z+m1pf5AxXOg$f zpfX@|FZN7w&q&npRM~e*hhrbG@tLrjO&}R0vH`cn@O&_rJI%V-cV}Gnt(dm~TFZ?B zZemw?v3cC?k^Ol6%4HO5O7vt3Cd!?7!7gBp3w9ZI$3J6ZM6xV5vhg%LaY(l5a;{{O zjmxzmP6=DmahDNeo^<`&96#rUSOhO}G6fxR!BE9Tnh&j&->0pxP`Qtm!9(tPA!LCc zyPu{Z&{r90I}}wp=~ig2+K1G0RZe}qflozFNDNsC-fAQ0s>PA^>ZXK|aLpkK<3hrS zxTA#%Q2}1_6zhkRxMmn%o2*!1#^cn-&;DvGX&!_kuT!IoWs(kBy>5*s*7LxS*S(fy zA-uO(X@?naH)c}XPNzPe9aDPl3&H7~&b7ZK?O7bXoC?=>7Hi_!?gCqFJ)MTOTBjzy zmth#Hb!)@|kE{^k<63vh+WtGhURMbx>U40hu0#_*E)xvZxijNWhT6%;x=rAE-RGEQ WGd{PbshWdNK+!HYy$r3pw)_|Q9~4#q diff --git a/integrated-security/web-overflow-client/_10/server.c b/integrated-security/web-overflow-client/_10/server.c index b33e7f42..a745f5e6 100644 --- a/integrated-security/web-overflow-client/_10/server.c +++ b/integrated-security/web-overflow-client/_10/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_11/server b/integrated-security/web-overflow-client/_11/server index 382a5e687ea4b3b75aad74dad3f91ea0f3fbc48b..54d3e3289f58da40a03f0e993fcab1089f62d6b9 100755 GIT binary patch delta 3568 zcmZ`+e{d7W72cI(TQV}1kfoErSdwjqLaZpzJ77{Em=uRV z%V27pq8JS(FEmX_GIa+!r9)GU|0s9@$W4f$O%s#S44p!8AeoViAT|)B4DVlWrADP9+BUO@mk+M!b$17kv6|9ybKC)DEmIV&dkFAM(jwbRsnt+I| z-uwR|8j}%?VA9v;tg%$wzxdlvltrfwnwIQ<-5pQN{v3X$|CTEcW2PoYh=;UL3t^ZW zj_VgwfY0;-9aj6dp*T&X5!hhZ1Oqh&_*|buPpF=)YJUmN8bt7?Inx{%&;wmM8+4@k z>DSPUx_*`O66>KMq^e;k%?Y*XP8g63U{240)p*@xFu;!Vx6*&I@df+?PsU+5o8g6_ zj9jXNEaMa_n=RYa=E={Q2+@&Ds5FLX9&9xVS#HEr%?X`|c;-kdkb%7p{%927g3+Ai z*PsTth^X0Q&XP1}I%Jsys6w<>gBqb4(Y1&+XwXbphv=J#Hfc~ZyoKn8h_-0ZiSTzs zM-lDNpjNnt=&Ve0)^9Xu4iseyunf_|8q@*H5#5DoOoKWhis-wD_G{3|a2(MDq5~Q< z7p`RrbZWPC!h42SE&0aFK09UQNFXuR^F@p4#g%d@w*B_j9rT2#}wFHa(hy#)5z+HDsf!yL`FIyv%1e2bze zAEf;aDsvv6vEZJfM8c!3TSt{z9J7BW4Yna!CMjJXCb=M+@^8RMpy`xw*9nSGgROh025AV+SmJ1@6~2js{Hm}(w_ zmqF0}B>fQf*k{re@UDIG<2@*f^u@C=dwbimON!Eivt%>un6rjT?4qx#l|-Tom(*@5;P+Fzl4 zWmr)XXn%S`QOvmbV^}h?(8j+}l!a*jgsWVQwh*7LyU@Od_8i*%P+2gYI$=eD%~gi6 z@P4VS5PMt}X-Ozb459@EE+=L_jEYpt#S1orU&5IJx3>}Vv)v})iI$gjp{#U$xxt)a zB#iYw{18HH1HbMC;r!hG5R&lS$6N1>}wNIQ&2-`0J$&}OtY8LOp~L$&LY-X>U4 zD(FV4U`wgb)t@h^PJF|wtp|HbtYiRsOGTQ1VeF0IEfW@`KCF{Oa#y{`8M|F6e4<)N zlgPu1_aaUSThjJ20UvE|lzr(+6~b^*97N6}odrv`v-~7h(Tdr-={XplT~80dqQHEe z#SOm>yhvkUtq{;Xqe7(n;F*egygpVTS{v<>8c3~HyqXQcN&zgDGF{UhtXyxHq<$bv z()@)BYC`oTz7k(~_dC_k({9h42C5@^__^e>o=)dMPP5-0*s#PT(Rw{YQb*U5)g%E8 ziY9-u#Qabh444{{qXyU<42+du3}0oe?S$UoHk^8}Mzp4iXTZvRhhck-IQGk_!^TmY z8U9k^Go{YQe)y(lKK(BQL!v3Qxe3@D3YeA_NUCBf918_9Q*|{m3+{wwn^I+9gvz-A vQ|c~SVDsF-*ufzp&q$y*B*6K(aXcoy;ee^BlH=Qe&I_2ntmY#J?uh$;4i9Qy delta 3413 zcmZ`+3s6+o89wJOk6oU3f%WbR>;uRs#N~pl0;$AZVddJ{R;-%BOd4QXqa-#Z6HFT) zg9b_5flal4ZM2h4m+8cb8JlXDX_ZC=Z9_6+jj>F|IM`wz<08a@sfmvzxBt0k7j8&; zXZAe4|NH*)pL70u&)Iz;I@U|~TeI4;y@WlyBxLN-10_dHVyXrb@xaHj$(PAHJ}^_+ zcO`-M;x!R@pJJ87nr_}FHD2C`)uMrS%U}<+>r7*>@+O4<)f?F;E0p#rXpdO9Znn8 z(_Xl4kmyaVe3g|Du1J8rNml4c=l~_rO8=nQp4V(GiB@P#u+k4%FEJC{I^l$n4f_+z z=oAbk%20*MElE~-T2r0VR1JvjMr;QhP6~rJ`FC(T*$JXCj}mYjbItcK8n%kt7PgrP z5r_erjI}f$er1&4HDfw_Y)pj<#=h;GrLDR3ImcM$!F4o!nk5S>JHpAOA{{1gfDQqs~7=}HtQ`A{^p|Bs7ed0$`%wZ>gB9+59Z6Cdcrn>Q?O6 z2-)Cce= ziWDN+J=js%(>*#mmnokmYALk(GnNB-!!>Sjqhb7IEvve3afg@D!j|+hn$V#Kb(?h_ z&*DLX);o9RdpyDoqiC3@#*7^Mn-=C6YH^oe;$Hc77_}K3WF{UJPumE5kmsg*sE(Y8oEYPvCYf!8&wLRRdUWz!!ZB))%nu#d<{) z{a_t{b%l%EB6^WgP3n?Gw&i8`TY?xaxAqiaS%<$vld5_gUN0=PIWdkf>f=uyHds8b z!1Y3hs~Mx2VD}Y&hWL_Do1SF&haoN5NEqu+_$vWdk%Lx)uP9ge*FAWmsDM_%o}zkN z3w~1KgCbA6C+x*x8vCyoNk&{1r@0}=%Pi!vSnULpTh8*}QN|vdR$@^D-*nrl2yJee z9*4tj2erc~w`?}XPE)p{>}iL4ZihK+^lCkJ*Iw)*nWn26z z_+@|D7>{|Wg!d=kQj5WY-hJ4!YCVY<;n}4>E;N^K_#yqX=)W$hWjk`gm{4~8maIs(&J;)FfYn)v-TMkEik zMh@Vo*y8&<9rNHrPL?1N5A-cNOP$cV{HL@P zrk6LMs?-$E zb`Q8}>*-}^tCdahwH$%IS{%60t0}y2y|yxCcKzK@P`4Zo)rqjBuFMqQE-UoaRc6KC k45RiXAmlEAn{{7cnvMG_O^ww&fTy8&btOFyt*aOP54?98eE{SpfBwO*v7YJCVw)4VhS8x31vu+9KO`doTawQN)Ci}1O@3%)danhhPgphuSj z-Dy7hABdxFK;=BoY6u5aHH@U$p())CgOUNv>AA2LpIZ$E*qQ!H`lij#;vcv&j=|>{ zZWzhPqdLek&Jb9%Y*E{$KW!pJM>3(>7^L~I%_wF$5loP*Q;mtab3FQH1kG zbCyqo8sGw=W|KKf(xB;(WfGwV(IyRQgjz(`BO2DAnXm!TgNU|jP&2%O=qHG_YtX6i zcSOe#?be_I+(ooF)139H2F-<%Oc9nLdQ5}bU^$|@5shh3J46wE577Y)Ivq|RI*jO` z2F-)3nIfIpD@=Lcu-8&xyyPL|x-#pV-no`HsCn&lT&nAr13xHA_wi|)X$6|vFl)1& z^@QBW&cBWQ4fpj|-Pd0ZYjg6g?M{iv{c(%h^dHEVh+-{+136te7aqnj+H#uZ$iEXW zD2no7+TWl$cmABlyNVJCjdyGtSK6F%G|N4ekiMD7m7|r-cx zQ98yr^IR4(U7VTCnN^Ir4ld;u*1U~=Q%qn?H)r-|sy=;;S%@6DtNE=99j3umvF;=CZDZ`r)KjNdG$+5=nFb6>TtJv$&TbQ|^qll}|Ds(lTq1`EZ4Wu{vTD{fyw@LO+QO2;HkY z$1Qw>ukOGOyA|3*YsK-~6XMsB;_L^+yS3tWF8(Kqmrjb8CdEAn;mE$ph!<$Z1*&-Z z70;yoE2C!a*P-2RpSiD_Ez88}3~3oBkl~v8u@-s}AqVu^Mfw(8v|AsK@@4Ia8F5M0 zab_aOV(pA=uDEyqeu`#Xu)mJozp)Fs;V2re)WQwB*Sv*sLgUE3JJ#!Q6zFu9Z^7d; zingCj)6C%3EgUD>ImS1(hno^HL~(F`SLgZjleza2TG8D%-?729hF@{R$7s0xTQyHR zuW^T)k`7zAL!8a|VvWZ|_$EV-dmr#v&JA0^ooAahn>*pj@VXlCzCrZDgW!3;50>SX z(02G;-rVi~x``)o+c4SAj`yo5?pw_d&j&1vqqT?7dBTNbuI>*F=tzI)3`^uwO;{x^ zqjq&9^ba{28jvILuF!BFdlATyPchD;sOgMtWo{dp+g~tCv~mM?`vi0Q(M_cWmwoso zCO(_mQa++Pm>;jcLhFy_uc*V4h$dTrR+?BQlR_5D`EDG#YvkonT=kp87>iGp8_{pMZ z?K!+w15Y$Yz6dloM!pLy4MfJ9dqr7(I_9&DV&MtAG7cZ(w zeTIc?y$^pih~e(3r3h=BB-u5rC^6_PEOfXqj$^1#l{|c4@f?D9q0`-h(JU}vH#F7q z8(lCfU0-Q1XBY`%eSp6x&>|;22=1a8x`x}Zps0Yp3@eKo95K8CQiCE-{UF(i!@ScQ zFLD}%)?A69mv=xvAV~OW zHVZ7iLG(T96ID)5nx2@558S094P$N9Pa!dQthB)~C`hVTZKWsKq#JsWdjviz^*V+M z{ud{QG=WeiI#Tnz*Mk-37bp`kHk)1~1U8m!DIG|DZl{>+#j3-xNOB!hxI2kU;3)Sx zjI~nAptc*5)>c?qF6zc=;DvIJ<8*O{rb9z}9;I#K9rz?SVcZ9u(nheFBe3JmfdER`W=<1AWAA`nHz$ JY`7xM{{lPLYQz8l delta 3387 zcmZ`+4Nz3q6~6cFg1f-VF3a+E754|oDC+X~S=}WKaaUMWoUVezeE5oF3}y002rN_z zUDWed(h@UoQ#7fp>g8=x5#*JGHS2h@7+$2J#hzf<6J9$Ur|(+^@;GN8FQ`@qAR=t> z{J)4K5s`pVw0~&NLEJza}H!Z_-M1xx3DMYIg z{iO!YhJA?cMf5EVnghQ^^aP@R(x7(u2cmtjPwjsT!ZFzUn`i@|Ja;o zxKTvNZRN3%?#1Re=u)hOF~>4pRfK$!>Aa8aiig_ElI`vxOB01xtXVd*D@f%2zL=Al z{zYgM+n3-E)^_Xk5?u6V>jpXUpZIP?QQl1%f!gfH3u~tpB@&)$-8ZE)yX2^;a4sP| z3y>>Emo?*CBu6X0hbGTPT3Ae^)zX3I`EDj~wZL3x`DF03I<1#&XP_9mtg1dYj8;nX;By zjm#xJH)FN-QjBBf-uOO*{#Q4NuhmQsHz%RfZi5cd<~w(PMtqJ_;;zq$PiV!5xcCzk ze|=Wmlo0nJggqC}j`*uuaj7bvKT zAmo7Sc9EU|1t+%6QIv7@p1O&+gLM<#osK*~sQwJznP1S7gP-V`m8ks;`-!&Q)vRi}$piicJ=jDcMPIqq#QGH=%4B^hfs^V+`^;sY%!=a=wL2BDxS7+ct6)m{|?i+ zi(3L1rgh&aX<={YB#L{U;koZu^S$CO_7-nN($@a)MS=8(FR?s4TZ2Wsn!%Cq2XZug zQI7PrhevzZcUq2Iz=3C~)7r(tzRtpKXP)S?A(q?Gijyqt(mP5EzD%QMFf-X)Ph-5c zURClulRV2MZ*s|dOmhEIMTy&x7dan)6YJ&Yo1W`=pb&C~6=zuyKZZCiDC>C%3-cTg zvyF#|u`u08QDtAy=+@5aK1EW`x45pD>kc#BUZmjYkF)w1)H$6($sO45w9#kbRi|tD zRs0H_LKW#j4LQSVY=>EIa(l{&M|(S9#F@A3B}P_1#i1`(M=RDj2?=dn6S*APuqJXR zv_2G>+8{^0)d;VvE}WKIM-6dl99FpM@FYygQ@we_n6n^D-3XjdZp8K`yKUS0z z7*l^sQP`%vKBg$FmrH1mp#8zPqKu;5b6Zg|@TlI38@3c}$AqF(quq?JdIQ=^Xb+;T zn!-3}*Tb6ph13o^^Q{ga#=<35p8_na@E03ZlrDHJKi{$FrlQ19k$iHo!bb2aT*-HN zwqgGx?2ZziYkpa%G^Of3(q+ss5XSl={z}17;G!WYFPJZkPQb>3JQ{>u1*>TT^c9FH zb@(x{;^`(DaP9?`n(QEI2-%phZZLYKEFT_N>~W|i78USCualZ#yH}!JaMbIfPB`V2 zEQZ9H$@YysjWFSLSz?Bu+F~~f_5`7@Xf3LD6}fa5<^&;>{tPYzm9E3@1iY~n4`Iyl zV$p#w`a+NRENLM{%qq0G3h_ zw>wm7)7db32wQfwB@zSdEd5SNSK|Jf90@zv1d>UH9>P5d+zpO0$ze`hJCmw!CcHIJ zUnUB;h`Y;*99?-q)sLsI`t)E)iG}n+UztP)U>r-Fuuoi*yu~JnWKykU<8B0#kZR|u zxspX5o~{RRO4yWM^obbrsPC2|xzFQ?2qENT31;Gh&Sht*8|s(;h}OgS@-4I!p7yU6 zVovy}{{+glUs^xH`$_x!v#m3}z*`c$_pOt(w3=;3_9)TNG Z4=~M!!+ztYat?k23Rn5*d8l8t@V^yY8WI2i diff --git a/integrated-security/web-overflow-client/_12/server.c b/integrated-security/web-overflow-client/_12/server.c index 46711cda..525ae72d 100644 --- a/integrated-security/web-overflow-client/_12/server.c +++ b/integrated-security/web-overflow-client/_12/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_13/server b/integrated-security/web-overflow-client/_13/server index 07254086a9d8aca44ba9e61b1442236c22cf511a..248ac40e560c08532e3c266e7aa095673a896d69 100755 GIT binary patch delta 3516 zcmZ`+eQZ`?g zG(@tH4KH{NJwsbZnHGs6Rxw19Kek4EIBTit*0t$It4^aOrEGFUfCMN@A@uFsckRT0 zb`{_I&hMPxx#!+{?nj0W(ETymWt-7eAQ4u0O^9LX!G*_+@-!7B^1*+4jXn8X=mCLx zgOZ+0>6VzdOtHzr-}oXfj|U|6Bi-7x9Iu2nDhj4zE}5#il?i@NKNJFPjt1Nu4M0@W z;QD_a4JnTXFlrmjznrz<`S1Sc#dX{3YL-4VKs*c1pBCW9+9&Kq=rbK0Ax_dtO@v_% zIHO%n0lv_RbWE*(3nh9ljlvGyE*PrO!Bwr9o>et_)cP`fr1OGLZ_``Rp%Z#E1<a8$i zT0(B;7u`d7+avOZN91*|xuD3>>X3+>7%-_#;&72f6iX=_F6b=y>`CmSxu9N-{yVu_ zQIvP}e}yXZk_9UsC`vRu(Y|LwX?Do5yq4*N^v_0HIaX1Rn@)~ZKaWka2VOV3G|B{= zGh6fWxuTLOw!js$JMc$z(>~5!T+2fjF76_cqq^`hOE=oco%Nr}o#7!l`Yw82#^ALO zw5+1Wt-)h7@yYmxB;i+jDe3T z#A5A;?<{|K{oX`1j`{rfqYHbGD^8%|S~c9Zd2@F$oA3l$KN#=x*ym_8!*}7CS#$TA z@Jg6my}Ng@pIFB@Usx?yCF6)<=l;%)OP8i{Zy2u`bob>~tn*C8AXoea6~jMM^R(jz zcX%E(Y>^tdLmbVeMHwDf>Qs-fKIXBED_X!+Xr0%>o$&R1Lk;-Q5PIQ3@Vq|+YYU5M zEBw50;ogt$;7;5#LiV!VJdWi4jePUG!?HM5J&MkgPV94IB0Q)eiSR|1$mi;?N)97; zV>JACITjw2qXV7ck$!gW%h3;T6ep0=5pQ8`yP4Y`GEJ;v8+Ut>xqa`B62NI6Ig1I* zChNH=N+Y9e;gqL1CBZ1a!Y-4&SViAXeg_(7iD3)+gmo{U%snWHqoTP^e-8Erpkh=9Jd*^E&wbm9gr7 z;VByY-iqia!TJ@^uYzlW(TRFFR(uiR)hib~K(B`6xl#DAC_>kP&k^Z$UZM7;UE4iB zXxzGW!=?>HUbCjoTjD8kmix+bV8~U6(+0(J?i;U;D9Q;O-ccxV&tLEY=ENc#<*&b1 zl$F>v;4n60dlB0M*w*4PdJ)?-(B@vH_aQe9AG_W93)dCp6g+VIpZzvY2nkO&{Ztdm z%hFcpaZ=sy#U?C4muA8ioF6^DybTrJGJZw>Tw8hgQQCAjlxO?NNBI#7hGplv=a}E=dweXFG(Yf1zh;y@V- zcnoU;xXQ&9=|^(Pkla^4%#+KL#;4=@5;B9NpU-LBg*YW_NNwdJo?EY#-?XO}ek^4a zM4K5J6DE0g#W~sq>leR5FT&X32Koj(?O(1jIp8<`muMV>N)goyD!ueDJX_g--)~iV zg-sSob)@Dtel3Pzl?bLPnQrL|RyFEosE=JqTE22cO{k&NQ|hVcJ6XM*_BoeEsD^0a zCz40Fkj0%`VE;#8!IYA`!i{W6m2RZ6M*|AM*-I9iYkf3EQu)BE8ld|k7gE`eakYfMjW09rzR z>?H3kz1_USajxZYtJdVVaK6HW5;5$Q080 zHJBm^JFuGYp(cYl7G;jHW;j9LHdtM9jMXJ;tq|gN zIscy{i8&I`s&?hParnvTb6vspx$Ezi{j;Ke)w_G6K{%)?wB(~_VsgYm4pTj0m<`UT zcF;b!p)%3iQu!h)AySqEN0QCZp41M4+Dv~haZgKJliCaoNoM*E>!~x*)&ZxuY&fbe zp))Y5_CO^nTawN6jHEg*sp=3rjMxDm;S2EvH;A=;uqQ{fDvZz1|)1)2^YB07y|j{?nr{8STIQ`2=XDNqAEf@l!Y zUn|fYIE3gyMBh}Px$qjIClUR#0yV?m5gkYLngY!OU788f)6#WO1!^7QSKUkcxxPSi zyO@xV#Z^;7YxJ+uwb%+^j%C_w3Hc<`b{G5A5A@69{h`yrys<(Rvhr&rzA|r&x-oz=9D1g(H3p2TT=N^m{x<@+7mLp$QMg}qR zA+Li)b&XK;`Hsv+4_$CopOM;7fi|Ci-}k|>l3HxiT2Nmqeg{7{i966pchJu$c~)}TM&WI%o4yN6)-|1#Xw!9Q znsl;<@vAtc;m73M_euF)Eudet3xggX3tZ;NSl}wl!*g|5M1u?t1+EC;z-1vc+8dZ2 zX0K%-bP1OtQ@X8v%=Qj?47V~STt2~aJ6uhf?bRC zlGkNP9+TX?BZ^TY#)U3KU&nUUh4#I}_eDa^vf>;oqQ?=(1!W^2U^aVYo87X_3@%@E z2ty>ods5bw$hsR$cMwBx_6w{%15Gv?S2_oWZASV8ykN6eT*tT2X;hJ6 z)R42Rg?k~5CiJRLelgn*Q?`QgBP>{Y^YY&ehO2kj2;p~b4ZX+LZw<}y-{3=w^+MPk zM0iKAXi4ar)J+l zEq;9i3!)grIvpS57Oan8-G}uZtgm971Ou*Z>bhxB9E3TSOMMMpB9On**Eq!v4}lE* zvs{fXS#?vDo}wXEg#L)Xo46{T&+uQ8cr$YU!rv^W;TXCn^nosw1H0^)@d~`Q(#6dz zz?GGoEoOW{;L0a1mQ6=6NIz7%YAglsvCvSLGcwr~*}yzG0LM!-;MqHR!A>7j+tSh)*BPgi;jTa13mNJ?L9RRCXQ z0)3S*)K=AyG&Eklhr$S#G$d?nqFj`NSN+9?!DLx8h;Ku7*yP#PFu?l~SryU9K5a0`cVgzWZt@u7*>Kq)a}hYP$&>hV(UvWv7t-MN zrebY8yS?D7*+TQ6wZ@~3ucZ|RYJA$B*q-&kjT&ESV*TAvP+I{n)#{<8wnQ7>E;9_& m`m*9rg2p3{HBaDn?R`wM$$(GWP$h%khoa3sdI6d@ul^s!>h*^J diff --git a/integrated-security/web-overflow-client/_13/server.c b/integrated-security/web-overflow-client/_13/server.c index eb2e0cb7..1c367e23 100644 --- a/integrated-security/web-overflow-client/_13/server.c +++ b/integrated-security/web-overflow-client/_13/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_14/server b/integrated-security/web-overflow-client/_14/server index 07254086a9d8aca44ba9e61b1442236c22cf511a..248ac40e560c08532e3c266e7aa095673a896d69 100755 GIT binary patch delta 3516 zcmZ`+eQZ`?g zG(@tH4KH{NJwsbZnHGs6Rxw19Kek4EIBTit*0t$It4^aOrEGFUfCMN@A@uFsckRT0 zb`{_I&hMPxx#!+{?nj0W(ETymWt-7eAQ4u0O^9LX!G*_+@-!7B^1*+4jXn8X=mCLx zgOZ+0>6VzdOtHzr-}oXfj|U|6Bi-7x9Iu2nDhj4zE}5#il?i@NKNJFPjt1Nu4M0@W z;QD_a4JnTXFlrmjznrz<`S1Sc#dX{3YL-4VKs*c1pBCW9+9&Kq=rbK0Ax_dtO@v_% zIHO%n0lv_RbWE*(3nh9ljlvGyE*PrO!Bwr9o>et_)cP`fr1OGLZ_``Rp%Z#E1<a8$i zT0(B;7u`d7+avOZN91*|xuD3>>X3+>7%-_#;&72f6iX=_F6b=y>`CmSxu9N-{yVu_ zQIvP}e}yXZk_9UsC`vRu(Y|LwX?Do5yq4*N^v_0HIaX1Rn@)~ZKaWka2VOV3G|B{= zGh6fWxuTLOw!js$JMc$z(>~5!T+2fjF76_cqq^`hOE=oco%Nr}o#7!l`Yw82#^ALO zw5+1Wt-)h7@yYmxB;i+jDe3T z#A5A;?<{|K{oX`1j`{rfqYHbGD^8%|S~c9Zd2@F$oA3l$KN#=x*ym_8!*}7CS#$TA z@Jg6my}Ng@pIFB@Usx?yCF6)<=l;%)OP8i{Zy2u`bob>~tn*C8AXoea6~jMM^R(jz zcX%E(Y>^tdLmbVeMHwDf>Qs-fKIXBED_X!+Xr0%>o$&R1Lk;-Q5PIQ3@Vq|+YYU5M zEBw50;ogt$;7;5#LiV!VJdWi4jePUG!?HM5J&MkgPV94IB0Q)eiSR|1$mi;?N)97; zV>JACITjw2qXV7ck$!gW%h3;T6ep0=5pQ8`yP4Y`GEJ;v8+Ut>xqa`B62NI6Ig1I* zChNH=N+Y9e;gqL1CBZ1a!Y-4&SViAXeg_(7iD3)+gmo{U%snWHqoTP^e-8Erpkh=9Jd*^E&wbm9gr7 z;VByY-iqia!TJ@^uYzlW(TRFFR(uiR)hib~K(B`6xl#DAC_>kP&k^Z$UZM7;UE4iB zXxzGW!=?>HUbCjoTjD8kmix+bV8~U6(+0(J?i;U;D9Q;O-ccxV&tLEY=ENc#<*&b1 zl$F>v;4n60dlB0M*w*4PdJ)?-(B@vH_aQe9AG_W93)dCp6g+VIpZzvY2nkO&{Ztdm z%hFcpaZ=sy#U?C4muA8ioF6^DybTrJGJZw>Tw8hgQQCAjlxO?NNBI#7hGplv=a}E=dweXFG(Yf1zh;y@V- zcnoU;xXQ&9=|^(Pkla^4%#+KL#;4=@5;B9NpU-LBg*YW_NNwdJo?EY#-?XO}ek^4a zM4K5J6DE0g#W~sq>leR5FT&X32Koj(?O(1jIp8<`muMV>N)goyD!ueDJX_g--)~iV zg-sSob)@Dtel3Pzl?bLPnQrL|RyFEosE=JqTE22cO{k&NQ|hVcJ6XM*_BoeEsD^0a zCz40Fkj0%`VE;#8!IYA`!i{W6m2RZ6M*|AM*-I9iYkf3EQu)BE8ld|k7gE`eakYfMjW09rzR z>?H3kz1_USajxZYtJdVVaK6HW5;5$Q080 zHJBm^JFuGYp(cYl7G;jHW;j9LHdtM9jMXJ;tq|gN zIscy{i8&I`s&?hParnvTb6vspx$Ezi{j;Ke)w_G6K{%)?wB(~_VsgYm4pTj0m<`UT zcF;b!p)%3iQu!h)AySqEN0QCZp41M4+Dv~haZgKJliCaoNoM*E>!~x*)&ZxuY&fbe zp))Y5_CO^nTawN6jHEg*sp=3rjMxDm;S2EvH;A=;uqQ{fDvZz1|)1)2^YB07y|j{?nr{8STIQ`2=XDNqAEf@l!Y zUn|fYIE3gyMBh}Px$qjIClUR#0yV?m5gkYLngY!OU788f)6#WO1!^7QSKUkcxxPSi zyO@xV#Z^;7YxJ+uwb%+^j%C_w3Hc<`b{G5A5A@69{h`yrys<(Rvhr&rzA|r&x-oz=9D1g(H3p2TT=N^m{x<@+7mLp$QMg}qR zA+Li)b&XK;`Hsv+4_$CopOM;7fi|Ci-}k|>l3HxiT2Nmqeg{7{i966pchJu$c~)}TM&WI%o4yN6)-|1#Xw!9Q znsl;<@vAtc;m73M_euF)Eudet3xggX3tZ;NSl}wl!*g|5M1u?t1+EC;z-1vc+8dZ2 zX0K%-bP1OtQ@X8v%=Qj?47V~STt2~aJ6uhf?bRC zlGkNP9+TX?BZ^TY#)U3KU&nUUh4#I}_eDa^vf>;oqQ?=(1!W^2U^aVYo87X_3@%@E z2ty>ods5bw$hsR$cMwBx_6w{%15Gv?S2_oWZASV8ykN6eT*tT2X;hJ6 z)R42Rg?k~5CiJRLelgn*Q?`QgBP>{Y^YY&ehO2kj2;p~b4ZX+LZw<}y-{3=w^+MPk zM0iKAXi4ar)J+l zEq;9i3!)grIvpS57Oan8-G}uZtgm971Ou*Z>bhxB9E3TSOMMMpB9On**Eq!v4}lE* zvs{fXS#?vDo}wXEg#L)Xo46{T&+uQ8cr$YU!rv^W;TXCn^nosw1H0^)@d~`Q(#6dz zz?GGoEoOW{;L0a1mQ6=6NIz7%YAglsvCvSLGcwr~*}yzG0LM!-;MqHR!A>7j+tSh)*BPgi;jTa13mNJ?L9RRCXQ z0)3S*)K=AyG&Eklhr$S#G$d?nqFj`NSN+9?!DLx8h;Ku7*yP#PFu?l~SryU9K5a0`cVgzWZt@u7*>Kq)a}hYP$&>hV(UvWv7t-MN zrebY8yS?D7*+TQ6wZ@~3ucZ|RYJA$B*q-&kjT&ESV*TAvP+I{n)#{<8wnQ7>E;9_& m`m*9rg2p3{HBaDn?R`wM$$(GWP$h%khoa3sdI6d@ul^s!>h*^J diff --git a/integrated-security/web-overflow-client/_14/server.c b/integrated-security/web-overflow-client/_14/server.c index eb2e0cb7..1c367e23 100644 --- a/integrated-security/web-overflow-client/_14/server.c +++ b/integrated-security/web-overflow-client/_14/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_15/server b/integrated-security/web-overflow-client/_15/server index 4d74232a572983f2fab146780d8cb85d25030166..d0ab94d7cb6a26575d39f00b0a8fbe975bf3dd6b 100755 GIT binary patch delta 3600 zcmZ`+4Qx}_6~5PY65BY59sfKVLTty07?jw~A4$4oJSTDU(2#&aR$9Rbo%q=ZBy6Po z2u4^)iyN$(9-*!SwxQ8Un;0Tw)7FR|XLJp$jHWHCIu%N2sboY52~d_o=-avP`Xz>H zSIIr^eCIpoo_p`P_dO5prF)_@=FEv%MZy~I3DM8pH|zHXX^H|8Y2SYWhVE>xbc2Nk zLe4auA?b`3S@-V2H9U&glPR)d2 zZaAe~OaZQG1v;wqzlP$p0FA&#-DVi9)xmYGjht8y z7Nq}$KJ*(7F9b7@wWH4olDQG%m8U(0DbYTjrhZ;ni5p7CAjj$fkgNU}Kpe8tk=mkXEQ_w8< z7oy{c#!^rVJVJD~(Ukey6x0SqMgf)~dOQVnz;Zz~k9J)tj$wbnd)yIUkuf1glJSaup#i5>I z@G=P57tjl^&pwN;gp>BEPxqozq(703qjz;KyDH1QI5x}hFgM(PD9bl?-bEx@S++1#0%(&MyI8;~X2o8lw zIME_S`u~P0kwgbj!2tsfvv(OXrOtR;=_GS$Dzh4yPnDS&t0PV^j)z+l>k)d~Z%V4) zXAfbQ(++Kdz3jw;3Fi;-WMUGD>~A@rYT4Q zPrd1%v}dK-??AiLIemYOEz88}*isp%km1RCpifz_*AQ|+zf+*c;HuO9Y?Lo+M_i9f za)2`vbu8D;_@=VQ_iqoHanAo3dvar2xZx-oZq~qEXTY?Xal+%sel*tOcjap|H}1o; z(+YMDg@JK6CbKaT#d^< zbQ%koE!GQ@E)C3O9e4RIclix-c>{+`oWL$}Ht~IEnJ%oULj{+gjYF7I3wOGQZzW8> zjX5nuO7Ax^A*We)hINUdyAy8bk<;7C-A-}0)y&O>ZW!X{>^Tazrsq{&WCMp2UEu^~ z>%gd5&Gh>;jcKhCGoSc*V4hNRh^b)RnddR^~bMEDKbsm_kcnOJ06SJ-@(1 z&&`k4e2Uj<=m+y6ABP&}MZO9x2}Q;mrD)M5gcr}B`3R%x6K6)?{k$f+9D?qq6P`GA zwQkBEE zD9T@=d~sBkhfprQBg-b7{5~w1*(l>*%kq4buiz}#q8vxL7iBZvvX@Y9hn2n=MI*Om zIe^}zKEuqmK8XJ&jEozhv;ypLl4R+SEXUz5KA&p@^ErTE`=u@^9Fde~SLpy%Ll zk((AmUs1q9=8B31D^zKFfco8*xL#B=_Km|@6BPRw&>-ycyXi0-_OAi4#0GJV4m^PY z?SMtZPqRWW2M00sXi!i%)-)|KkRW)A1=@tYT|0%uVNr2|YtSMpQBylD$tE%AM(z^{k!mnDNv@lUdy}{b zuF`-@Un8mpMXpa;TVZ9Xpc$)%ZKZziSiYzj@olfPUhFBc5WP=SbR+bYxQ!nvsFm0X z;ZCWa>cLwk%u_$R6&`jEl?U6zeyMntQdc=d{UBFyFXEK2IqoVG@ZNi~?6ym-gwZ4^ zgq$3WnH+(`n*cEhhKUZQcZR0?RGSs9=Q;Q7iG`22Qd zz_P|JDuI;Z#iuzCsuI9lCDC;~p{f>Lj`H;^iVgGU)z+;j@t63^dyds?pgo?sO;kg) z@C(szIhW3ZoMXRCuwjjf0n2cPsA$8d~X2z*`JpvlofZJpn!t}g!E z*;Y5l(4O4Cc6ht4!l;(o*lc)!Mzu2ZP*q=HQ1{UcTk9((&JIy75F8i!>IC?tK7l8t ZFI-`0t>U@t1o}*c;dTwz9JnU#{{g|XWnlmS delta 3407 zcmZ`+3s6+o89wJOk6oU-EX(dH?6S-HK-pa$D+_6eyTa-jvk_iO<8SvA7O>pgp5A)@|qJGZK@0s?aSBQ8hl@MzuY=^G_eOZ>yIQZ+}>Rvt--DE7v!ieH`|yR-5xM*23&aJ~>FWgkcuA zpxR0g!A+Hs-j?ehvl_x>3GjT93EC6dK}Uo5(X39P=U&pBonZhl_ADGr3WG2CO_)y32dz4n5^$=Q>t=B_Y#Te4 zwQ2|vhzc6j)ie)&rZ&P))#-3uoeFDZHZ3GH9(nA`T6P zEzAt9Mk5)%1i#hy=ABa7HQ8D-y4z-iPd!X5{g^s`(!y5V&j2MQ8D;FD$=1ir(o3~&bmCmRQ?_AIEjw2YXa=c zvHI&dwEuJ52f5?xjQf&+L-lk|;!rq=3iODKdRJ$H%>q0|@=EZmm*xXC8V@1~_6gcrMQ^h^O(%!%0M}pA(O851-y) zF8&0?-&hnMkBJ8n!jX#?XZ(^?J~R4Zrqg*5!cf++t+Kh3qtLu@cZSC&W-qvUfAo#PjQ@3_g#Jr zmE096K(u?H-P_YWGP0N{R`g=HjsIaepmZd0hZ7xR-iT(s$8?0X?YO zrHFVbL5?^xvozuf?ifMGcqL}!=-=gOj-nP%`Ar^`ABS3A!4c--v*KwRfp>D9^gXzj zyQZ@O!*m^(Af4>#T#J+K-@$X=E9ZOFN{kojLekEmz_37u0@qj`UaG??Qp@0A;9W5k z7#4$rJ%NdS_MR4lS8-XH^0M}_u-7m~e=GBZ){U~<4prU6MMR2bq)vR8CN5(BvE93X z@wx|O$!koqn@ir{k~t=s`?n-T49E*!iM)aB$}8hU+53C67j#){nMO%cAdJEd)Xb+*y zj$$0N4%l0;ibkNfKyOaKSh!VkabR78zqScUIt_0Z6qxVg48o|0mt1VH8SDg&!)o*5 z_~YywC6J+gL8wkoQvFkvmaHa>^*j6tu-RdyI%st)7tYVZ3l2Ng!b!&_S^-lIV`4GB zO!RoW-Acx_J9Kr~KGYEMSj^^w#_7)T;DyDCS+23Ff`^?JjMM6L)6;OwX{8o8=XC4T zu{)EU8!K%v>$K{^YMA zMxV@ARw|+)TCkNEsSj&|DwTxc(UMK(Vcq?>nK*+p$o0SRT~y9W<92 z1>D4aWiH#O-6#9;_LWON)|BYTq}?a?Q(&;vn)05E>PgfA(`7E)JDbP2IsRQM^RSwi z8`*d~zBnY?3^{qS$kO%O5T}H#@i~tXV;=MT%N#%WsaOO*a;Qp)epM^oi@6s1On0b)QRjI*Dse<7<=^3yk^Px_B~Njb+h8Q0RASw6WCE zLbKni@x^*R==FOS(k`s#aoS+a--)T!y1}iBr^~R8`@(Q?gL~nBN}HaeS5o2j2A3wD z{vNPZZxZGN*j?>PiEk$UeR!?9T+>qElQk`Hv)Y@oZ~{)S*ObH28ZETc6l>xKW`f=t mZ&v(aQM>tQcM06C`3y5}Ea25NRC4f}P`J@cuR!z0RsRJl>=!Qp diff --git a/integrated-security/web-overflow-client/_15/server.c b/integrated-security/web-overflow-client/_15/server.c index 83915eb2..a7965503 100644 --- a/integrated-security/web-overflow-client/_15/server.c +++ b/integrated-security/web-overflow-client/_15/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_2/server b/integrated-security/web-overflow-client/_2/server index cdf70be65575e8c68cd07c6db4ceed4efd9d57c4..e7dee0ee09767ef03c5a38966118a96baad91390 100755 GIT binary patch delta 3518 zcmZ`+Yj9J?72egumW+)hTTd{SgrEe1b>$bbsa&os3ob2FAmDbAfw5@ABL!lU;(*gI z*fCB~g&M;drcDW*dWK|Zhcejy(Z&<7+@uj{)5J+hCY_St5IQ3U^Dq!kqTbr8WHPAt=Mnf5w40YVf0Kcan8vSmL`rRD$Lqyf& z`hOmEDUUkPtD8)x6OG?}`mp7>sx!Nve(8(#!s_eM6Y!$?F?%WcOb17ZleAL ztJhF~FV$8$rqsWMa;-okutT#8M(QV zUl>B(uwt{D)esIUY`CGd!Kxe^jEEY@&oRLk{BF@`U|-JBoS*J|4*$TJdkQ|vb-|6? z5~_j%-Ap5kmQ8BwjA!(Os7M~v>VmWs_UNny4#d;N20e&4mxv0Gi?s^=sI$U(U4DT# z3)R5qi013_3&bom2MY97@FTh^3)Mj#qT3J+XQ6qp9nseiZOKCO;V7c-Bif#YPKSRW zI)P|+7HWh^L>K1e7yK>@H9=XP71kkoDhsv1dPEN(8qY#)5JU7WM2EA`8E_iWQA9_w z&=R=-e|Qw>qR)LECgf24&t}dl~W_+=v)NvhWe|2-ooN+Bx~3NM1WdKAs}?B7{AAry@R-O`ffgXI$}2 z=_|7JH=*5Tn{~LGO-p8WYO*a(qlI&NX*Tou^d2b$nDo z7He00XVru2cLLQo=D&_Vys*F(Cs1*v4sO|m{9Vi@G=bKWM0)-}!-R?Ah%IHK6OFWPnf{8a8;!D|NHef2f#JX`TGSNshXmw&G0Y1cLG zFo7DjNX^_Kj^_NrERQQRipN8bc&y}#HgJ_#=KhR3;p_Rj67b;>^umMSd4Cwzm6XwT z_(jQry`S91ow#R|>}9)o9LWQl_~vBiIW=7e{Dc|Ol1f%>4yG-_B6?r@PJ!qa~-5f*#r=Run7$Y@v(rvtiF#My8vU16B}Z>%Xk%zI(86h_IqjE>W=9&jc!Pb%;OeZ>nh#jVp=30a#Aq$Jm-tsM z!dK3+lb4;BQs<~MvImct)*Di!F)2m0n_)w#MaQB*p_U1>0(O_qu4v%rb>N39Vs-z< zQ#9~{<&jSVjmsln2i6866OB@=>>R>tR?MG7ue#*m4fwD$OxJ_g5$b@-Mc4N+ZbCqqeOG^JRF+Sma16@b^X5N;S+Nku`Rlu~ zyaL-M9LN@I&tZE2+Xg&H&tbb3I@~L@UgXB%6SrG?_NpwOf=RdU$?q`Nq3MQ~Rl$NB zb+slxS4T<^dIx{ixQGIK*<|$JQZu~`p-cE{z^#@*?-_llQ|&~Ny&A4VY>rzc-h;k5 zOYK{5SL1?a3QMhhXcX=@&Q0VRTTG&&dOp>PU@Q~LkKt9uie0JkHJ5tD%}mM62`lUh zWkm-&$^?2AddeJhE)10kMzTayG?;Ws*$>p?FvfMFBC%HrD`6=2tfXG(@Hpr-=<#d@ zvBCs#l?I%`uzJ`i;^S&A7`!9sd(3N9Y>KsNq9>IY+mSzSzyV{5gi$Mqn?jN=JZSTPoh+KOwxqheS2aO#1awq$ps z3VoB*yrpqh3Kzj%DcE&&Vp^fJ+f&*W*idOzjr-w+N{`*?=0J#*8V6&I71i@=1bPIXtZBmUH){mr zX0xa`QgR!=7D1ra3Wi#VZtV}$HfxHM=dLI&Td}-8*i_-E@KpDotb3OBJC}s1im2fw z(PKQD!=0RE|4CrMloAEwwOmn=uBEa^1R4a-fqKE1PL>fP*PVindLi?FPmD2m}RvdUE~H7WC0ct(x=lv2el18eR>rQ(AMC~Y!o8!9tjKut?*ex61T-r$fs|q T<@jEpOMUw5bzHLGj5z)W^fE~~ delta 3330 zcmZ`+ZA@F&89wKl4;yf>0b`pO+u&pY8e<3sLst?z;N+%bf;6K8sTH854P;qIHRzTv z5k}asjJI^}*qSNR%%5nf(u|a8Ygm&&vXxHS(lm{#G-501I>iLqK^s;`Ab0P%$A;Uq zyOPhx^SsY<&&PZ3J?;z9$$omwl-8c^CG6rQA(NY5EI6srCCebuz4)F><4ffoALyye zXOHK-SWR@iPq9j1O(*Y@N-u9jYn_UBi=dkt^`>Z)DaxAQ6n#r?aqt+6gKI4i5SnuS zpCgGn640ocGP=9E-(Fvlvin~di`^$%ADrEPrYQ)ARC(rX^jsMnv6CZIM;K;>^Qv96 zA8x6P^p0Hql9doHiG!mFCg_Ok05RS~|0r`W$Xs*02^!)|^ljFQPeofhoE6gHSbPzk zg|T=Sl%ujW!9>r?s!Ot}4zVMM9facvVelsY4n9e=gHCOs1f1%%`b8WKTgA?-HVq*H zQ9+}+ie|&F)kZj>*1~)0WcZspMVq(9i&2Cm;!l8OWS0;vSDf!5%)*$*@ z1)2ee5j}+HYYH?IUP1IUqHiit6Z`|w2}Exw&@9j<8zCh*MH^9|mSNxe`*A22sjEg@-@$OaeoA{LC z3?gF);hl?CNBk;h_}n(h;+!Y2Eg%}VGu2$|uw z$w)7NgcI9iE=;+(Aa5cLsd;gD(3~p>HJ`y>)~@T?i*MwWwQl?j?-S}>;M?#try>qS zdq+Dw!QP39)l8{E7VWnEm*s$xDBy$>iK!pUS=IY7H?&0!uOWqoZq)5jI9`mC9p~pC zc09?62_&W~Fe4}bDGzfJwYbag;OAy#25NZ*1B~LM;%OU!w=7Qj4lG*=y2{a}=kN^a zVh`ija7ZK1@Z9&v`Cj=r`bBy$=-F}qRe_BAud_V7ScgTVhQR^ zS{4IWa4AydY3*mWchO^{jWMCpNtWB8O3G|E&P!eRFwI=R6k@A)9{qYpWyvKb*~=wo zxFm~7?%kE7hymjQmm_DeU2(bNxseAFAs1M2krk1Xh~t8?J0D~=&vBbQ+-4S+FEWfF zvh1r0UG1u_n(4mFbwylvi|Gzw2#$V{wP&H(Y88s-;fU2h_rfo%wz8Y}7CMJ2GJ+a% zfwfrPv%87G_|sp`4#2cExAZ6rmfyU-Z`On=cUcMXJ-H+BuCIPaVBYr)Utp+4^Xq#CSK@G)-1`Y6`@Sl`9^I@WP8=%|gan~|g;n0GkhZ=g#Uve$VUr`h4bzee{X zp-P*e`aqSEs3sPK{*1p5aDJ}O@n4a76LKHoZw}LN9Nky+{vMSbyX=^80$y3?5M~$Q z+PZCK6TTpDwwCTfYuiRq?1$KEMzpxh7`wMNVD~Vq4B|k$= zKwY=t4+0)UiYC!>uE=OcPL5X=Dxx7e$SF2bFO~*XG6}=Z;_c?E`Y(%3#SxsvSU3E& z*hMX%-(*mwlRm7Cc-Zk_&wy?|?3v`Ak*MMMP2VpbiXKB_cV-_ffuxejhwz*zZU=LT z%dCr@9%HKSMAL1xM8sLBDF(H z*-vQ;%#}6KO|a9mT?kv@SDqJW81&^v+79{UE}938HZt%)Ra{6Mc415(v z&{c@T?G+7i!xNSJD2xhm!{U}^DntZ$*;}X|O5mCyd>gXM3R7N}KDO6aqDitD@_jCi zE}A(yXz_V8-e}JYgFeqnR)y8vryZtzU6?s-TV48CHeA(nE)1u(x>o*Nw5N0Qax&c6 zTBwO-w;OV*w$m(Vt8!^#YiWVODvzcwx@UcGtICtKvi?rUtuBL?s&&v>U8IR^mk9=| mJ!!EgLG9xAS|D(z`T?fdl;5LisNmqYA%B~PUWS%!8~z8_*!5`u diff --git a/integrated-security/web-overflow-client/_2/server.c b/integrated-security/web-overflow-client/_2/server.c index f196c34e..c500fbb7 100644 --- a/integrated-security/web-overflow-client/_2/server.c +++ b/integrated-security/web-overflow-client/_2/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_3/server b/integrated-security/web-overflow-client/_3/server index 09032435c135305cf2d6cfd153c70273ae3cae95..46a24540be5235aed44b8b6d2bf55e1969d04347 100755 GIT binary patch delta 3628 zcmZ`+eNa@_6~A|Pfn8i+pRiwu?5;?SAM6J#E~F6OvaCL*Of^y3Nd`x3N3m5Sv=TK_ zM<|lG#jTh#wzVc1oiQ2Pu^E9s+R&&=O@m2O-Lxi?PDvy&oh~CHs4+w_ujjtI4_2Mt zVefhOcYf#GbMHO(gW&^of0TCHW_Ra`gcV*BqF;7s(d!0jmI4y#(7!x}o*drj0fBmg z6=}SsN@C(|iXt6*WwloVmbV83N7rN8D z^eY%ZyST#H#cF5_Db_HaW`ot~HW(IlU`)@0&G_A{)4{&39*8CqC2+@#CsMLpOA?(pxvmA)4#RkU_aV`@TAOmX+{6TMpA-yrn zn}X`#6GV*$W0shLrbCv&3RQ@%PC@lhjp$ZH8&l9s*oNrKh&HF7MtB9$_YrMNL9^lS zh)yBeoq`H*AJHY5#;jv0XdaYgTA=~a(D!(mxluQnb7tH=Pu%{sD?a54@b`Dwd~Y zxnq(u7c-`lGjlkzf-$$i=Xpg{e?-43^J*3{U7R_Xsrd9VW)X6vuKJIquJEuFc?Y{% z&fo?Jnpe^H;gER|-2iWy^B?a=qsU+)2Yc`8Y`7xJ{n$5)@Hki8xhKmb`*8P3(Zh|X z?g~#yk&n<~9hfXd3$}7rFR~sqU&9qgnE3)NJY#VL%Q>|55pDrjtYO^GG}u*F=QwtS zLD*0uMF#(bA(2D}P^$&v7L%(1nNnx0wQPpDE0tM=%*B2aV|BzR`VqM{u??XI?G~rn zeR>btZDwe-n*F_Zr;Tso&cq-RIgc0*aSaczjT`?Hjn~c?pGX?_AcQ@8XCnS(s_{I< zIRBb^M(2XT_ ztmmT&u~<7}JNyr>-$_*CnEyKY@WLMCic_e#Rt>jo9^+2N2~Q#W{$!uqK2M_=xdTtl znZGw1?}+KuyK@KoiFQu%g{54Th#`ud2f8|khGuf_zj*JUyQ^Qa&Qlc^x#B%kjJ&Ai zY3CSscpf!uk+yS(IGUj)DIV)|ipQ58@mR(cyTMgpDc;GQ@b!F63Hb0Zdf`Fvygv*L z1tqi%eo?S!?}xW>C+-;~d)f9LN8|oYeDl1`vN&2jhRzdC>~qs#IIbas;ma(M&#lHP zF@m<6BH@2X(QsUf40MG@``JYxMK0nfPN7X_Y&Uazgt`4O(?rX+aksBCx9{GTt8m&! z&td|z$$DnSq=}hq;U?eaCg+&Rud&NSFIJKBiSNMnxz?r-HgNh`KTc+}og3Z8TM5HI z%#2nerT-h5kh82h$Ew8Wt!c9n-{S{~M3h;P+NWJ_^>ajC>hf8;nfVOVN_c2(PJIcpts$6X(X^Qeh)q2VO^GuXC8% zn|D6z{^9nmTQ@dsB+}Zot35uq&*}G;Wx}VfRp6aB`Sj?hET6)$of?y6wsZ~Svb+!F z0hGT%Su-KaqbSR6%CZp$--0Q#1m&@>Ww{Pz6OM8-${~~oP}boodl_W|v==QXiQkZA z4_cGj3=>;=FaAam!-Y`Fe5`ShqynRe!G}df_V{&KK8^NjDZmdF&v!wX?^x%+Xr9nv zGn{RDK@-YK*Ou#y8G6E4Z{x2TGsMH*QPcWwX_?-J&=>ft!+ku+ysP?fht`Qr_D1;% zqVtP1(p~7Czuex8M}`_C)3f0BA!&1;P<$yvXwDNEN}fwf5rh(t?*v|)tk{(r-;T*Q zIb3Jtj#6IP+INkxE{1H<9LFlR*c1>wGsj?r8|A` z>Qriq0%B-5nDtNxkZMPM1621b?SnI*%x2{wlvYxkmU)joYB^hZFF1%?doyf+3GV zom@Zc4h0Oyl8bl@-V6mY)x4Tq0(V184Qd+bp|Un$P*>3eyK4i}8-*yR3-$^FAuD`b co4{=`5DplcD|sY)fi4diZdCJ@1!u(ZKZVF`EC2ui delta 3373 zcmZ`+eNa@_6~Ff_AG>_WF0i~^T=s*-D(bQz9}70bU19N=kV>kgFq4ijZB(pHNegNH z8cdOtEo^IYLaUv0y8Kb6W~{~1k4P0k(~x#rwW*Ua4s9^gj*FlHBUJ?QdhWZs@M_XG zv-jNlJHOw#=iPhWyKg&#bgY{mF{L)Ac?r9COUT&cudF_<(pEqo^f%KBj2mSl7kJq}MT05AGDW;5I6*HPEKbg`IJwpW0b#r2 z|3xH`hy-++?dgM0oL$)5Y{~!a&BDvO_kOeIgR@g*a6q%loP{wLlOuL=i0TQ$tZ+`V zm3G4ojYw}P?T=Xtp~4tA9A|=-m==&?P4xGQ??uJe5Nm?E7!&;)8^xwzSUa2+(%?vJ zKAnQ$ST~fSa#x&*o>Np86jcpkhY;Hj$KpcZjsF$gjkkkdYoP>O+U15>%!aLEYi5&< z5P@i*URy!4;HO#Lh#(+yF!dhKYvZO-e z;LC_Ui)ft+)j|-_ZbWyf&;&S#=vhR+qe7G5HlmY=cB;^2kd+{UB_S#Ks0uZ}Q;1e0 z`U@4B4hIoEfaselGy{H#=t)H1QK2UI2cn~hUQ?l&kenz&QeskaScO{p3s%gio%;8a~5Q#chSQHmZZF!Cm*M8W_LF$1PD^o~8qlsbl53zwKj)y!&S zt|_uJR{IdeI1StzK8Vo&>Yh~V?#w~2$p}57vFO6XMR96GZ2OdW9-qm@^p0@x$0+{l zlK3r72@fNLGv_a5d`c}|r-+wNkpJo#2svy?e8^b3qtjM_~Y`NwjKD2Uc8z5`#4Xq;{o4>dhQB4 z5$zai@pN^JjxJTo2J~XMs{gPWP&+=y9WHc?e^05ZjypWy@<_mU(S-qvP`6VR@qCOD zac1Vxh{w5O6de;~SdnA@RMH$nE$;GVJbxDNK&#wA4|DOXc-e;Gvc*OJ4hxpmZKW8d z{oo{NV^8Okn9{&=y!Jgxy_Z*Eyl^{`c8vJ12xP>6mDS<-8f?PV3=a6;m4f~&Qee2t zKRLkO(^B9PE=7uRTYFj9dl+M&iFty>W30A=<&=e8J0rK@!!$XF#l=?d9LDPyQY06c zWH*rX+0)hZOsz#*%V?uH*(Z6(+7Ep!G| zWB@f}ko9mcl-Z=N*pr{_?STnvcJX0GR$j%vFI5N2w^|ADJ+nFRp09RuV8*x27nrY= zg05vFr zY1^h`nay$-?NPMrr)7B(?V7u?oP3q?Q zK83GtG(<=A;3yEO7h9tyk%Zvsf=%WthR@=rUV(ZUPszFp84`C^UE%#JdFq>!;ka7P5UgSpUc)<-@xqpGh*yfx5RCHwr0snNl68B>F`g zbvh8Igx%6hMIy#LR`iiMy06m_k`Fnlf}RvXZ}E9*hsKg0(ngpr*-qEN)1FO2$O=F4 zyhuY}C>3clXm7|A7pGW77jJ(k6^DI_X zNXz3i!?>>vE2n9r+YqgWD+cZh!HJFT#s4AAX&k+n2)8!o>7vzL1dfVLG!vRC+`8ym zTA;VWqw9?9Sts16@FXm*zYDS}OW!RCbg5F9`YV=9ay7^oW2;8dt1j}sP V@6pwjaqw%9Tjik_p|NV^e*s6|5^ewh diff --git a/integrated-security/web-overflow-client/_3/server.c b/integrated-security/web-overflow-client/_3/server.c index 047a9d53..8b97518d 100644 --- a/integrated-security/web-overflow-client/_3/server.c +++ b/integrated-security/web-overflow-client/_3/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_4/server b/integrated-security/web-overflow-client/_4/server index 4c2ac58f079836afbd6bbf007bd655e14dc3b485..e1fd150dba55076c8679250e23523e49c99d4b57 100755 GIT binary patch delta 3474 zcmZ`+4Qx}_6~5O$$+K}1JN|igNMbth>ucusKhq9GA}vaJ=2un7nwG@&D< zpi)B9w79`)=n<+q$~GiAZ4<2sk=8aU;0)Hl%G$8fs#EDm+f8#spy8)1h0wQi-?bA% zwX5XbcfWJK@1A?_x%WMf?xTBSw9lE_XO##mye33gynp`h4Du`$B=Y`$1PuK-yweXB z8VEb}yq9W;nfEC+8TdcBfcGbBB=sTHI<*|Hf<08Um`ixiT+6-8@CW)quFc0$n~$S5 zAH1OXsrUa$3Q0);4BEA}O(&bTy*EyLi{$pAGiUmBZ~o`;F?dS*Jy#)$rlKRnL%OJ$ zFw6}nv@0pV=US0oSLK!QPfqsn@ z`t(8iUl>B(i0bnstD&V{Wy6Ht2~8PJ7?pHj%CJEzK6mJJ@NCARj9+eh9RI+Rc?>RO zdSN0npK2gWm~COvvQ_QO+hia_LyS-@)YC%PC5TyW#8bryhY|5CmQ)}UYYn_Eh;T_T zWd+kv9ejqU$zaNo($EaZGKf%vXj2+0KrNzeh_o;R`<@H&uXa$-&F>Q0) zO9;7{Q+NmaTOR1If1tkxTCIilF1JMF;UTly3?D3%h+;2;gVtW_XAj{Roz`YK`tQU} zMN!_>zX#Q}Me`c(DM~al)xB#<>2%AntmWB+3>KiT9II@`Qzyr2e}+w>A6~V2HOds6 zvN^JHxS@&}Hp3S-U(K5+(>=*0PG_NnmrD#ARf!<;^r4U3+x&^#8yS_O@1pX<3|N; zM?Xf!8ZbM2bKAJrarC;MzLFbWVf49Lc+}wzS8}NBJHGkcu#)+HuEC*tdnRxw48n;P zIXe6nhC~wGKt%_PILzMF=qdNaJIiN0SEPH^pyxvsX6Dr$r>K+1t%)rN-Otmf^Zt1k z_Bid(DcUQJ-dl4ZQ3_C^o23&U9SH$?TcE<%=k^|f` zQO{!SiEpd8fB&9AGtT)hlMim}CT=*2hAXvj(-|;rXFicB^u9Ma;CB^iG-J16#q8qU z34C2l@80d(I8Ll*l5gy%+?0qTii3xGdoEp?$-N=8qTH8Xv%%91zvqU(qG9ZLHBWo4 zalu1L!FDc)v$?b&O>wDCReb3?isjs}1HAc;Im@{S-_O_7fDeqK3J-$k{Q+2=UqZX! zh5Y%uKe~k{ao0H6%}(E)r3`I47nSk zk-y8a$cP*r>Wz#KvU^{SzK=6MikzPK4ko*U$^L>_VwGFC>~l=^+%2UBmwo&sCNNv9 zM`tJvjIxJ+OI<2R>i=g?=cgVRoM+6G2*Aq^#-X3sIWT2NT^J{vfa=#3;WS_hsb{*;OE zm9y;TW%s4rJ?@F_!Yih8LXI{kl88VI^uj(Y~Ft7H3P{-3wE zwXNT{p2(|KH3drjrJjmlxe?y-HsP{?zUZ#ObX8G~;`Gjg!8do_e$0slILr7qin0{j z=W!aX*iK=)58F1pMlWLf6g=WvrvJ&fqQv2KpHDx5D#zd>U#Q>*xF95wZGKKupOvAl z)R{5`l8?|C{9gm}irusg8jELZ#5=H|xQMnww77xx!G&T`zZXxcb>MpOl}t;AO+tS{ zo=CP5SV{t=NAOj|ic78Wb1eB8Happ8`Nax*1+pT*){+1{3x`YGbPf!a1T18+q*`$H zYS|0a@3zDRN$s((3|3m8)W3`dVUOQUufbveMv%&E5ZCCy6ByBsSS0*7ngizGC~991 zimH!QuO$W&1aGNGTd=lkXOTE8FKuv*S|n99z0#5#(g*$Mdj!sv2B-}zWp=HVbYUyH zQuDf>VaNG|%S4RDp%roWww7%#9Z7!SraalZO@rDbxo#=ko5Uq>l?Plxt&}pT?Utmq z1J;#`n#mg2S?>2v7D=iRU%+Y^#F`Qd5qy%`H^NYv+xVf1T8V8A+$i@`0lXDrW9q|K z^~36}`e2*huN0n*nM6n~NqrKha4+JNusQCj5b-K{rQ$1BDif|JoxvGlaS4nDE+E`b=w#;AVuN-)z_Axr(S=>T3L<`SIe#_YmE^?Or zHo$^8CIu|lG9|TlEtyUd&~U&IOy*b+s>2~eOS0DjJHnyq{EOqOhn2lB6yA-YhwB2C zRQ8Noxa}D1sS8a1vgxyO)M|o1*ZB>p19AkuscX>WYN4*)Z%nN&{@~bIztGT?+`le( zyFO%0rP|~IxP!)2W(ZKdBxFeKqZxKA2~D3J65wMJ7^)ZHlO+i}DMOKvp`)7PyMaC& OGJI9bdk$O^_x}LnO+NVm delta 3304 zcmZ`+eNa@_6~Ff_3%kI|F0kyb!Y;eu2!`F|V`aexeJiXyJG5Y}Da@o5rcL~)Nl6Pf z8W~Ipsax3AET z^v&%3_?`3ny>st9_uadP!*rsT95VB0NQ^IB^Xda>yb}Nu z^#Hj3y)ND}@8SVZdrq7^DM0o-~E6zNk9 zk_t_PZzB3AqKzt42Vq2e5#6Oili@U?Zy@@#3QdKN5S>Q!unJuPIms5tPEIwvtU^uj z6-4V0{hbQUgbqXxBKo=t&4S+}dIHh&D%1-9Ky)0@t15IQ7*Z^dnv!aWs?h8K)9U*P zFB)CCn;t^$$g8IY)*4@>Mc4{rlBGFn2>Ce8eh>Rq5A@f?`vViEHVQ9gq??Tnkw{}B z5j(5K3b2yRUxUA7^kghPgp=N$v0V!NJ9~hA%zWF zR}eCkgT7LDT{~_gDO~ju)jlGT`ktl%Ek_ET3jLyC2DRmFGmo0mK zU+r0ko)7tQnOD~^MVn2!khpVpPAfiRHawl%4=`)yrY^ELl8RTq%*$rH?{Qu+=M6I6L3F|B-(&6D&}_F0C9`nIZl-(S=XOW= zb^HnqB8v~|53s-Hk6B2l2OXx~q`;+lAjCB$0&#TuyJuS;8;hnrZEx9Gj z5tz;M=S;E7LvV%hd7;{nsQH&BHAzRZ5qcAU$*?8gL2a-*f0gj&JUpN8qIf~cucac) zV>8U2R+x7?Oc9-^^w?3)9uW#X^~m1uacC|ii4aJ63}d3+8}KIquM))* zs5w(?v7t@zR~H(hCq{6VSTKHPiCL3EBCxfj)^^eKMZRem!723h!QV=}w)j=-vw9h% z8BC=XyuJiV%^EYR2e4;VdKRLCr%HcVax!+aj5FC0B#<;R@c{0O;kjTd^V*ED3t^n~ zM9kU%EoBw~C-Fd;$9dHyDt0_4m1hV`N=zi`5|w^3jFdW(-&fEKayK9DlzDLOoIcBz z_=QvP!{WZu$i(FlxC*qW_F+S_FpypBEe{AuEpNT01&?j9m5+C%h zJ4>XwBg0 zXbRliTH%fWd#XLj@yWz{{co$w_04&r!fA#NtNqDKE8qrKO*y<=V}xBb t#rpVyS)sqipB~>VIxm0Q9D$oPpJL`s2L1ZRN)CP(3OD=dD70)|^FKP|_t*dc diff --git a/integrated-security/web-overflow-client/_4/server.c b/integrated-security/web-overflow-client/_4/server.c index 1a363004..c0a3c5b3 100644 --- a/integrated-security/web-overflow-client/_4/server.c +++ b/integrated-security/web-overflow-client/_4/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_5/server b/integrated-security/web-overflow-client/_5/server index 657e0193018d4c6523f715b152f0af54ce69062f..f8c317bd9e3ba0d878864c9932ae8422c1405b2b 100755 GIT binary patch delta 3568 zcmZ`+4R90372cI(`($h^Az3GZu_W6Jgooq_yigUIn|TXf_q|k*S8WOz;|g-yARCXuN=KAArVmkqkgp&hGy^kD3-nCpN&Jm5)P!l82xsA9Dbz#nj;@$CMQRTi*!;GVVDz6 z>X%Z0%X*QHY5gyuBu%10*kafQ(OLt1s<+ZpnrDaBUxE(|5_r?>X*LY#f?k~kdeXe~ zKQMs0VU6=N>!G<$Q^RPQ9U9Z^5S0y(m2QO=ylyiXV0ZfA^dD~h0set2<2Zbf;fB$S zJgS3iVTPH_mThYL^zRu7(UDB>33W6db_im&6Y*rT!x2PW3uFz*z+MNx6-2lwWMz9( zPy>97XqGW6TTVgKA=@ZIHKL6vr~oyHwj$b`f@Z=-L|;I(Ed|Yj!-&3%XlDvK75<87 z9MPT>)C~6#otK%F{Za~Qh2l&RRw8;l1+~E{ME4>ZNkQ!pM)WO2hf~n$a1zlGM58Ha z9$e29>C8U!l(!8BOa;Of4#;c&klAqh@l!-DpVA9Osp?sOBxutN(60&^!2h9L}s_%nfkGT3G!DjGJWshB4ioIhd)%^fG24a+FZh1tk=SD#3R!)ng1^ z3I5#0^j+AWJD0A3w{oXH+K-~(U@Ql-hq_l@Qq_K(C7a<9?znSLRj=;G)2D`OBkg6AOgWWVjm$^NO^nqQp%_Qt-q=Qj9@O2!V>glE zU-w{_Jr~-=-0~B5C&c}n63h9D_-LxQlZ*e3;$@TK)`YkhA?U;D?K2Pdux**xop>taBr;r6ucSiz5OTnvU8JwWC427UVZNq8izczH^UH;Sf!#8#XcN{~GZ|qs_ibW8`KRjnx6^CnnkHKRu%(-qbFsvhkfpe^oPd8#0yNcR% z!NA{?a9~&o4uk?D{p>}c1mDAzA45%dq=SWB!@_=_dBPPNdDu-X?AhCDHE#RJDJ*Ta zSx-(%BqrIwC12-~XPM+@m@;+(yWrcgZ^Gu8;`%xq;P$gTF=X^_=Azs9R>JA8VxmT* z^na-ma*B1QSr;3*H6iO|vNkR|$z|VSG6%{q#5#5zhU+u)tKMUY1F=vbhO@QdS>jh2 z2wxjwk7D)!Rk}u8!5#RBX&+UBO)({uwjS2x+XOZX9QfFPmcrBd1*Hr51Khu2QMl$K ze60GHHw4f7n;L?j`HFOjm)|*?hwFDs{AN+vNG~ z=GNA=>(>%x*|J8d#8cub_m*YCEAGWG?jC=l=(?&N!?k^SLsi+Wdu~)!ccVRn_UCA~ zkE!Yi+6^~VH47L28kWpFv=_cm)kSDu#8tMSwc^utFWTK`&!K$|8VYAq0k#xc97Pxl z@0Zq!u*YSQwh>j0z~RC|hk%)nqaxYz@Pf_Y8Thc!>0W{PzhS^(V5;dEU0rs%zQT}| zArQtoga7T|D00%>;47M;lkURuq5>@3j-q<{Dhw2fX)oc?xAa{u(hKG`tBia?o=R95 z%*9g4QGD64=Focl-b;Mv%}9({!Lr6)vaI2XiX}P(M~a~r-~NCcLY)H|YPS&N$5=}8XhfnMYug|j7+BVO>oI2O_Z=2Fp-T<3!k za&dkBQW587(~E?_meOq{!--GoB$K^7b(o7J_A!aO6SxeHGRYy-$VrE0HzvGou%=AZ zjaS3=GLIu#AZt#1!)vV{drHh?6b8y98iz6L1#p*(4apDd1d-g+F02!`D~V6l3TYa7 zc=2w;DPc?6RW4$MJYW8qBUuPz39%nJ({v_s6pmD!raiD`{yusR#^$f4FT;|`dY#D$ zzo>kQM!;MpqI*u2L=V9eRjcv(%__;fK3CQPY1N8X^TF>E!Q@luhCaVFMfPW`W-Crx2lf@G?bKh~;RVz*Wa_X^g)RF~% zto0a^=i?}RQCm;%g1=5OCO0<@9d(t)mO@!mw7{Enm6^%98lMMu>*gDiWgviWVWly7 u7fsNyuyW$y5Q%3bFi=Ntx{BwG$b>vv8i>8LtC_TT!dILwGqL*p8M`Dyb}9n z_MUrx=l47J+sNut6c$J!smKe(t^IG6I{m?k>;+%1pU+IiPNZ8{1 ze-TM6A_1LdOXi)Yp8t#R($UvPqIK;LK{el7W!Mow^Q*oC0d{%!9xGUMu}+{)&VDl3^5RMB07rb6&1P^3@K*Nr|1n)6`I{gm(M2rM09Cy z77=nsUOw5kQhb{hVlRj_mS(ReRV8kfb#ePhNp3a@3Pn?$>xNFzfL8#5#M zXk^n@;ddEb84n)8O>fVrmqP!H?viEsy~Igq%zU(<@qsLdf^!{v=Hzy}6gC7>3F*&4 zt`sh7$Gb=hSAGvobO;7Aoy*gZ-EogIXAQ`7aHfYd8yNEy5KOsiMpVo`#&mM#jU`IV zI>szTj?`6uMd}KUNul>}s%IIz9hyxW=_s5ut)wr&sA=h=S5XuiiQ4C6xvTTZzsqtz zX2~)f;*KPAOqAg5B!v$*p}Q+MCxtGf!T`ltxhuLk>-_9u`FFVEI65XS39u{69;oNg z?k{lHaL3b(`y&CT>gv3WQ(+S2=#fGrr!XZF1#p_P;C7bi+>T7CbFjU1f!U;H)*|x} zuY<8V1}VnL=icZZg#K5Tq1N4+g&vCu4x3Hh^Y`b)SMkonB%<~&h~MQNp58$&{uIUE zSP*x|#6t+-%*6{C?^KIdDdJ_5MGO8cwO?R93d;* zu$bvtka1yKtws8)_mo4#^)$`&^;lhkQ2QDDep%k$B78*8?{(v6I8V6q9zO;rcSUm% z?Hp|Lb#;!8E>ub~dNJJk|F9ZRJ8mT^4mUa`exOuU=Pe%aALwCQ`VqP?pci#pRT0nO ziv+!Q?=Fsbj5|irF%$tJS$$dQTQ<1P5%rJvRCdc z$1ojxrpR7)cV^%!`k&#o?^Ei%G8N-RJCOA3NbsUSMuL}E9iFShCR)qjQ1Bxu9K0xn zhPr}N{p>j{g)U&?Y09!*W?=^~Mt=+Qgv-WQZHFsAz(qt0@5+1eW|}&S^~ctF2IF-O zDv}>E$#Y!t4wqbKlKcOb<){gHq2cH|*smCF+tL5IOvqW*oMTP&7~;60Z00H!W(N{aVD>|-e;b-?HlgG$?6aBZbMU&&zWORY zg-)Z2^rMEHWj%JnY&NMY@x;Tuhhfs@D%;P<%A+{&_1bXdW*Z@aCpLsG2kJM3?gqXV z2+h??VRtRUn`;XmNF7t!sAn41+MDoI8nHJ)T}tb(9B)w=c0P`;%~aR@#x^MuWj4zI+9PPcJuS;qXrI0#%X)lOe+3V$5bd5BS*}G}jko$Xv;%0n(H72O z9JFhoId_GdU=$CkNp-Tw4!szE*@)rBDOVo0)%ZIwCCk0=>)c$chj0hGlkUZr8M~}Xi%lhb*=?gDw75OA z7mm8^)CQ;B9-}t)K4oXhu2z_F+l>*eUm3Bl4R-mVplBniUoNt1E+qRQkn#+*0QKB} z-w60MQ#^(-r;E*2^eKFGqaivXg0sX-{n(l`DI@}$N@}bZjSu6dVFo9W>xBjc3AMdICu!V~cQS40nLF)MFK6 zpQLfsH)Gy9Xf8DixQV+;i>&Xv{E8pn%*xe|EhR>B1%^sJbR4F!#RYrK8{%KMF(R2& zI+=JH{y3!ARHbs#$>QZY5vPPL=~b^8V;=SX%NjrD=~#pSa?%Bnc%i549CbkR>L1f) zm|newu7XXz8X;nXH+?&41dQco+6o2b9;~g#@-0X`UG6c~n0P8md1A=b5U4PNSRwVb zRx~8^jaF`_FeoJSNo$*^5EbBUf03~_iEDcCiOMb;O!z&<_}O2G70qK%5b)^4SS5+j z9PsJ1ewi)eYAR+tFv#Y$>f=P|~sq1U0M%A!jC2S582c%PnHGGQ>G!oZYKUlcHT-Fqk5 z0;V_i?b~m^-P^m{d-pW5hwcv39_y?glSo+OJt5j9d*>h4Ni!6XNPGY3(e-6=r4NkM z;}=u7mXO52b&4Vt|6>ce9;+0UhlI4MIbIGOR4^I}xn`*1ECc+SerT+8akSFK(MkxZ z8l3+xqBb5;3p#Z}){A?ZCYOx=cGKKvM*nmAcfY(^VL1FQ{6zhPEf-@Zk|V@H+Npss z%nm2jD=EOIYJpBD{V$*>#Y01|MY9b?sx@#$okdS6mK{oe89vf@z?))Cv0y+4^r=kH zlj5ac!XWw$E1VZt4~+rE8^%+tup-q8BccZMsadcQpIbB<*p+%P^~YO(gn!^jI}RVE zIbl34hpHe$JKM;zWsBOH{j81<6-kE*ZGh&&4y}-3M?BH2(2Iy;iKqZ+*sI_ztpFFb z`V4Ops)0+0>UH`IF$qnD44nX#h^|ONwNQoVW<(p4&~#`*^bJH?l2APyMD#qO?MdiN z_zR+wi1s9*MtFee!gPJcuaeL#C`=b%HKNCpPz$UF zOBuWx{N^X=dDv^7PuIdb=Iq4-=oA`?X5#4GU8^t4@&Jy_GVJAsyZ2>zbQhjJDZH-{ z&E3ICDfBUVtO0|?HFq;-oj}&Z?kl==-4XZ46e;J21KgP}BhLw!_sS1bc?i$CT zFbOMKq|neGFeMW01S(iy*kW+5MyAviX)T#%b|f<^k-4DMz*wCTig9YWHQI#G!+xd7 ze*eA?9ab~63g*%i_okfh{;WH*~I>c77}F+=md3?48c|wPfc! z#X0+`d)n?xw%>$yt98!49=0q~t5cQCIEf6$Ojk1W3PLs*vI_JVT(+8@4)bO0jA(I5 z&T9Fr0xZ|A$kx(__pcAlIOjjc9^Kge+;9{PSF7Nb)uZ3WIKfF|KZy0aZFwry=v{bv zcK%KQ?}(}0yL%VM33tW##-?*qG=eA&?(6QlcyYS+#_`_4aG&2{gC`sQ!3}>x!{|#& zopxR40nej_ZBjE2h_ku4Fe&14jS}(I$0C++LmN1AECua62;a{)m4x?=U=*GNuls$l zI;W7f!^=7IcmDl0p2QtvWG6e`F?1eS&kxU8R>k3}FEM!3fn%;83J$BtQ1AjP=YI-TdY;nF3rqk6Lcx2D`CkTcN2-A;11pD{NZx?zaJ>^ThA=H!-tzy=ORyMs~8 z)`Dk=Kcyjj^&EQ@vlpn;IpzrMz*kJ`xD=|7O5G_NU~R5N%d$YFf+@5ZUdYWWuHi3m z|M!-MtNw+rRsVNuLm&I=YeRSZb^g#~y%a9Ifbh!Y^B!PSZS?dwe3;uv*MQgFc)~GC zZ7tiLbN`@u^X7FM))A?$ZiT1FUF0bBmZZafo!^1-yx6KMW3qe{=XU72EVHev8<*u> zD0iXUk8<&ZERUgFa8s7`IQeI>WEP^_|CKB+N7;b0+=%i5$~`D+@GW}*W!)sa?D_^h z2YoJ+?aB>V#kKK3{-;>Cd@aLMJeox3K>$I&Ixa`1truoP_h_B;U-_?8CM;7r3$ zRe_9Db(uz=rX`GZ7XQocz^eRQRZR@G=V#L!urJ@G67Ru4{!+RTXn~N@h^ODw?<_cz zW^Bn4(SwlZ<5C1;p{M8&-gm6olpa6%;-7l6<2tKZ*4RDEnijScdT?gFg?3s1gM}U= zSt2SHEJUU42I{sOBU(|>*ryC@jZox%l6s-TZKv0v*S!J6;w*@$G~n0#6k!vyB)|U>tPQw&c|OYU@jK5KnQFp-c~dm|B6m9*?p+;Pcz%9^(eHs032#6Q34=zd`^*g+w>? z`zx9?vy^XQQCzmXwmQ&I>@Ief^&hKxj`lm2G*T5&!;7NZcrKL(Imdo(V8fCUJ;v*4 zqM}`oSC0tP@6mbVCFO+*zfac~*BYVC@0%*O2;N?-?S?`BPE6fj?J*{bWyHvB$DyOz zGxcMs$HY;S9^S2X>k{YT5PVg=j4lR$z@tknZY8t@e7Ym?O*{f`2Yl&?x{57?dx1r| zL>XwIqQ<97?4kkMYJ5`%g?RXg1O@{Fd{Ps|V=)-?=~^l{z7yzDpYBE#*DSaq_WuE_ C^JkR+ delta 3449 zcmZ`+3s6+o89wJOk6oU3fn|3UcNca|z_?uA3rWyjVfEVC4y1+zI&p-yiISRxOfgN2 z4qBwi4s1*MOQM~2y0kM+&6pI+OcQBD&@{B2##n0|y8=3WECXhD<4V*UpgQ7z(^%u zemoz=dLr^M#V&!Jy7`z?d-+MU7j=AC1P7_vXo;#UQPu*-=?6xalWSZ~?sY*>*pd7H zB9drC0tVfVtiug2IRj05pWr^~ml!I;a*5eGRyMZz!}oYrll zJ@ApvOs}i$YpjKEX&f9%ut0lUJIL`C`j*N)r*h5l7HEvK&_AN=~s>JdAD*o$y9Aq?KcU%{)oLI_ zAUbH$*U&ZaQ@t5}qECen^~vxjeM)NnMlY%eNyMK3OUN!FTB$+fz-=(YdP7R8tU(iC zJED&v+NeSG5JI#E(Onue2~H#W4x-O%&=mL>(P>0q)}U#yCdmvrNhzsEG^i22if91Q zUuw`S*pKKwMBmn++3*IUClLL;2DQN75FJPKiUwT;smW$YNlrxG2eQr1olt`lFU>+#HwHI{C#CFFLx?GBEs?;4lK#)A{ab_$0xGfbl0OXRW9u#I(N z`PeC@ufcCKyEB*W!$sed*&ql19oefW%6sus(3Ew5LDQ0=1pSMh`xlixb~%)KFpZF* zHK>(C<$Lfhl0((s!!9xk?_}k!O-FU-99KTTln$nj@O!dx%oDlzqMk1 zA8%W{g2*UBICIfT#&2PvLi~T^-NhBYJtQn?A*PLS1uw8@|D* zh!fGSk#MNa%(O>+XhxXV}Y{j+=pdi4tW7{#;VWgCGHa@_PUu#~f|qY}e( z?w=+d?C#u#DGfc&Yu}^RdvzVgi*%ysi822LfsFYtu{u0ck4+@N;GqAa9P(d~gQMO4 z=^^%?eXMGR*f{P7u z$Q?j$|XL533&Rr?J0;{o(@r z+YE}RKr)?HY!4^TcQJS)NQ9WIOUd%`sf>&RRKHNVBT#vhV@=`#J*41;e~?2I&{BK zXxE)j^nx$>acTi7U4!2U`2ABffiY)_%vR)7y|&R20}&y&*i60Hnsmt|3=b7=v0gBK znKm6WIEmUa_(QQoU0^IR=`u+#_GbLX^5MvY(R?_vs3SAc!?PvdEgpz|{l;cyuSJ2R zlZm_V+$invC>T2prBHs`Os9k1Er@bCF2&8 zR}G|=FP>F^ugVN!l|0y1)fhK8UcH;bh!8g@Z)~PQM1a@5g~ovd?is*mE<0>6>6MJJ zy*?i;k_}MclMG_CaztqHc?{m@$P4{G&vI3T^*l}+O!_*oa#}Y@##l96Fmf&o$2UpK z|7qGXIeIP`u5T(d#Hzata%;BGJZPP*eUihfSleE14Zpf>xfFrdc y?5Zs?#J0-<{k5Kq*qxwPpA>}55x8Fa8J5|k-(zU3;t6~k3O0M_IcV8@@BaYraU44U diff --git a/integrated-security/web-overflow-client/_6/server.c b/integrated-security/web-overflow-client/_6/server.c index c168dedd..359cf401 100644 --- a/integrated-security/web-overflow-client/_6/server.c +++ b/integrated-security/web-overflow-client/_6/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_7/server b/integrated-security/web-overflow-client/_7/server index 16d56522d346182935da4d3948febe19b68bd8c0..1271a8e5d6c1520984041ae7dbecfb531232e46e 100755 GIT binary patch delta 3569 zcmZ`+eNa@_6~A|Pfn5aIb=iHpxb6oFWBp)v`EtQRd<$-Tj?PF_($T>ITfY)TumO#k zGC&c_7PrBiI;}P7#2J%*jLnGr(S(V*R1-{N6Rb9|Q&TavopnS5eiaq-dhWZsuR64rQ6h<4Hbx$o+vX$nZB{eSoBdNcT-7Yx)J za3=9l+!8$>Q#8r=KR%z2$IC?JB5o~ej+a0?6%6`3KGK(SmL7gbKR4Li9JRSQYJ-rf z*7g4)YGV<#pi|doerbR1=*Zp;^Xgw7zuWMly>?m6&)|yI{CN1OHNI(vym(Md`1=d5sr*NtPrt26RHN$_PD4 zKKfr6K;4kSd6o50SE;CBG|2*0$rczEHISB^30v^GQKNx9$!{gU()2_8182%HIG^Hz z(G(k1LArLPfo01!wK?l09U&@`3Z>dgYKIoBknTV{-Yjq!5$7UN0aCD6!5_2&T-K(g z`w~zMe1&M5E-hV5K$9U|CqNmZRSBpT$`Rd$Xk7xD3iXJ-iD+X2ng(wndJfUH1avz5 z1~j>zk|pJx$w^gL&k37SMzX=W@EJ!`gim- zS(ZOe`V>kt7tUGwSe8SDx!ECw)7MNVq<qDl8X42cnHii}!kAm(>r8jqA2Dv6`Dr>bU7R_Xs>Jj$rW-j@cl9NyJ2)(bKE|n@ zXK)P!Oe^R)*l(Ik*TaXVtcCq33JpdxaQ5!bnk%y0k8`sO4|B);N3wi<51u|Le4q~9 z-N6Yd^aU!`f!^$%y^XVuBkM`|D(*PQ-)L z&y?So=)VnZ7R#&yJ#1ShcgLE@IDri3bXl9QVXq@(g+Yrz--9a_)58e1N1 zgP+>ww*Kudp2U_B(#nqaB^38>;)mx9tKx9^1q>c_;+&fXgF`AZ7`(^|`BW8l(d($) z6bk-T3I~Uz&_H)^q@TSAq|j%$@}sEfjO=D%+gaF`nI~La&%^$Vh5h8NT!z~|auN%e zZPwZ;$qFXf$|c|BlHV}NFL27}aqL2;qsyRSmaw@J2e|!g9xW3!aM4|SD`EOAOjL!G z{%>VMPO|P4>!KrfCS~W5)8EKtC%9}olUY%QA@;KCFx;GFFZqm39E^4cqnNE3&l0~% zLHNd5_9$i#P^n|Y8EU~tO!KG|s*XzCNt<2vjc(-3zP^geIz`aNb3PS1q6O7^7;Vr$*s(dmUW|K1bbg=SS4qxNE!T z2Myb{ZQQ((NUK*@dGkH_&LUr7Dx7w$1WWe#8qG~vK8kBQb4!-lt!o;Unhp=SkqkaE@EH6jfimTj$_Ac6eXgAC{I9+T3v=vr1FXrJsmgc=J9DyW9URPALc8E&;|E{tLvLnm%qo^O_LgN$3p?_>^ei0CbI@EE$nzS=B2n>R87i#{ zsK;T5XhmhjK4e&{gM7~l>VtNVgWiI}p3NW@WI{xx0jGCJJ!BB^`zsgpzF~|#<`Wc- zF-c8y#0Rc?0T<=UH>szQ2)vNL#5!ycm8glGnq-h3=tb@k_$1#;ZD1%csg0xytzeC> z>q&(P*AplZFc-60AOv<4?8+aCeM85Y>}{#S*d(@ZaoiQdMX(lnt=e)i?oe!f%-aa- z3kB798N62LaS=Bs;VWHf{n%4tAo>`d3IhcW-30|T5*v&adZ`v%MZ(hfmo?WB@<_SJ zoV;Cee7aIeGf4cKJC3^$r-UuBy-2`k+rgr5tnoq^i;)7znW55?BXGF*6zzfa3tp!e zVQfJyeFt9fFHz|o@GJjL8UaIzfbKaZUU~@Dl+@z&2PIy^W|OD{Qpy#t7C@j>0DY-M zxAp}}8#FVNFJw_%vV3VpWo?0{z*F4!Uio&~=Uh}rRYVOx7CnZu$vnte_TvK^mYC=@ z+)5FZ(XCiDi9iEhoiA2mJ}3?Nb#<{(9qbPHC(AE_?=sf9U?9+nsRt^&hIsJ|8@TTn zv{!g1e>(LTIciLUKUH{i@$+#69#kx$SrDl7>f)PggWZ*WU03Ypb-@Rf{?vG#jn9XN zl?!z7vd}{5V!tka7xl1vv48U55HFvRz(Az{mlj9ym<$B{y2etDw*r0MuluH)kIc9u Gj{gCR=VAr` delta 3439 zcmZ`+dr(x@89(Rl0=qoqUSQo_fqej0P?x(rbRiA8E395yI$|s-%p?^iP1MvTI6~SO z9kocB9oW?LE3J0Sbos}rj!m(oZKUymHqy+b#>O;b9NMm(c3gxQFeN^K+6rj+ipwLsJ^OV@l5`UhPK}Au0G1U>4aKM5}bD5jAi7nDrow4N-$e8WIy42f>^VvS`w>j?QI({UfiH4lteB*p_#shz@4v$HIs(@&J)p@@TZ!^POC zmPg=^+1=T*%W%;N(z z$_msd-Hlh3?qF02UBs!LV(@lowQQgxaMH4r?tl@?qKB@bDKs2&&Zug4*JJ-w)j^z_ zWjMr%WF$t*@ODzdy)8(02WOPf2k6KE@4~_*JzRBu`a%0nP8>sG^nC$#Ep!GNIkfu= z+J`yu1k=7O;8fjR6F3znQH6{W8h!&)A~68Bbs&JWL|y{DS#9XLx!Cx%m?`e`nr& zEN&h`2xs=rXAF9Cxn|BCE1l;n^t`}$Yku!Rwk~taQ>~Z$1tK=r0;eAOB|>(%VYAXR zpyGvXv6rS_yQ^&?UQf%tfj)bIAk^Q1w{na2ejOjtb8Fpv2j>ZQ-R0Y`ic_&dM7z$l z`?|YEM&>J}2w4ob_ES~^dLoSz9wbJ8q*YbdEgq1)4%m{uhZF{^MBf%&#Ir^%;?&fG z5sz|W1c|X~tjOp;v^1mW#a(_K-#>F#VA8Ijmr*<`UbZoKH_t<_z-->qy;T^dbI&;0 z%kIt!Olj~*Ui&_+-fNa&yjUlSo*E8b7RYe$eO8BO8?cGhGdL7{PYDMvE1{w8;P@bW zPAj2Hcv+d+Wj)Wrj$n+zZHx)8h_c!a*Noyt#FkH~d+}x(KZEthR_`>%>pG`djx)>C z-0~W?2rQHP|5eqP1$ChdvDfgt`a=6NgP*B{oMFvb*2In?jtk0Weu9O0hKJe0!(3%E z51>S|eO2e%Fz;K=e9v;9m;2skzTGIn?60%)321RRgt95v=djSH;b#u#%4_%(I)yGW zh#qo=ov|Hevnkz4C%&BRg)v9LiUUlnJ&FV0st?y}au5=DbbaW9K;!z*RN$L|&`hHe z_S7T1slH@Z=^Qu3GrCy+tAFZU9fgbaUQEs(Jz=zH>`e*_Lge zP*pa^5$q3P|H!1Oj$>bYTUFEXMO}*9wH*7$@2P4%_CNDFRh7|A>QY3uFAco7P9YxsI;cx4>s`kU*3JdKMm`?=#i6akBSU%qdsmK|S zF`F^=y%Jm?z9`gYBpd!^NKY{lruq~9*tW}`DP!pUi zT4(p-!zPgqDzq<%1DHVZfVB8V3a*z+YRK_3hCCYYU10XeS(W&bV~1U9v8jQtc^p)P zZ62BS!(oq;I^dK?mQ3;YEZb{#w81@(Q;L}U+K7FHu)_}}r5n)we5uoLDa8+gv?r+z zsC)x{FW^^>H;OSQy;eJNnqJ=+h?$7sF0)cUwiZJgiNMCPb@t2BmuWLGgOjMOgtyCN zY6Pj=V#r2JD!1a7Q~*a7j26I=O&eK>33il!zpOw0jhmR6z5E1{Num$n?l|rOdxdNl zw+)T@1qi>xMalkKp&(R1-RaV*tB~>ylhUTixC_PmrOY1Ct zEs$2Yc(xJ()m9Lzm4UYECgZ?J&2|ds1ml3Rx`hfc0gn4irT%2@>BlE6I~*|Tm!-ts zUy2vaDkuraW-(q#BD4m4W`BI-hrWPsuF4`N9;XdP1ADQOwylw+M0H%2I2VCqYvj3q zGHux$y^sbs*OZzQ)m{ni+I3WbZMCvFv6e>YtM!@N3jLa+4X)SvQs>s+0|j*};ZU6j xTkE{$#CF-Bug;g1xHC-JGlG!21a8)ShGjPz^qHHgc>>>slC?g10b18C`5$JW6EFY( diff --git a/integrated-security/web-overflow-client/_7/server.c b/integrated-security/web-overflow-client/_7/server.c index 85e9d784..5aa598f7 100644 --- a/integrated-security/web-overflow-client/_7/server.c +++ b/integrated-security/web-overflow-client/_7/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_8/server b/integrated-security/web-overflow-client/_8/server index 4de0b32d0a9686de1c3a813c4b3548d408e9c440..2b40fa0344afd260e088b6cdb5245e186cb49a4f 100755 GIT binary patch delta 3555 zcmZ`+eQZ)Lc>RkuM2g-S*QNceOi^zGbt?Zi;+ zD!J#K-}#+$&%O8Dcb`Z1(Y;~XZJE_=6bWm*Cq%nw|Gc+#(hLP8(*A$Db$wY}=>r3G z`^6NlB_z>vouWv^|5y>%V?I%NNJxvC={m(>EDQ2O6PNs60>V5??3jMix2sydsVRxE8we+fR(xWSWRNikzUJM^iH(4FF; z4`2}eMikBt)D~`mA01VL7P^{v>~2o7U)I9zDQJnH0)JyOe??zZAPXi z3Dv+wL^E_5nPL)}3Yj_qe26YjLbXth=w?KNNoYE3LG(>To0HHCIE3hjh_)x8GvObI zP9oZ!gc{&6qDAQ$nSV$^v!OU$fYpeeNJ7o92GM%Hs-ZSMa96+bgP&5li@9JEANtOq2Y?fg!H{5?D%h&ec>65}eK{R&- zCZ*74=&=U$X6G}TIqM{{o^)Ty4R0{_XVkFDZ1Y!eX!EzYx!kalaWAWIsIJa&914@L zphXG|{TWjt(GH-38Ai-{$7*CsospKZX=Yn8(}&FY<$A{Ih)|3Z;MV9Cgr4;CB>R2w z2zFac&?1=1Pd=P-et;(vlZa-0%lR_5@bucb^QY)sKkfWZ+_?`S9N9CSF(fz( zYFVzGk!|Hq?%y#qSQUq>?_lt#9miZh6c|yFp}=`o$Y+*g7rlnQ z>qCKmO5wnW6dLRbj191hKni_?vp9-Aosm`+wwHzd8MA~dw(zjWS=bNm%0687vC~+< zY_V2NyEHMEP2AteMFp3ijq@yXYT{0J@m9k04>70Z zNE!G>Cge2h&af^zc4x|M0yzWC-0c*1`!#d3q8o;In>~l&#+Z!^e3+x&}P9;7R*e)Y`oL zMb}T8Hg8_HVI7g`>zBJrTqX8$Pgy!#ajbyK{Mf3iW3qe{=XUs}EVHevAD87lDEFXz z9p%CaSsp_<|F$e=;N)Mxk|{#@`q#3&3}qwEawE#~DEFbP!?)~tl=YMFs`EQ^82X$> z>(yJbjBBs70_<^K#DfDz;G)xM9ljyUC(tF)a`Azsuo$cbwtN8-_?`yUz)bzGRJEC@ z>IzLpnwBuuIsC7<2dfJ5RCO`fS&&0-K~I5GB|e0Kg2i+r&_W?4h^OD!?SVs+_5;eI~lPuB=eaJlwAC$PM4-BOywUHb_ zDOeNpdeXy$^YNDon2T905CU6Ex0j5>zoHXNc3-M6Hi@rW0(Zo55v*lytF~H97!-c&RIG0DDRdIK{y-mhc4jT5yyLOB3JHaUyx7JY-L8PXeE* zl+G-Y_{vV;4#X*8Q`%iF;M?qt@>|x##!tjae&ozj>B(W}tvExwVeNv~=y{k}&`95c z=e)C`x1?Sp;AEe+)6h+2tTfD#OHS_-G&V&Q3<5fCq69zf0Y3GDv56D_g6J( zW+~sqqPS$)(wf@FQdg;~qW^gHi?rXqC`eUA4Zjp!hT&8mWSITjz=kCyx(zqeL`Az9 zuO1Po->vh+OUeUPey=VV*MiXM_fC}?yY*Px3xob$n7Y5lZAcW$sDax~!0sCN)Q_cZ zBS(!H@Ru5wE^!_X!`C%S=tA(__##q{tPE!vdMzl04;P(6W-NDAB zJ9F>t`~3L6@4ollANO2{j`z|&TV{KfkFbNcgp99!e#H@!n5uz9eEtL3#(KUk>j zFHGd4cuzz=rr0I1Qx6}LY9Bv|^`e0fOJF~hEVh`+7GrI2l)h^zaC1$8n|li&C^YB& zzlbCjk$}n2oV_%1-Q3&o@3uE;wvILbb$jH_4=%n3orXgDGK{&99C49-R3r>@z)8bq z+6x~VBzi?_Ut%qU%M;*0k_|c%IzUOZ(cfs?QySNjXoJQC8~qC#C1zk)7aSL|pf9n6 zUW4I887k4)mSm$RHP;!<)qvPO#GZk}Nn!9M{|c@ryFfJNQUV_1Qp+vOhOOeRB|A)n z2*dzQ##*`zUNK7WGou+kFs8zvjA`b=8Xu|%NyeW5^T^I2TB$=5z+;kNl_|}v=+Gp1 z1ktUCHtJ9#gb?jTv`vSmz)3{kLiGDOGz~sRbPCbubZ9y(OOYTqCCz+Dhg#r4MC%d# zr4G%8J&1N9`lb%ef!7c{hUg!3s15#x=oq3Gb?6c>r%I5Pnr4pb(A>tLXF*Wn?()VBJU| zcB=I&@Y}4OtofC==)1DED8Y}SyH!m6ubr zm<>!>jvA$B%SELpFs=mO#;G1<@J?v8ZlYsw+`58331ikJ_gz9$a3t!SQ`MgCt^ZKf zL7baqILwJ8BqmDnc2YtITafMv%qhY5(P4&?9QVDwTyKTdN@SGa$eWlFi2~$FIdCmU%-e}drF&>s`J(a_y|Nya zD=S<~)ip#h&Nj|Q_aO9HUxVIvbr$+9^+#Lj9-k`=teYAIC@Z!df?dit~iJZ}M&U2B)HK zM7xJNygl7xV~dqihb)F$|6f)EdSWFfJV;FZNUN&ut30497Vtb$7_b6;+jS97Cuk98 zX6}x7gcD;(OjcnMvuwXcvke9SMvIWF&Bb)#2#|Y@+oH4hGIEp}?pT9PSBB z4YKF75p8qS@}(`8F;3>Y495+*iVV6U^6%63m{mRIWjb!y%N;z&?kSJ_bK^IM-alr_c#> zkwNs3Q|ye@J)2GGNj&z&>_M1x8e~-r7koy<@Ca};)SoF9*&}DGp zkbT*_2(J~mh3G9fU$EXT;v*=YB;#4~2T){;lrA4h##MA#8nS(iArHrT7nnS9W(B_b z*kRXNY^vc)9tRa+hexIZaM9(&GLA8)OC&pTnqJ=+h>3`hS1M5-wpK$b3ByCB8|N`v;Zt+Rznu)!(PJgD?g5`7|o9(n>Lb&5uPmjUg<#W%QrqVdnF1a zgN)yW=f!Xr*vnl8vkHi$hwUj$24bCW(I;$H_dzDPfnize2*8hbum@$MvORpSqnve*(Am)M}$_t*W`u<6$m6ubgnutq&W?4mC0-4q7S4s?=sJ1f z|4e%pN6)6hm376Ycy(7mUhM{&4?AjQQ+zE8pug5@>Wl4JAADHrO<7of59HUafkSm7 xwAGcE;@f3|{yJ}F{7x`xPYObA61Y-#2g__C;59W?@dO@+qV-;S7FyTe`#*Yi9Q*(P diff --git a/integrated-security/web-overflow-client/_8/server.c b/integrated-security/web-overflow-client/_8/server.c index 7ea9508e..1c047327 100644 --- a/integrated-security/web-overflow-client/_8/server.c +++ b/integrated-security/web-overflow-client/_8/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow-client/_9/server b/integrated-security/web-overflow-client/_9/server index 4c2ac58f079836afbd6bbf007bd655e14dc3b485..e1fd150dba55076c8679250e23523e49c99d4b57 100755 GIT binary patch delta 3474 zcmZ`+4Qx}_6~5O$$+K}1JN|igNMbth>ucusKhq9GA}vaJ=2un7nwG@&D< zpi)B9w79`)=n<+q$~GiAZ4<2sk=8aU;0)Hl%G$8fs#EDm+f8#spy8)1h0wQi-?bA% zwX5XbcfWJK@1A?_x%WMf?xTBSw9lE_XO##mye33gynp`h4Du`$B=Y`$1PuK-yweXB z8VEb}yq9W;nfEC+8TdcBfcGbBB=sTHI<*|Hf<08Um`ixiT+6-8@CW)quFc0$n~$S5 zAH1OXsrUa$3Q0);4BEA}O(&bTy*EyLi{$pAGiUmBZ~o`;F?dS*Jy#)$rlKRnL%OJ$ zFw6}nv@0pV=US0oSLK!QPfqsn@ z`t(8iUl>B(i0bnstD&V{Wy6Ht2~8PJ7?pHj%CJEzK6mJJ@NCARj9+eh9RI+Rc?>RO zdSN0npK2gWm~COvvQ_QO+hia_LyS-@)YC%PC5TyW#8bryhY|5CmQ)}UYYn_Eh;T_T zWd+kv9ejqU$zaNo($EaZGKf%vXj2+0KrNzeh_o;R`<@H&uXa$-&F>Q0) zO9;7{Q+NmaTOR1If1tkxTCIilF1JMF;UTly3?D3%h+;2;gVtW_XAj{Roz`YK`tQU} zMN!_>zX#Q}Me`c(DM~al)xB#<>2%AntmWB+3>KiT9II@`Qzyr2e}+w>A6~V2HOds6 zvN^JHxS@&}Hp3S-U(K5+(>=*0PG_NnmrD#ARf!<;^r4U3+x&^#8yS_O@1pX<3|N; zM?Xf!8ZbM2bKAJrarC;MzLFbWVf49Lc+}wzS8}NBJHGkcu#)+HuEC*tdnRxw48n;P zIXe6nhC~wGKt%_PILzMF=qdNaJIiN0SEPH^pyxvsX6Dr$r>K+1t%)rN-Otmf^Zt1k z_Bid(DcUQJ-dl4ZQ3_C^o23&U9SH$?TcE<%=k^|f` zQO{!SiEpd8fB&9AGtT)hlMim}CT=*2hAXvj(-|;rXFicB^u9Ma;CB^iG-J16#q8qU z34C2l@80d(I8Ll*l5gy%+?0qTii3xGdoEp?$-N=8qTH8Xv%%91zvqU(qG9ZLHBWo4 zalu1L!FDc)v$?b&O>wDCReb3?isjs}1HAc;Im@{S-_O_7fDeqK3J-$k{Q+2=UqZX! zh5Y%uKe~k{ao0H6%}(E)r3`I47nSk zk-y8a$cP*r>Wz#KvU^{SzK=6MikzPK4ko*U$^L>_VwGFC>~l=^+%2UBmwo&sCNNv9 zM`tJvjIxJ+OI<2R>i=g?=cgVRoM+6G2*Aq^#-X3sIWT2NT^J{vfa=#3;WS_hsb{*;OE zm9y;TW%s4rJ?@F_!Yih8LXI{kl88VI^uj(Y~Ft7H3P{-3wE zwXNT{p2(|KH3drjrJjmlxe?y-HsP{?zUZ#ObX8G~;`Gjg!8do_e$0slILr7qin0{j z=W!aX*iK=)58F1pMlWLf6g=WvrvJ&fqQv2KpHDx5D#zd>U#Q>*xF95wZGKKupOvAl z)R{5`l8?|C{9gm}irusg8jELZ#5=H|xQMnww77xx!G&T`zZXxcb>MpOl}t;AO+tS{ zo=CP5SV{t=NAOj|ic78Wb1eB8Happ8`Nax*1+pT*){+1{3x`YGbPf!a1T18+q*`$H zYS|0a@3zDRN$s((3|3m8)W3`dVUOQUufbveMv%&E5ZCCy6ByBsSS0*7ngizGC~991 zimH!QuO$W&1aGNGTd=lkXOTE8FKuv*S|n99z0#5#(g*$Mdj!sv2B-}zWp=HVbYUyH zQuDf>VaNG|%S4RDp%roWww7%#9Z7!SraalZO@rDbxo#=ko5Uq>l?Plxt&}pT?Utmq z1J;#`n#mg2S?>2v7D=iRU%+Y^#F`Qd5qy%`H^NYv+xVf1T8V8A+$i@`0lXDrW9q|K z^~36}`e2*huN0n*nM6n~NqrKha4+JNusQCj5b-K{rQ$1BDif|JoxvGlaS4nDE+E`b=w#;AVuN-)z_Axr(S=>T3L<`SIe#_YmE^?Or zHo$^8CIu|lG9|TlEtyUd&~U&IOy*b+s>2~eOS0DjJHnyq{EOqOhn2lB6yA-YhwB2C zRQ8Noxa}D1sS8a1vgxyO)M|o1*ZB>p19AkuscX>WYN4*)Z%nN&{@~bIztGT?+`le( zyFO%0rP|~IxP!)2W(ZKdBxFeKqZxKA2~D3J65wMJ7^)ZHlO+i}DMOKvp`)7PyMaC& OGJI9bdk$O^_x}LnO+NVm delta 3304 zcmZ`+eNa@_6~Ff_3%kI|F0kyb!Y;eu2!`F|V`aexeJiXyJG5Y}Da@o5rcL~)Nl6Pf z8W~Ipsax3AET z^v&%3_?`3ny>st9_uadP!*rsT95VB0NQ^IB^Xda>yb}Nu z^#Hj3y)ND}@8SVZdrq7^DM0o-~E6zNk9 zk_t_PZzB3AqKzt42Vq2e5#6Oili@U?Zy@@#3QdKN5S>Q!unJuPIms5tPEIwvtU^uj z6-4V0{hbQUgbqXxBKo=t&4S+}dIHh&D%1-9Ky)0@t15IQ7*Z^dnv!aWs?h8K)9U*P zFB)CCn;t^$$g8IY)*4@>Mc4{rlBGFn2>Ce8eh>Rq5A@f?`vViEHVQ9gq??Tnkw{}B z5j(5K3b2yRUxUA7^kghPgp=N$v0V!NJ9~hA%zWF zR}eCkgT7LDT{~_gDO~ju)jlGT`ktl%Ek_ET3jLyC2DRmFGmo0mK zU+r0ko)7tQnOD~^MVn2!khpVpPAfiRHawl%4=`)yrY^ELl8RTq%*$rH?{Qu+=M6I6L3F|B-(&6D&}_F0C9`nIZl-(S=XOW= zb^HnqB8v~|53s-Hk6B2l2OXx~q`;+lAjCB$0&#TuyJuS;8;hnrZEx9Gj z5tz;M=S;E7LvV%hd7;{nsQH&BHAzRZ5qcAU$*?8gL2a-*f0gj&JUpN8qIf~cucac) zV>8U2R+x7?Oc9-^^w?3)9uW#X^~m1uacC|ii4aJ63}d3+8}KIquM))* zs5w(?v7t@zR~H(hCq{6VSTKHPiCL3EBCxfj)^^eKMZRem!723h!QV=}w)j=-vw9h% z8BC=XyuJiV%^EYR2e4;VdKRLCr%HcVax!+aj5FC0B#<;R@c{0O;kjTd^V*ED3t^n~ zM9kU%EoBw~C-Fd;$9dHyDt0_4m1hV`N=zi`5|w^3jFdW(-&fEKayK9DlzDLOoIcBz z_=QvP!{WZu$i(FlxC*qW_F+S_FpypBEe{AuEpNT01&?j9m5+C%h zJ4>XwBg0 zXbRliTH%fWd#XLj@yWz{{co$w_04&r!fA#NtNqDKE8qrKO*y<=V}xBb t#rpVyS)sqipB~>VIxm0Q9D$oPpJL`s2L1ZRN)CP(3OD=dD70)|^FKP|_t*dc diff --git a/integrated-security/web-overflow-client/_9/server.c b/integrated-security/web-overflow-client/_9/server.c index 1a363004..c0a3c5b3 100644 --- a/integrated-security/web-overflow-client/_9/server.c +++ b/integrated-security/web-overflow-client/_9/server.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_0/integration-web-overflow b/integrated-security/web-overflow/_0/integration-web-overflow index c11fbe6a70a919a8c4255758ca070c5039b47125..184a7ef64ff7c0945ceb2bf030c24f3d89e27e01 100755 GIT binary patch delta 3370 zcmZ`+4Nz3q6~1?WV3&aGx-7d32n#Irr?Sh>>Y^k1R@|^Aq+-;nQxh;&B}N-g_auUmJdgBs-aOI&vkwpY+PBKgJ(Ll3M85nh)=@)p7Bwb2&6nX=BynTbi$=yY z>?*YOA=5$tpmCT zXhQ;;Oz#8z9O&i*)JR_d9Rm7x0-8#XfKE21rtMBZ)2Y~Kqh&zb5>PWe2lO4FM-osA zwE#U1^i%?Br4vB=fp#aLHo6WpCnYs4nt(bw@>71N-)Sl^XgrMFl8dw*lT2%PYC|T{ zajS3Je`L9}BVzV)FLZY&GnSq=hq2q~xeqYEK5G8WsQG1zj?J|;=1MHs)oD^h*Pd|_ zldT_9wk2$N4t%!JvM3n(Ci+uZmQU)RrlXeW6GM+=ITRRb+A<_>%nP=peSl4KY#g}3 zmMMRELWs&c5YbM`$;dC71$NV*%3L9sPL;V`Wu6ku*Xf0f!WoAXnAw7vuQIDuW<)T{ z!3l;JbqB+N-eBk?9(7T`%cwJB9`7NubrN4rGpt$Dp8_1}iq0F7<#6+|zsd43v9%Fl zsj8R?McLdN$Mbhbd;CmQ9EIZAG!%I6 z*GibZutk!@w`=$fegoHn0hJn+x(jwuPxfTKjf^>yW@f?-Hapvzhs{0_#>ZBvTPdJy zpUTZRv!kUTt?CN&YFJm`pQ5Zktwk4oaECVJWWVqsw9S#%goE>7A6uh3xFI%0OQlCR z`09?5@J~=Z;-!8tVzF0PyrfzjS1p3Vq74?XUM$8nbR#Es>oYJ41qQ=`L3r4OvQ|fL zfq3ndI2FZN7HsNwhPGh0ZyX4Q7Da<${i*`Sj>11X2Jh?>F+zT#XN3Q-zT$st+ZC;_ ze`Y{AJiZK3cwBl}?ELjFu4$=!n9G>|`*TAV{fp*??)n${Lqm&#EyZ^LFQ}RL2$2|~ zpWdW1ecZ8r(~sOMUS7L)ur_^2Q^p=#T(AE6!QAI)9 zQtx$HK7cR}-H_!Akgfq)eiL#b=Cw+U~_0V7zSq4QkI+8pGwXJ3e zx1l03mGr{-%@P|p`K4B^k+nhEc(*cpf>qG`((2N^W=Zjx*lAfhi(fw<$4yB3=~9m) zei3|JYhg>sTxR2T@|Rh)Rz&YF!|kmsQ)|NwZ9~~6M{O)EaXayu)8J{1#LI0wLXL8e zV?yle8Rx8vaRz8PICgpsoU;XzqE1tK#y*GS%*=YJv)se`=_Y#Q&TDhTFS0QrOH;}q z14}R;+R^V(4lQRQ+HGDNZ=`pZ+Bx-kO_76cO?^^h z%BAVPpKv7IXVaK0^e3O2@1gs?IdM?@?kOF{%9nV@=9%@J@1;w#JYyS@R38mE&_qMIWJzxGnq*0tu8CDf z1ud04#*u{$>FrgM^SxRfdkiXoQB;omA=)bBCJOJT2B)vc#XK;wmAvZyGL zW46Z_uju_We|9zh7rhHCp3HtaH``}iQYa|~D2XbcG5+5M(vDetiLnE!eDrpeiMp#w jhKt{c+oNc`osW0#x%WP&5_~AZ`(4(_`7#ra)-u-oYR&IV)decXs$V_tGll1BgD_dS zFMKXX8|ji+v@wUs#m`%-jlCgR?dWn+(r^p)aHq97!)ng3n&}<>FY8!^#u=-S)y^2j zrS|gw=P{M>m?D#*-TwXdJ8S>6Xx{e2+rD%BaFfG0^_J@!|0=P zV8y^P=i2$NR9CO7t|ozdb6xx=v?OUF^Q$< z!@QPyk(B;;Wm)YS(H830O{Ffp%u0 zd2}76zD(}I*+=5?gV-?3$@Z8fgS=nl7-snW1ts+ zp2RUBEP`L*e&IuIfDx=TlgaM-bM+{^Q>U( z^Lb@=F#gRq#s~EA;D9y2$!?qPu$0Lxk{lf<6(U&!p*YUcw`~bq*CI^lcH6p0{7U-A zilV${e1^{3mew5nT2bPyGrPNHlETA<_wY$zHiEnZ>LW%yNynNn@r2vjv<;V%@n&qBRwXzlTs?3iw&N zXm8`!sNS)VZ>0^6;-y;v$CK&y8AVC-ZunGDhQ*FWhHEs%<4{c08w7M926du!CK4Zq zMIRk?R6bIov7`sg4Vq%&F3iUyy5sPKui#*S;YmREhk9RAyeYV^U}HuSy^{!qBu+yU zi6@7U5=#@kQB*{oMV9iNU`BdJwlBWNEJwUqW)#eC1^j}wdxXQ!gytvR1?YaevFr#p z?ozqSK@O)QaQ4ou@vk$+o(GJ3vyJ;To>nCQK5;a;Vjh8FH#{!*-K zw&IAUcn*q*pQ=^WdqZ>hR>t93sNgUFyG>ah+i-NjW8(uJn>0lU6jzs^B2%BJX{KO{ zRennIs#QzA`UVGtO3O+s+cdS6EaGFdvt(iSjwx)pt{K)XcIO@#5C1@`{UNp9LuU{z z{R@zOm~6#`k!-yz>hLeC(WIXiaJ=WjOFhB!xc^SThz*OY?Ud+YHPa2kC}I4=|JK^4=z6KQagSiDXJPnz(Z1009>&7o zT@@b>uUi$L3a<^vXVyjfYM%xCWVGh%$nI^EJT4uA=hEY z{0Q=W$bFE@u>Hm$qqL^-k=p*x6a}X`V=MA3V&eVy9Rh~QQJ*TbEAV^mnxb^l+m)5> z6!M9|UVlo^5&6uei@pCYTPm~7TM*YdK|QkZMFWH9IDGr{^Be!u?$@$S<T(C^z9*+}fy-0o!NKXx3tP191BE8l#Hd$!c zct#FTO|8!wzy%~8{i^rU=2{Q;Q@qy4SJR1Fk93#OziaEP)tS3c)PZ;`pVP4<@Gj%UW**deM$PWEL7@in&w+HbzeVrV%N+4cmS+(HKfAMtV8+UVo~ ziZ{N9=)CFY(!~X|ziFd%+(oyV9+w76X=(5UsE!4l(&T*lN3f39&~&gJ(E4VdHEEaC z;A(lIcau7TPCD8g8MG|1me0IfDa_#yA#~%RcMsT+L)PP9O2yrO`({_}H{q zqj|E5L^E~JL_M<4v^Rt9r4w?{G?W<)(XE%rvc;F*7#ZOif0@bW}!@r9Z)DY}8C@(ZLkkX0lXt5RpNJzMlKuE-a*d z!`^$(cfRx8`|dsWzRTGV9S+e>6Q|SjggsJ8NZ{D=-)I7?cOPc zWF=~%lWdAr3jR!`l5MKw#YUo@lEraoqejjVXF1|52fRZsa}!pHGhyY$#smaqjRpTt zF&0;hfkxh#@$#eRR@VC8p84sIlQK;evcK z4Zvz8YdDl93asg1B&txfYMp>n81bQhxEPC}Ki8`0y4 zHYK4dcoWe}h#p8nHSiZirx87zglb_1(Gra|?H5UCI+SXRuoclr63W3gM2{ePHVM^3 z7}4{HUQ9v_Z~@U#Lek2ION6N3mIsK~T!5Kja`lj0tP75vh{%{)GG<~_q^@l6| z`UI;gC$Nh3Lrz8kT?=b6jA=(D{363&gJ&}eSD!(Z_9;oBkSP>M3e^%b%9!QI@rN1) z{UP75Kll*}Ut{oA=+CI7L%2_Fc$XfL@!oh)9?X)0-I=22@5c=3g#_>2M#|m_e z{7lZE?f|+&zG;8(8b;iNPDA0+X*>ha7=OGl{GXEJIyy#{%Hf6~-}@&CI`tLqDaiqh zdkgogKh!aXUEv@i=!&f<_rtR31iGodb1SFj72{*Gu%`5aS$!<}WWM&^?)3uCoM zDe7F3bYi;^njd#2xrfgm12q}oL8ig=`$x0EKZysYeWiv7d0ql(ed0$rXztik-Vd9YaHNiMJ2EC|8Ki z`Ht^Mj#PAv{9H`Zj=PdzZCvmrNf6&=XlIh*5PpqN@zVzj75^YP&Y|P>N=)$K&&6R5 zV=PXRTvC;i@7E~J80eBlCGCQ47|Jf8ZJ^01UXzJ3xV6cleB9bj4DQ<@Z6%+$eJWqW z6FTNZ(vAV&u#61&{>9Sz!#XTtk0xMmPWH3!qPHXZDigSY?7n76;4a$~;Yv3XxG^D4 z_y?Fh?4`at7ZG6*FG>;TrHDEf5y1$IZe;BmxSNxAXd?y%eN!Rd6e@IMT1&0hk$C$e zI|JFtLg1P|hFZyECk8)E*Da)*_WbEr@HP@R0hTDZco%S=C{^!#sckLYFb8^^@M z*x}HQ~y~d4zbsxgmJX+pr<{z+3MPPB-|&r4tBmu30{VBT>gbya$(a z1G1ai?b`MH&gY50zP`@xv^gytqBzJVgRN@m0OeeUjU~at;7=J4yba&;VK;r mRyk&q--35L_6&o0y+E&k+2_{iR!Z0^*y3~3r{S1y>3;$5Zx!GG delta 3091 zcmZ`*4NP0t6@K>_115H2$2QL<7#qwM$N(EKm@wQvhtfEcCx}|QMoWXyv}Va#iKr!2 zwjh$Gba)OM%~`Z%(pI`^>VDca3DN{8%|M#sZfmzBW0X``=X8zcD5N6UXhNX!zWbgH zPP0Af-Sf_O&iU?n_n!Nch_SI48@8F|*UJKb)K(ChUaEXeS5cr~Ld8p$Ji6doRSA-b zd4jV!s+N(0QPmklE?!r)s=ETR@{y7AqKX^oFq2G8X|JZVR}=k`{lzq0rus~m$;!tx zMa8bt|Hqg}GbTu<>9Xv4Z2t@uk9}>bw`AgB;+XimaK~06-4ysIYNKZJ#i~`4s z=q=47?0LGPkyxC!BN*T%k0n{!7fk$aT(fyfF8<1b>z@VRIJk*hO(CTzTTtR4UrGe57wV)$0rm8BSp>OgP{h8fsWr!$rWN7lh;mYO$2EcG_i; z3~#D<5+WI+=PmA*I9QI{Q5oEvp;Tqqt$HT7XDfU{vCi30tSu3Wo&)hG9Da(fSlZbf z)mk^PeYDeB)VvpPG@k5QPNiZ4JO7bNP4M-Je738Ghhex@tKrb`2+XmzfTtadWrXiYgEIvC4^6lbl2((Ud1+mz%zjE?dl!X@GAHH9+qJ!HZYH_ki^@tgre~= zq$DJXUMVc3oaGeso;d;%g{e3Lv zl|K@>U2+^B=Hs$5Jc(?VcgbaQtv#0wy$r}syKNFXOa1tGVy_uW&*L8<*%x& zYPIAme{h_e)U4F9O;USt6`Q7m#hdyMEMOt^Eerj8Exv%@iLa}*Kc>`s;IHT{`2#pT z8E?b!5O4d4*WvFv&?KMWaJ22i&=6l>Q&<)gd=Cyq|BS?q%5NRuwAGw;54Q|8bgQ)A z<+Oo?R105BXHfZbrd60ZC-bYw0+>A6J@mPEwBe@0&^>0;DV&~w@~$0)BXOpllS zLKnV~O1%!wGo*8Gto#5;RN>S#p!UL$omdRtfP4q?C}ay()-+_8cDUQMKblLWdgu+e zTblq&g#PCCJFa6KgtoQD7sXaXuI59HJ}+M=2K0NpzoN==r#OC_zEoZ$UcEz4mY1<6 zik5F>5xP(=X&*udXpwq|X&T%KR~sy~b&><;#l3Pg4Gj(YBg)Hb^IGoGeVGwPtkvD6%T` z#Ob%9i;Ug`Xm5HY#cI{)gh6;oYz(axd#8=I*KVyHHpvQGcB2v237K2gy|_{E(I09( z_RM|fUaMJ<$y6sX7X|CA8mr)il#mhEB%y-#)jenTriUaG$&UgN{Y8k?OKgPf^&Y!7 zAZN^qd^+uOp1R@Vq66?5E0YzQL1{71kW4TMZ_`x02aE3}S}&FQBzxw@mUa{jr~*N- z;AXTP*3bS)J*-UN*&g;u%t$AE@39%$*B~(;MH`+&@2v6r;*||_tZ|ok+D5k;9~MU( z)a>66(<#3s&abCG`fFGvE&96v?P&6t;ucxyT&Xa8-K1{6L?@dj$FpUnIA(W6M_pQBJ{NKkK2XpvRP%{$Z19!!&I1tX#3@*Q;nN1-E!~nfmq7fh}9vMVbPZ z8NO*++~U{CZdnPCX>+Szm$^t|!k}d))l1{hGLzCoi>>~Zg0H}pi9fRxd?H6cDt|9)wL@DX3$i3ti||VZ=irJQTp}?sx9B6O(RN zx##iwe&6qY{?2#qJvkoXLlNHLkStc2iA!r4YdkpPx8}wS6~p9`*W5EnoAi*xy#Z#_ zW@EiYn{#w&xE*EM+)*Q|gJeIdOW@SP?UFCS@+DY4`W-(f#oZbw?v~X-oWi<>;{T@@ zODM+3tZ&HK`PSsRqG zUD4b5C!!_U(8%9V=X=!ll!|s49Q3KdVY~w$7xn0@DlyLYD_m!Q+ggXr@N%f5Ee)(~ zdeUnt)08>YCCk8>n(8U)NNcJW%IY8;EvGD#o#vY|vqCATo@#(@0lFpyHPTj~hk-Vw zpy~7`(2s%cN{$mi{H(x#M$hMz%>Mu?t)rU4(?X$GQ>fFJQNgSPClsk4 z2t|TJq3{_9Uli~<>dRTq2T8Kc9b?W1^XV#=V6{d$ zbS`K*v8{lf^gEsUgfAWuci8A&uC40#567JMC7iRr=KNx+bF=2W%5JOr;kfghgmVud zJlQuMu`AWttvcsj_l(=4*ym%vXr$BOC^*z1vND#OGpU5roetNeqp8S&PKT4~9CrR5 zH8^a~wre?Ujhc{;Wg0P7D*|nczEbt%+RuX-t7?2OaaD^o!;Mizxn4srJG_}6V2GLk z`|)V+dk(iwckMo1$Sd93h4=he`1kMQIqhwu+NzRfiba9q;r>Y5;NW=S?S>U{B``i| zXw(cDFkJhETBL2aG{O3W;7ghye$C*f6vaVCSZ44Aa2v|VtB2B*y8Eo9E0xgZxZ*xGDw5w`YRIG^08ZKa^PeQH|pQH+&? zw6Q-pq+|WTe~YsIXa$gnx+Y z5o!9~xW_T!@q*@YO7mDFJi6fl?@eO7ly2o0?p+3_aBwsd9EHLml(jb6590N+;vFd7 zT%pz*uJ9i0_8r5aaD6NkF>Z7-b^`kBB-Gi5VuTfrofG;IWA*>G_NZ3jzie22d3+M4 zNI`Z*;%yuF?$Y*}M}>?9zOy)dF;Krad@ry%5RTV}+RN?&UbS?_V?<(#eRP}76*THD z-{~zcY~b&^M!0j^&KEsDcxlU)4VyNw(CXDIyyc#9SCy|agNBP&AVjKhzhf@FsVGMg z=@Gi^o;G6!mT?w7^lMPsOVM{>12mz}K@wg=zYqOq=zmFplI6y2Hx#9r4waM`&q8Gz zoi6bgEI`e$;3Ug_U2RsHezqYq-Nf<%{So&)l1hsT4cHPPXpFHibm0~U4BrF#cBz{; z)ArIjXE%btqKsYQ`@RpPuHN&d(@fHE;?Q+J(MPGg%qtzi=SEykwZ&12wwD$0>2$En z%bTdLtVpNh^ktbxawWcoVy(nAor*n0Qng7|XW~>Kt^r!?u}FE6eN3yChlFOl|Zmng_mSZLiqrT#-mi(ph}B zba+}b@k%?7lC#q5oSry2COKOZoMBoIj)QiCGvt<4bC%jN_Az?SBsNTam0ljF+h~!y zD!Vgz4owhQ7S;--gC$rA>%`wt2`gtJ+LkIiR{Zs$Tt(>9f^K(;A~T9!yv-A!}_gtAbD%~W(VB2*z;+5}R0-+j+^ zOxdpV?z!hX=Y03Rd(M6L#iM*U$_MP`nH4eh6H74AOE&qv9qy$R%@A%Bv~m)kMGLADO4hRiCMHSs6@G zMAKRJ{}|&b#yIJ8+mH$ovx@iQt>9oc|UY(bJNL@M) zO~NY-FGH@CzoJmRrcliQcjwyqk7<4GAjNZ!(C$1N9msRj8+oPX2{4Im+grR-&zOeA z=|Wy}omf=5xn)@y>d+UbK}h)lS<&*)b9y3QqV4$xV@DRMrGB7CfQGYB9lZJ6`)f< z&u5`FG8RZ=C@>h~S*Sz-pc@MeLxxq8x?`sD`~nYSv&mJGCH2XMNEh}uMQkjKfTjG|CPct$U@UQgHd@PgJ3VQY zjBl%W0wNKm7pxTx7|K+J9ja$scs9c)6x}u%inhi>k@rFTxqzRdtJZct zO?9?4d^c^k6>r!DI1)>AE+&)FzU}`=CP&5j#Co=>h6iD|UZ)k%@i5HM*2Pd{0ulXm z%2u(uMD^0#6RuSa*Y6ET)|KA89?AWfbO2^oND-m@O>G_Fcj^Z!Bkkp2e5=9 zv0*HUC5T=xDx&TpQ`vrahWf_#HY|Cr!F(CdHhA9W^9rv+V;nrQDo>&Z(A{xYvS;}0 z4wcz$WRq;Zi?=huzf1+Y?g@T5J9t11eip%dmVzHm1&;&5%-*FH%h|#8O7O}XwM+Im z4s+&>G{P=9j}M4_$!yO*vt2$Ux81$`TsHI?AP4QROZ+VL;>G@DuQe1eC`m*j!V5!X zj&hBr?F(vMS=l>}?`>wj$G^Zl{eAOl8g8hjL7qWvXndiTxYAoVP=UU3$WAb9jUYV8jz^&Ys4*%Cj4 z(|2R7xE^Ay*F+uusRLc&2?0l1KMD1V12&FhF)F^np~zpcaFg;{`vh&Hpxr4fSf5IJ zOwb1Ak{iWgI*Te0?|K$|ePc?9R)p+QLp*B8n<8WxTyT&_#rSRNa+dN_bii4}uhY++ zF8^iRb|VO4qv9evD@Mp>qFw|=b#MM}t96cUI^B&g3UB4h7ksR(Kk%%JvEZXyA``)F zTOxD8M}m>XZK3{}rvN|PR{dq@&~$#nGfNMYhBblz48303$*H@b`;2>*ld=386fXab zzU5{zc@mtzCv(N>>Ip1jEpAO6YOf9QAsmM9LB0oh1k#6-bqTVCx+>ar1JlW5H~pca zLN^JPFkPweJ8xhgSnG1rOPXe5uJ#kHAupem0D2G48&p^6Dm^Xo4UUW#hHgCKw!Sh? zKd3C{UOHO2+3`&*0$Z4AB5g0isblC?;a= z*0?|#sqyd*8mVzCX+V~+FM>pvD&nHb{Jj~A4YG(=haSI>o(U7m}P}6yVJ5lmi`gD z8#gf@{khKLm@1dE4a!){EG$IkdWpL!SZ~wXm={vQii9SyD%xHDyu+K?l61JZEi{-f zOuRwjgXC!NIJ^NlZC2#dDWCJy1s^xAs6x~Aar81x7 zNdMHO9GMZhV$6!4r>(Gl^-UUJH782zD=9?$21Nsy?s-(u*t6vRme&}h}Jjz_33|YBn(*pft{23!65`6d z&c1u^`Tfp0@4j=-{n*n%J{;ujHnS;NVxp)uV|5)%{$Qw^qhJs&xeVQNRiT^A+~p0$ zsZz9MCROHW;_=w>RoPZ1DV=CLp^4yhkXy~}h?YB|<)%OK^X9%BRi`gUQaXJU(9~xC zKab&v$1oYRwJBAHSMNCQ?|foW$2Rw`fA`c|f9kmK7X3<_XHSEx=-?Q0ux4&z0-H}~ zwVQZ=u4t|NGf|TiSI2*&$W2P!r=Z8;Z1j1YO?MkM4(iq^G$ zz?g=8OWg_Ol&DW!=#V7fjOp;qS9)qyx<*nu38*<4^;TM?Pc-^tP%V`KZ3OzG7*t0) zfgS}~AA=^)8$dq=x-SMb(BFVg0(~V0O{6KH%M6Le*J98l$~RbP3(&3@)J#tTeHG~G z7&MvMfc61B7lT^pEYRyf2V+nx-2j?CC(#&=LG3-+bKcf@0rDt=Djzoe&Aa#y_vFD(Cx;VBj={#KJ9fFg2B`Qcc;7(Db*4_7u%%eiEy>3Yy<5 zb_lJO5Qm>ml@0F%^srr1tlifSh}$f5H`P-7=lj#f6%pg4?-)B{jhj{DO;$_sGc(5H zSgrVia5o^l**!DjVUaR{doJbrn1w#UDy#2FCRRv^KL zzgC7h3|j>0W9+EYU+{al78;<`QK_ro2o23&#t)Jqed+2{xWUq92ePoV@4>ito4S;I z%JM1m0ty#EY1@ErSi=T&2qKo^GaR9(W8!0pCQ>Hvtbvkk)GN z5EQSS6MLZ8x%@5H9f2mS_C2HiKuy>m)NRXQ>sJpHAiS=z|4>B3^{%~F3qPJ#U;I6mY8gfylMTCDU3uP z{@@m!Q}zTH!hS<6p3PI3FLy+3vSt^fzUB7d7R2Hm}AcFyCC$Ax*h4URx5En4o9rfIh@ig1EXc*)#kit>A5duHvb{ zV)4WKG>@(WkGOj5BIANw9-@K;mG&@3huNAg;^2P?I>S933%2XcqmkR#c%+3UVA@sW62?nmCeNC$;Tn3AdbuWO5I~`7O5B zK1I!$nVqEmA{XzYTc{DcVyiuRL5(OfBj$>+6imTJu(Q9T2rOq}vN0r1R^o8V^PNhl-FrZMsMlqVrou6^%I%^{K%))K`&ySFn$gE;>Z}EQtH>?~Z delta 3151 zcmZ`*0c;c38Gi2^Cw8#GhwYpl;@FO}Hen=o5+@EUZqKAHM)I04$|fY*B+@ztEmBZP zyL3beg>+cPUEnWTGX>S%v~?5R3Rs##)UrgY>TQAz5K3WUn?dbrMnHj)mO!f8|L$z( zDBF|n{qO(2|Nq~+_y6zSW#V)^PDgC~>~fK?ru2lg9;|&wUsEb$q~_oyuRgR?Q9{5| zZzx%$Xn9FYicV1!{Ou|NFaIu(QXy0g%1#YAJJYF zS^_r^ok4U+h3dhf7ob9KFpj8D1AG(FD56Ofx(o&o-Hqrm70SbJ5PcWXNfl~_zax4X z(X%Sl3dT|a45bERMuiFxM6|8ckUCv`QG3W#r7QIka$EY^lGIAmcDf2jzrYe&=6r&X z|17J#hx(DP=!f%qD#`mPSj@|}S(o;zX6X{wMlJz`%!yGpctilcLGjEE-KFz)& zNzzB!=i!ohP3`EHk`xOs>>XH;`kax3u^-REgad6OiRQT_Oav_kLbB(e&ElpV@T^5J zzNg?>6xleuYVowCG0NV%N`&i1jNn!xY*j2X%(5MABJoWZBk^!168i`Pf6m|+;EJV# z&On28CEW>ItmSLABOFU-yA~uVKD_0hk~G22C$49MLOhAYwFV7?4tFCR4=+Sw)98_a zV^+_j6^a%2kh?}9uH8rX3mn|DIzyl0X8;}FN9e(+PAkOEneFR%3?uR3S)2+N@keAL zvGh1DiDUuZE-QoHGLw5ZT1JK^`Bi+mCf zbK%`N#tV+aBWzy^+w)7c$r*6jTuTqAp|=pS!&aL>Pr)F**k`tSL;1X%L`+2Ye9CRF z;<)G+5MEI|IF8@j!hD;*z*-~Ka#6z_@)wYM=s!bq%fc#{kEzicHoB!BQ`%2u|**&khs1YD>CyBd6^mX#Vos( zs7kfy_Rrx#8dxBM>?}sndEz;x_Q&OV502t&**DPW zd+9J<59#nHtPX$QiCy*?2FJozBMElErtnxyuy1fA_7_~ZNq((<7IqF}Ol)IJqPa&2 z`z;nWI48BS!*mL(fW7M}j5joip%rNWeJ+#L4Jje--8}UB|Qd1jxu@; ze&TQjF5zu=5}n8dyU0$l5oR;n$eiNZqyL+=%)t$Zt9c)@mcM+V??e;97oCKJzP&y+ z9on=$HWzw26kFI7Nz}c7@WyEEmyx|Qx~%s$JYLz&1@ENZuI!@FTiScVb%Mef_fz1i z`jvj)4M}bTQiKc7e$%C!|;8SMR=kPpxlM>0?K{h_H<~^&PY-( z^m#m5+f7O8h9jQ9=Igi*B)ru08rNw;}{PU?eLotJjP$vP)@pTOVh>iL@7oy0Q4nhEUnPTr;yWsTj!tc}C^ z`VP7uM(dq43ho9oPW?1(1-Ca1zvEnB@?|jWEuSE>R*jzQM=ODjV{gUpt_?OctZNwI zMLC+f(~xB(|A+PvygR!_IGnE=Xp=ybU~lr;eL*o#%W_A~<}CD}jSKqGW~fS(IlS29b{cz1crpT0 zO3}tXmykLh5V+ap@aI51t%dnO7ebp`y?ojt%9G30 ziKAQ46A<87Yb0e_Z7xa$g4-xeaz&}+W8D-JN<}Zk%gIZ-!(aInsI{ypVe6M@} diff --git a/integrated-security/web-overflow/_11/integration-web-overflow.c b/integrated-security/web-overflow/_11/integration-web-overflow.c index 932de8fd..f267d636 100644 --- a/integrated-security/web-overflow/_11/integration-web-overflow.c +++ b/integrated-security/web-overflow/_11/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_12/integration-web-overflow b/integrated-security/web-overflow/_12/integration-web-overflow index e57eab29ec549a514409abd624e29cffce7023ab..f91c71995dabb6568c1186d430627ad3091ca6ae 100755 GIT binary patch delta 3370 zcmZ`+4Nz3q6~1?WU{^tQU6$QNgk{0_Q`zNbafuauD{fd*GHTSePEElyQA)JYCRT0h zh(oa1*)Sq!oQYF2qf^_`smX-UPSnw4No}wh8%=60I%|q;Gg(J8h)Pkhuit%d7oMcO z!`^f6cfNDpdFP&c-{n}8_eXiV(`vCvOfZFUT+!yRO zsI!!07In@c((rSZsB>qvqzqDWM3=;AH+NV|ldRGttCW7j&spOhl@s?!${JhEVp;ZtbXo??(SU1vI>?kb~`KoKIS(j%s-znze0(r`S#{~iG_Q6EQ;toI9+10 z{T-TSi`t$6pKZ0R4o5yu{8*Od4~^fTY{+xQcw0W9w)1P4qrzL?78!w1RUv2EE|>OXzSX)%kl}awGm;N zs+b4GwO8~4+TQ?mG&CBHT!h6HYPT279L1@C$wkrvKlbiJ9Zu);{p}(vW63$HC7kMTx~Ft#k-Z&G7u7l) z{4J_?+MjMybJ`L!As-bgF;OD|ZH>L`e{}8LP-9h%_a?4tx~do$k>%^v^pew;@h*m_ z39uiIbid{F=ycbH>C@ceU3+lykA*)xjOVnqj;O1;LscbWK=JTEv^5?dFT8qa;jReE zM-@+~ib+sh`IJkUA zN%(uH9`RD&8MkN`7B8q4Csm6oVbKW-Sl5bi9o@{!-}MxXBB7CJXapYiqpa1@9uTje z5vQU!%fc-K?#NE;_N{~A$m&EmYFzJO>^S_h6Y$R76C>m&aZdP;8ms=dwoB0p`=t%@%atUv+$}_%Y9|uGPl39ViH{}Tt>4zookld zkmaKY^Yl$wz5wYTl;u|-pM!iIGWV7&4?s>HlI0BC2$o`%=R$5r<<~*Rus<3h{m9X4 zkVhadK>m(q7tQ3Iw4%u7I{l?ABehB^MvoU`?E|vhOgoE;TnR+585XIQhk=OTF*;sU z;Q2S=SZKgBG{v$MoYG?&ujE=F5Q3ivGASK{N1)KgNR({cJo ziP!2*eon>GiZ+W1y#>}PlcdbVwL-K$TH#%W7eDMR;7!!y-9S=#HpO%Xl6-IL+pQ9A zLo>)y+7IWqN*&-7mf7`Y)(Pq0eadVytD+TUwPlB_lHya_=~)&_T|XbiE$j&Wsm$k! zdnBzw8S9yig~?j(;7$sb+x2!tA1uf1tvpBXzzuCn`8L<`WLi?j;xnhi)0&A_ICzX) z6+YLj7T&as}lE^ZZ zGRVdftblgndsINnnTU3`-@%*dfd6lNn6^|p_z{X!ZsYC5=k3+4%A<~X-_^}<(a^jn zbe4RYANUbR(gO~i#YP_my!;^D3)F+XrpjmiB3n`(u9O%?w`g6!L2p-u`D5KztL7M{ zDmPF`s;yhPxTe0`TkfswHdnvEySFcF;Ha}pi+ocX(^MagIM75xx#UV-Yg4+UOq-IG zQAKMcpSd%McG5m6VD3xK`sfoWFjh)cCdCj-Ados_Hh=C7`K7u-H_T z$hFvKPF3^~TCup6U#0`VQpt?dCyN8-aFL`Kpd@Mn=G1>1NIPb!CB_b@3DB!G7V4`h k9V>n}ZjYk%lWU30&yy<@Fk2p1vH7$n6yQ(NzR=A70wO#)eEx#v6IIrqGK&%Jjy66V8U-e)t;W=c#vYRg#lYem1+6{af~D}3#uM;BPGDgiQb zPvA_Fs>LNUs5*y8!RsnfbyuyVbmDSWqv8hI&#lJl7^^zQs;1xZzZ=K%RL*#wq;$q9 zq-k~kzlf1o#0crMt>!j=&&N;xV0i0~$gumS_sprm51(PQS6gVeBUC&&q{sGg0~1&_ zy{~qo_GAxD zgVhF>KE=#mS33yIlfOaIH zsdOFa4A6ZEsE!;uE9L0)8GQ+;o*o0*2y`F;T|r$y_W~VEK#lZApzi=3O+ZcbFQAuz zo=ZS2l#y;FeY!p)l7L#N7HCbnerTp(I{C06FD>1}*lqctWkahCJ9sgAzd;GDaBg7i z^A)*wp}+ABy+5uG4H$i#%%)6>Ay;C-iLn8P5EDfZvgJH|+Y~l+6=OnonKlPQpG9Ai zW%+dS_vxZ(ZPAghWjR#8aG+~J-sKGTW*o&{7;%6b?5&(zCPb}S&scPlYRvA3n!rAA zM`eCbFkLG1U6mPyh=%E9bAHW40@EazZk4%BWkv+E4xC_k^K>v=9|?v|W2i3${2X02 zH}M%Nv#jQw)MCkAy901&BHFqj%i*4uf6MZS*s;iPlWKSrhO1>-0rj`R9IjsohNj@r zOM{mDhjUbx<^gxDYPfn2?iVz4*WwI(hJyi)Cji|))LGT=Yr*{~HfAu~GmD{+#2HwE zp^0In#G*t;v$Cio%i!J%X0T^;SH%+3fbkZYjbMJu=M}62qa1Oj)i}{EK==FoEpdb! z_sDItki}~8oxi*2{F9io^8x3biOzkh^9yj^x#V0Ea~=bPk-bY9uS#?-SDaT~D_ydm z#`a$PB8{+H9sPY`UKXe4Y$D|&a@kzVk0nBH06Uy5~2 zH2g|6JP*UwA1hVWb3+YCv4H1cLO>tpsrSgH5gQy4A! zbC8~ysKQ(ePoB~;!#~lxGVz&8~H8Kf0x=FxqOiJIkNaw z`h~;kzli(qIGossxY|yN9#%72E}X*2fB4^4^Bi4wxGG-}Y~?HrJlWV=`+}3Pz;`!> zrUIKchUNlK1VRg&gS{os0e-x(=f;g0{&E;C{1CwMivJrne2jf)K42*Td-S{18Bt78YjvhrcH798$2 z+Emt1)@PKIXo-!MtzhvVhWFzJ=A#eFJofQCDbb+xwamo4WGuIG7X`{KS_`xQv}#4O zvO?-C-);BCrX=nz?kWw&Ya?D^a=!owhe2O|N zt=vbU%H0^9SN%+Lc_kgLdP;N5Mz^aT)eJajt^Y-s-t${EvzhdvzmylzyuTIDmTHf2 z!YnC+E9HsaEo%2$X|OstWLRTL8uHg}=QOHG8X8#F#<8GW@)(;_RF`HPKH|AYW9yvw zt!Xeerb-IZ7^{OS+An!@2V>|#IxhKj!!d1`<|Y4P;n>m?N0d__(9Jt&EZ{N5m%q=b z+OQ1kJ&XSeW;0c^jsojFx_JHiXwUiv{#P0U7N5RxnqTkNdGjU3!AooE{JQvWe=HcZ y_@a90IJEepRMUK&f3e^Tl>>pXX$owRQK*4>zwS=8n!_sE4=uM=)v_ocIsXglbKCv^ diff --git a/integrated-security/web-overflow/_12/integration-web-overflow.c b/integrated-security/web-overflow/_12/integration-web-overflow.c index 10854a95..342b6885 100644 --- a/integrated-security/web-overflow/_12/integration-web-overflow.c +++ b/integrated-security/web-overflow/_12/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_13/integration-web-overflow b/integrated-security/web-overflow/_13/integration-web-overflow index 0bebf4005ac40a44028893e99dbdea70d523f237..c63b590c22a7ca899d9c942be61ec4170aafd4a9 100755 GIT binary patch delta 3424 zcmZ`+3s6+o89rwpz>-CFg=KenF08~yWp{b#5-WOF+_ENQe78C^0ZpUCV52cs)5ZXU zB(57q^dD!;#B@xCPU+NSBuwjLG+Fuxwqs(FT8kO9m?m`{(E>gO6?^-gdv{?q>6yLf zKj-_u|3Cjd_dkz48shyS-exnK(j+E|S~FI=XX>vFwaE&G&Uv??bAsCGBr|vWI&^9; zCYed?bBF{ywj#A}tB{mNOpa)xI5lyr*%M`XqAU;nhMzIF7pR=}0!eAKQ&3Zr|NlHj zq8=k;(AK1{xp+-}YsW5=b@Qw9f(^SSKJ)#YBlL=PiaisqV!<)yV2#|w1eQf7wM%)B zE@`d&Q&E$otL1Mg{q0J9LO~DeZ1kDVroRCj2X$)F$fNi0v$R_8=I<%IZA$%)!fw;s zXb?{ao}>gDnRGgul<;=K=9gZ?kHQJ9v?MWuY7=!-mzYV7i4OAxI2Mz*CG$B0V;Xju zIuk3&m}D$;ND^?y^mwwAmRgn1m6S#zYECIhR+^n;ObNuHTB-nA4|GKws;3P=4*;!; zLlfz3pr?Uui$e|c3D8lXJL6Cz-3L0|U`*K`ho(}I!Ah%ucEq7(dJ5 z-yad8;wD6-o3hjM3+IB}JfbqQ1k<51cdN`(g82(tlkS{-B#!yF6fpBuW|hhe3uY-e zfza~aK*--82!4#A&Ix!Gb*C@nePp&w zAyq+wdkHHz5Na93Pza&}nn1AUC_-Y9W@^gFphX#`{CY40E#WPt zsmf;M?^BJL;pVU__R$R?udf z+js;`f`oSIXo z{)AZ;y+0*7^zzr5VYskZ5zXapsYt^OX zSC&sj5uivhNNaoi{TkNe|5~K=M~hHJ?%t$L*;#AegSI97vT(3VI9RVbxGok&YsF=R z8~O64GT|R0^~6j4c-&%zuy|gzIH6jIVopLso)WvF*vkUV1CHQ!toAK~f#C8;Af#Vgz}PYPXUE~4eJENYwa*CuA$|FGYdaOK zuzzw;**rcCQYa_2WWKup`hHa1T5&IzG2agt1kd@FF9_c9E%OCOmj_ylZUSCfJ@q~! zNs4?lL}zkpH5YDl73bFQ4;;Vb_KjPA>U!pd`ub~V0ukcnUbKLp))2XF~Ry19`V`S$fa@pqgtW20s0!x zD!Sy%;ydZS)5&`&e^Qm5A^uo2ASic=9TAxT^S| zSyFt)S6Y_JVmH!B^g>Pu63JA zw%Qj(Cnn}soQ)cc*GRn7%EM$Yb=#*z@2fG+hA3x{R)b@sm%-UtASr5`)=D{znlm%o zPu-;=z9H0@y)vskcKeMIS&EV^BF4qgwiie-g(6F#77 zgLqM&+Z;=VgJxB?kLTRVZ=XsN3$zgKR z#LAh5*nbqvd!^S9`^H!Vm0sFeX`VyaSa>INz`RhTe2T*Q?fM;(gdi@K$^-nwOblxjC9%NRE_2+BqJ=e5UAe1`<@Li zO?Rbt&pqGy&bjB^d+xh07G)z*HfT4^u9pPf)Lsy(UMc>Cz9>_{grZlj`1GN*suCg- z^MwXeR4pk5qpCBAG(7GSRd?4)${;CcMHM&F5oR-0C0JDnRu%n<{l(N@pmO>PBxTS~ z5wX?t|02c`5o4s+wOYn6eY4unc3hxCLVW)wJ< zL+|JwXD`w^B@poq>~^-V)8^PxZ6+sXf(4 z(_poMWk|EIA1k5WP(sZDcckA!O?%de|H_cWuUk9x%6rBiG~K zm1X(e)Nj!hb9M2l&ty5$u-x0VEFW-%2eLYF7RH?5h6gI<*Kkp5F$hBZ1FErj9%=%+ zcR^)(In%8&-&C1#h{DsxK9Yy|U50Y7K;jx)r0UA4x$0Nw8w(fZw9 zB9GllR+}|&>E4QSbHds6fOEChc~EtJ4$jZ7I*SSC2|$?Hznbw3j_=C5ZBd+aZ{DHQs>|27%NkH{koWQNo7C>iXXmKLnays{ zt4>$&3huvAI0<9?YP-Nk*vKIhP=Wp4<_c z3bpKr%!i%`MV4E_10~M@e!Q{xvvBWBM%*_?kLI_DwReY4=eIKI%%r-@Pv z&g?pIOP0?fX3BqL`7-2Fv$D)*IRW`2$S>cKWqv0nW@NdO_ISOHqT90E29IRR!+>Y- zB%SiQ3N~W?n^;?+VXg5cu|6wJ_mR$!o*{77@A1str4PONjM1Vumz9vU(93#gYvFe1 zFOgt!Qt*_k_$a0s0&X5YU3f49Yf)&rXqLEDm`cbYDlYMv0=PqXOWxLQ>L_tBKSfG> zteHkjT;h^IAC{DwiW1iu-%8$$=}}x@e7={5!zAO#E#LaQWt9^Pnj80Kf$WV z|x8ehBr=4Zn%LYx75>4Cbgmpsl=k9*oC-6<*+h=XL}@IV@5g^_#2y|{S`JAph(3*%+4x*C|=8@PHgV2rWv%l~S^2D2^zwP^g=A(nQE-N*2VRNwr}c>U=Bz`m^g*w4OqBK7F#H19Yfv zJA0WXfF+l&pBC$anaP4!D4^>4N`3N|9y?Ya)F*eV*GDp4)dJe5|YQB{b5I{Rr@)fK2Z8c^s$x2n$gQ3xRlknHWe_w2+; zx2O32eCIpgJ@4Lg@4Gn_ro&;{$+3C^PsB$q2?-uq`g?6KUBa+)#i8w4Aa{Czr4HYu zQtl;dqL=#=t2F#^WpbaZ;-yBio@5d@v{4gVo?w+HSmp2sdVw9c%A9d4FEz#?#55HB zKgD=LF%DWqL)Ncf<$PbXs%`srhjPDq!x;WS=Wn}VpJItQ2c?q15n>^&R8K@K7tSg+ z(hyu%nCPcs3A{2$e7qLNeHMIQ_FFa{`BmDA5*tI9#&k$8Kg@-2zo zsp4Q1e^LBt(m2p7l~A1aX4;D{{S5ygmKK30)!7hKE1^-H1FdQcdkuxfNo>h^PD=%}dv1#8XgnZ&CW&sxG}%!#D^T6Ba3YOY}`t*O-md zF*efnA3^Bsjj?X(M%%qoLNW^3wRP3=+{ftz_EOu z2*&py*AO;5jeOE#s1Jm`j{iasgpX9;h0}%=OGDFw5b{s8@1GJ{3ImZ0antnWBR3GK z{QDzfRW*)PydUziis))sm1W8}EaT@z{Fm@dmTlz+sM0QUADex2QmX4v6hNiCWGP5Fjpe;QMW~8 zwZ|yxd@Sq4cOo>`@BP#fzI+IjGs3-Wqx+8!W}NpWoHM`Wye-waRd(KJGP-{<>ugUr z_aKBLm(NDbr8-+B=bRh%S^Fv6=QD3K*2Qu8M?1w?nVFn(sf4p#oMl0GDss4sGeZq$ zqVGZjXM8du&uM#1gY)5+iScSN(2m$k?zwC4LNl(a>i+yyHOq#ZlY(%g3SQ(Kx(~34 zIf3ly$=-K4E5nRTz-Kwd2VTQ-ekS~h2^=TVF)6QVST@CDh~nU$aL3TlY~nSe73FMb zoNIVWHl(9rN{!$8a z7=3Y)sH`d{-|tXbWS~ioO5O!WVJNqhwt+UUWK}lG;MOJw3UO;Y(YbG%yp{aY_Nm&7 zCv@D2q-_KKVTKI&|0SmNhjm!QAB;nDUhXsRptU2mR}{F4?7k*h;I_CaB2^wy;Oe+E z;pZ@W#FzTvtVdMzcwY86BYV_|9#Ql_?*_453%BzM4y;3`kbg4lpG1YDnAURZ6(rs` zFP?$o$rWh7X$kGe-QF@92-U{}VbwM(A*WHF^r1RAC$?~f;}=Bzu*&d|WFhr=dzO602 zB?u=l(i1RZUA)wZ%UFsZ`XHuuE!I)o0F7AZ;UpZw`ViKiV|@&k+t#c0+!TaXh}dkZ zi>R^--nV)3S7FW&{{sChOm#+@qEe|-Ye*hKf5zW5Xp0LO-6WJ0=P=&;@OZJ69)#zL zYv@VnDK@F1II5xdQt_i2b~JILnn=_!aF#jPZv2*rk69}5o&?Qhg>(rVDRa<9=r1c| z7z$sN*;z~CQztHj_$+}Udm-!9@KR6w`ZV*VJmVt*o&M&D=(Qdq>_+Nu%?71apzv{E8Q+vYaWR(Re01)YHAN)zpdP~~pg33SX$?E&CC($P8o4 z9%u9gu)_0mij(d!F?s`h?6K2haNpB_?9E;W`%M-v4K8IEw(h`Ij|onC1N1w+*S#gm zh0^Vi=WA-$uBmQt*~VZ)jlItH&JmYmFSxU|Nj4cd6g0aK#dqfP!NfYXk>1#foZGYsa(1bPw7evekaT*g+wX1|9%0Z06c{|j<*6^j4> delta 3091 zcmZ`*eN0=|6~FfxgH7zjFSdC$!PwYrfef$#gPjbw&!KLd$qPg+TO*~#{IOK@h?x6`L^|`pFaY9sw%4$sdC9-dSo9p5Qde) zJF5HW({NEG&=hMyEQms;z(Sv3+7Yz{(qaL8rZUmD7@(fTAO{@hjNnmw=tt0{cEb#M zMbS%FXreF3R4>X@bBH?%E%YhaSU3#n!o#qq$PD|69PsO+a()__*s%4Mc54aYNE*%* zwbrwwa*sn4od8iuRLG&b|J$Yym zTt##i(S3QS7HnDp%CtKDP#&s-?;;vObT|)P1O15hAv%(W^6)02Zy-96hZ^DUh@MCE zbRKF3eX#(#Vx2ynhYAotw53>=T&kQ=A2B#J#co2bOW#J6bmgK=wFh0?cs#}IIe|p8~TP5P4lam2$*z)WX?c~se-n_LncB0 zwt{C+Wa99&$<>lVmIF5x1{Y(fP#AV8o@wUUiaz0Z$4odLN{3_bA@P?CegrO>+UP9Q zn>Wxsu+v<+X*a^LRHk!DlH!9q{~<}^Y<*%r+ZDsTXt-RjV$jhjn&Y9RaBLbQ5-?(R ztuIr&xI4mCisAAihEH*D%WMx`!fgNpPa<@CS05^dmznRgxD3Pb!8z;-lXxF3;aF-E zQz99Fmr6>Yr^Havho0fViQdK)Pbc=b>={ANZ+Sh;>%as>p3fDYOg}=m$9kNwM1rz>5MClMzix{$1} zIyo+K148R62j+0UUG8tk4eTc|cvG2%e=4So3(>)e$9?g^^XFG8@D+i zbb2@y!s8(o`i#}#AKJ0WJjmc!=+kh5EwD*k7UOIW4#)n4i5ukK+RJEb8ErSSB$~Pu z+MhDoz`WGL7Sk!L0`{+`kZ*884p~I|_--Y{t%SVHLRO&*F60yJ`)%m5mD3T}XDgwX z;dz_gcMeaxF$^N(>>xYEzHl}(4J;_Ge*J%2P4jTo=4g6`dCNOr@cWTO;4wQP!S8L2 zO$R%+#^!_f2V+Ye;Y95t2;Uc}{wjQ6R+DjGhr7$8T;M;+m&!XS^c44;aC}Zd?c4?r zIDe;&T$Q9Zkn<#HUF)kaU=lTWYU;7}A}Bj>G5iqahbRxDY{8W^g)#y=Ty5%K%t}%Z zyy;`Va6T zo3_JPt({vW@YmWpzAAgJuu*1@0jza)-l7p@jh&?I8HKHNZS)WvtFzMxRMZ=>>-#aQ z3U>;A&pE*0Nh9qwk04vkDlIvLUIHD(){J|n1-933sUPA+nJvFjku@ZD%eoym5HEaC z@3!XdJGWbnL}hz?>d6jCE|MJu9QGFl+9=Rrur|7_ zo`9G$%kt5z&uQpF9|!D3pHZhM+w^ja^Nf-bp1co}jc#0g*Rb_Kg;%iVZfsdcqQ@#A z#Dq7a?P&e_pERPC5|-_LuRslO%=-zQhCNLJ^+K%aN$j0A|BSo14vsWG#GSCf_2zrI zVH<4nJ%OgF#Ng(T|NOu{Nbcwqp=|A3v^SM z;0lt%cSR{qC>7m&d!Z82j%%Aei!gbY9WQPMK2jvgNF-Ya&9Gl|YY%17Log=#w4+&V z6c$9^a^YAsav+vdFgQSaU^3|DbJIV>D>j^l&FDS5Uf8>N3q1>y zh~eJ>f(l}wL4M$h}Ue}N;VmP?s)b%cr2ED*hr|+Cf z8YNnym&O#EB>b6+q_Mez7dwe|RuRXcotijToaKtMT<`~afg83-oM9U;c7`FOsL%g@ zim|w240Ou+^nsT@?)X#n+_zc_s!j~{G`(i6y>%a6Ru)<^Q7RD}Ay(2x^@L$ra8|j6 zhTyu=L_c9Q@Tvy-TXB3)tj~yOkID?6s?6%U=wpRmg#lb@7yS$x)lT}B$ZHkrlOnrI zZH7twMewIhGJ{^Ff`X(INiXjIDgHq;sS}>jWI%&P1x=bvXwz7^YbeYnu_g1zIzklW zOX$^9LW(wJnU&`eCq#|EEU_n5>m$=K0@Kk4Biey>6_>naK@Fi5!MnLAH@G9=BvD zL&L-`l?*!8fab7&E)cqm9@n7DXkR{uX8;bS9xitOw`912hKc1$xN6Mv{Y8RKe~o)u zG63UV$Nd@z2Pg4S7(@gufzU`lhD2f=(4LV2H5vN+-N+0Cqb(&1%u90ST4a9HV`Z$4 zC`Fy$NY>aMgdX<`%Kbin2-IwZ=?tUi!w2)u)p6&vuQ`{=o!cbmEheMqM+?qh;cmq@ zi1i|bPj)Rt9Fr{4yV*qN%o~mc`(e3#s@rVNIo8EyWqxvgEhn7qHd~kMmm^2I%@(LK zo9Nq6Z#F*DDa~m|REzUrl!&oP7HBZK-}Cs|E6|KFtM4yf)d{U=xH&5bH!9#ovoqyA z>|#zJ`_XLQ+h&_WF);&|G7Anh;WWquNBrXoGUERaOY0A6u!=pn2m7+Ko_!0g!RSj&;E%{2Y?cIWvrW-ipWUVVPzf>^gwSX>sQ0=?A$|7qf^K~8}`ql!ZA#1srL#J zZ=7RiAUnAN9XG9^gSgvUCIg|mSRkz4X(MC+^~oTrllNJVrS=7;A6A$DZ)>k;W&Tf3 ziigK1AqeNB6~|9o-}kCJD<0+&;`{E#&}CoU#?Z8{))$(q3v?FULwHN|iboiUHuk|C zxRBGJxOTVCom)@ewGL9t-UB~z{P2a{yPw0la!^Z6pfZ-BQ%V^qG`Bl&sD6Qg$MRb+62Y|JMD+n z1yyt$+6zqTQGBYQ?_|L?EjJmzQO(5LD7cH9+$sE)uwoHwyeGlFqC8p%M~j>&H&m3T zP*C_+k%P0wKXq&&SSf^jM;=$M<;4;Eu^%Y>YKw^6Ah5o}F#R2)4)%3-s+%H6~9qNco3k~EUI8a|He$tn2Q z?X(Qrc)3CBD~W-)fGajpGx&;)N+U+^E5@5uafZ@_x2Ju@2P`%5X-PPOUQ}Xc+rfXNwJ*Ani7um!%&Hn4#OR+aqc`OOX89l zCz4dm0z%Sp2{xm3@q3h@l@b*$))U zEHG8}ZG}D;)_8wLanijeh28*v^*ZQrxbLk;_SSMI_hmXSK3vQ&?A?JzuL<5M572M) zT`ym$S}NWSdA_Q8*kPO|NVD~Ki% zL2r;y0LuoaE|JlvVDpA5`XRi5SYk4V;o=6b&SmFC2TX}duP*VQ08TrO5=)FbpwbJ6 pEA=p1>6%Y|E8gr_83)Ug0{s*$ey>iyTEf=AR=<}%1xNkM{|mN>76AYN delta 3091 zcmZ`*eN0=|6~FfxgH250hi#rsz#o{kI0J0JU?+>)=TJ9}#0F85R@u^G{@BuFsYI00 zDjf(&Mu+Fn(VRwGCQXHoY?;=zw3aG@+7#5O&bD+*ql_h0wmDU+8HGe7Elo&>-p+l` zhL>i$(!1xL-#Nc?@4NThk92}gBJ6XBQ?#5UMn$J6^6_)lD7rHw%8i_y=M>xs{Z!zCS+8K$D+s@%f8)n06rZsQQErSu zoNIUezliB<#5CwN?dHo>r^l~EM|XNw6$gLw!uNi9^MlhobZe??HVl;;91f54Q6phk zDZHn7j2?u`8iA%*4PsslGI>_|9Mg_yt&kS;;4_VxzQF+P9Fm;y7H0yV)<-{r4y_k1 zpjQmN4EbjIOF7i5a;SO4o%vS!BUqn50_pt2u&=-ZeFaWPfavRpPN`56{1eej zh@MrU7APtdz))x?N~=%-LWpiGG$hYdUeF#fR_F@7gxrw6u`0RFxQA9_>o}&+8pk7q ze6hxU8}(m(O+T8`lOw#Jg4tATG1^5EO-+xKGm-M3kSyomTc(7mry3`;%d|Zj|2*@8 zBuO7?e+U;%8$8GEN>V(sbf{-Z>T*Pfiu!RcOqQc>bf|G*6%!$|fso9{u+i+It?-mt zD0)-DGbl0%IB0fnOktEmx0DE96k!CH5@DC(nP#5N=o3wBzYtAC($V;b82Bp&?}f|e zRyqfDmUVO=?6j0_*n@C9m1$p+q{P6^e@oIN+n+d|t%~7MG|bj%7<4p-=0s#E8lOSN z5R6;g50)uj+*Ua}N+=kJ_z&v(^gE)>`6>Fvkp?i79)x2wW zz-6_7MX>nK-Cic|&5|AWksnu+hZXXEBtN@Cwr9!H2w~5@l@aUI$DRL|lm2V$x-+ z;JB8X5LsKQ9_q-_RT%c|*l=q_8=dtd=KQqL0UWqWZOk|)2fme2SjOF3`ZCGWVWN^EfuxZ>Dlk5zR#{Y@~H_E?tfQ7w_F(!92%TQy7 z685_+Y-mB+$Trg{%mVhWr!d~YluY>xqwG;AUWKxsQC6V~Zsdck{U&sj+vzy;m6y<2 z_<6Y_a1n32lSm?y>>@kGTDY2-dPYiUfB(O&<^{M~?ri)q^OjG(@DnXVq5Td*!jEr> z&xE&ci7$k=h2u-xqeC@&5q_-2b2oZuPM7iCfQRidF7#z`)ZR{^v#|4R=Ol%{yS@We z6({uFS0(9nj5!AvD<1T$#`&nmTQh{Y*Mf2YH^b8?mrx!?xfgfVd6eDYakpwu&q-1z z^tjzx<26Z&!EtxMeg)@&L{=ML1v*lO&>!*pj8+QTLG0C(oUVLAhr_Jq&zeLe5i*mNBjBm=@_szbS;<|SPS{=JpgxG# zcxfA)tZ{I62z*jg%U5OZ6*kMP7{ONS;H^4Q*4RzT$^>kwZKZ>7tkywWz*T3$uD8)3 zxV$NNhjW6_m&UNyeS&PYX!K+dy#zXewFS>kD{QUXTsO>%ax`_NA!|tPm31#}B!2i) zo!2&2A*u~>TSH7ZQodfGP6*dqG#27RDd32hCXg!FSO2`tmz|Ovom~YS_7?-%AkY!8 zHF#~lkeD;e@|mp9S?E9?CmcYZ!3t5f;pHTkGgwo?lV8AegO`rMb*z2h@(Z@yi!JL& ziZBZZG2_cK^Z$d+z`jO-`XS!6bYTfRbR!y|*0J23r_10QZizNJ8vk(O*8G(o@U)emOTK{zP} z^b=Wa0v5%tx#b_`6&o(YChzhSd%jpfn<2c(tIy@H9}aBV zOkaa(#B$R&28){ldZSyE2}W4o9MI<;(zsx#H6cDt|9)wL@DX3$i3ti||VZ=irJQTp}?sx9B6O(RN zx##iwe&6qY{?2#qJvkoXLlNHLkStc2iA!r4YdkpPx8}wS6~p9`*W5EnoAi*xy#Z#_ zW@EiYn{#w&xE*EM+)*Q|gJeIdOW@SP?UFCS@+DY4`W-(f#oZbw?v~X-oWi<>;{T@@ zODM+3tZ&HK`PSsRqG zUD4b5C!!_U(8%9V=X=!ll!|s49Q3KdVY~w$7xn0@DlyLYD_m!Q+ggXr@N%f5Ee)(~ zdeUnt)08>YCCk8>n(8U)NNcJW%IY8;EvGD#o#vY|vqCATo@#(@0lFpyHPTj~hk-Vw zpy~7`(2s%cN{$mi{H(x#M$hMz%>Mu?t)rU4(?X$GQ>fFJQNgSPClsk4 z2t|TJq3{_9Uli~<>dRTq2T8Kc9b?W1^XV#=V6{d$ zbS`K*v8{lf^gEsUgfAWuci8A&uC40#567JMC7iRr=KNx+bF=2W%5JOr;kfghgmVud zJlQuMu`AWttvcsj_l(=4*ym%vXr$BOC^*z1vND#OGpU5roetNeqp8S&PKT4~9CrR5 zH8^a~wre?Ujhc{;Wg0P7D*|nczEbt%+RuX-t7?2OaaD^o!;Mizxn4srJG_}6V2GLk z`|)V+dk(iwckMo1$Sd93h4=he`1kMQIqhwu+NzRfiba9q;r>Y5;NW=S?S>U{B``i| zXw(cDFkJhETBL2aG{O3W;7ghye$C*f6vaVCSZ44Aa2v|VtB2B*y8Eo9E0xgZxZ*xGDw5w`YRIG^08ZKa^PeQH|pQH+&? zw6Q-pq+|WTe~YsIXa$gnx+Y z5o!9~xW_T!@q*@YO7mDFJi6fl?@eO7ly2o0?p+3_aBwsd9EHLml(jb6590N+;vFd7 zT%pz*uJ9i0_8r5aaD6NkF>Z7-b^`kBB-Gi5VuTfrofG;IWA*>G_NZ3jzie22d3+M4 zNI`Z*;%yuF?$Y*}M}>?9zOy)dF;Krad@ry%5RTV}+RN?&UbS?_V?<(#eRP}76*THD z-{~zcY~b&^M!0j^&KEsDcxlU)4VyNw(CXDIyyc#9SCy|agNBP&AVjKhzhf@FsVGMg z=@Gi^o;G6!mT?w7^lMPsOVM{>12mz}K@wg=zYqOq=zmFplI6y2Hx#9r4waM`&q8Gz zoi6bgEI`e$;3Ug_U2RsHezqYq-Nf<%{So&)l1hsT4cHPPXpFHibm0~U4BrF#cBz{; z)ArIjXE%btqKsYQ`@RpPuHN&d(@fHE;?Q+J(MPGg%qtzi=SEykwZ&12wwD$0>2$En z%bTdLtVpNh^ktbxawWcoVy(nAor*n0Qng7|XW~>Kt^r!?u}FE6eN3yChlFOl|Zmng_mSZLiqrT#-mi(ph}B zba+}b@k%?7lC#q5oSry2COKOZoMBoIj)QiCGvt<4bC%jN_Az?SBsNTam0ljF+h~!y zD!Vgz4owhQ7S;--gC$rA>%`wt2`gtJ+LkIiR{Zs$Tt(>9f^K(;A~T9!yv-A!}_gtAbD%~W(VB2*z;+5}R0-+j+^ zOxdpV?z!hX=Y03Rd(M6L#iM*U$_MP`nH4eh6H74AOE&qv9qy$R%@A%Bv~m)kMGLADO4hRiCMHSs6@G zMAKRJ{}|&b#yIJ8+mH$ovx@iQt>9oc|UY(bJNL@M) zO~NY-FGH@CzoJmRrcliQcjwyqk7<4GAjNZ!(C$1N9msRj8+oPX2{4Im+grR-&zOeA z=|Wy}omf=5xn)@y>d+UbK}h)lS<&*)b9y3QqV4$xV@DRMrGB7CfQGYB9lZJ6`)f< z&u5`FG8RZ=C@>h~S*Sz-pc@MeLxxq8x?`sD`~nYSv&mJGCH2XMNEh}uMQkjKfTjG|CPct$U@UQgHd@PgJ3VQY zjBl%W0wNKm7pxTx7|K+J9ja$scs9c)6x}u%inhi>k@rFTxqzRdtJZct zO?9?4d^c^k6>r!DI1)>AE+&)FzU}`=CP&5j#Co=>h6iD|UZ)k%@i5HM*2Pd{0ulXm z%2u(uMD^0#6RuSa*Y6ET)|KA89?AWfbO2^oND-m@O>G_Fcj^Z!Bkkp2e5=9 zv0*HUC5T=xDx&TpQ`vrahWf_#HY|Cr!F(CdHhA9W^9rv+V;nrQDo>&Z(A{xYvS;}0 z4wcz$WRq;Zi?=huzf1+Y?g@T5J9t11eip%dmVzHm1&;&5%-*FH%h|#8O7O}XwM+Im z4s+&>G{P=9j}M4_$!yO*vt2$Ux81$`TsHI?AP4QROZ+VL;>G@DuQe1eC`m*j!V5!X zj&hBr?F(vMS=l>}?`>wj$G^Zl{eAOl8g8hjL7qWvXndiTxYAoVP=UU3$WAb9jUYV8jz^&Ys4*%Cj4 z(|2R7xE^Ay*F+uusRLc&2?0l1KMD1V12&FhF)F^np~zpcaFg;{`vh&Hpxr4fSf5IJ zOwb1Ak{iWgI*Te0?|K$|ePc?9R)p+QLp*B8n<8WxTyT&_#rSRNa+dN_bii4}uhY++ zF8^iRb|VO4qv9evD@Mp>qFw|=b#MM}t96cUI^B&g3UB4h7ksR(Kk%%JvEZXyA``)F zTOxD8M}m>XZK3{}rvN|PR{dq@&~$#nGfNMYhBblz48303$*H@b`;2>*ld=386fXab zzU5{zc@mtzCv(N>>Ip1jEpAO6YOf9QAsmM9LB0oh1k#6-bqTVCx+>ar1JlW5H~pca zLN^JPFkPweJ8xhgSnG1rOPXe5uJ#kHAupem0D2G48&p^6Dm^Xo4UUW#hHgCKw!Sh? zKd3C{UOHO2+3`&*0$Z4AB5g0isblC?;a= z*0?|#sqyd*8mVzCX+V~+FM>pvD&nHb{Jj~A4YG(=haSI>o(U7m}P}6yVJ5lmi`gD z8#gf@{khKLm@1dE4a!){EG$IkdWpL!SZ~wXm={vQii9SyD%xHDyu+K?l61JZEi{-f zOuRwjgXC!NIJ^NlZC2#dDWCJy1s^xAs6x~Aar81x7 zNdMHO9GMZhV$6!4r>(Gl^-UUJH782zD=9?$21Nsy?s-(u*t6vRme&}h}Jjz_33|YBn(*pft{23!65`6d_{6r8tg85^-XOtUp3u-T~F_6XF4+BDjpnTPS(UtOkh*#tab$t z(KW4&pBFVrx_bT#rN2|D&nW0oot-Y~?E3q#aZ-oILLR+`_t84Nn}4kEb}02n3cF2j zry-Pf6ho4oOgbGECViOn_B%huk0ME}v^+V3>XUWUkeo?P$xicCI2Mc8nE9rWF%A2M zI+80X#gH=1DM`Q?)1ypPT546cKvEjXs5zw?Y*cPYNew2TTB-oL3FxW>R8O0M9s$~r zfF{$2K+gf)k$@WMFF;3u?oB{b=o!#C#+1}U31}J>8Ev!%XnO)`rnNvn0D39`wNNY2 zGeCP2P%E7UdK+ke0&1f>K(i*Lq(&1^M`zxo-|7#T@(mg{W5e<^ZRc#$MxN4;f#n#! zx%)q|+}0T}m-15R9?oGbEq4)P_tSEopnqpV|Hg#=RfCO% zPiU$oY*`CFYqZn`LpP#7m1X%0{mXRPGJjU+nJk9_qs==<<;L7#YwCV%nyzecgROJ_ z`hpM@4m`rx%oen!wZwW}eEdQkfCKECDAN zuI&$o1B1cP7Z~cYfY(rW`cghXX6tOej>@f>^Opb)^+cDB%5u16&EI9YOKfdK=v5W- zpt!k5E1-k*P=^Df!O&$`T%|T^!HiLy3g`?!ooN0~RdEH1n=`cZl{MG@M-@8$E$(qu zL4tb?J2)6_8NyHqq8*xGsOJ<+53 z+xQ8pvs;(9s%zRDF}MmLC+zte&CN%2DYJ0bdpP;WruXO(#%XOCQQztoRTYf@#o)eh%fP^R;?+V6 zcLh*BuP9d)lc2cyb0tYz?y3&GF^5}JhnUU4h6IlT_&&korH2ze{$5p_hT_(XNbte0 zl`scki$%JDGj?nSzk+MQfJ%)@-313}VCo#cn~YhrU&??RY<9LQ7n|LTkh<2ZTPdJy zpNh5c7xjX)z9%rKVLgHCBCS7PhAR5x0d32g`ufMvwnW|)4!XeZ+Ne6XD>g-Ig-tm4 z>VdN0pCPZrq+T7j*efjFQZ3G?79L^I4hvW>5bbKZo0YTc6&QsABjLaZJRC$?tF8Az zywxjCMRAq|n{PWqJF(jvhk~KnXfUi_pU>E7_-9@4&OQ?@u`ezN|6zUE|JHUWT4Ddn zkaBpO4^cQftvGi6`oCY@TJbc8G5_}#hc5eT7l$7DSNcPvwZYb+2Y^>p&w7SP4AIZ; z(S_`K&DHyz-kduAiSs;nY~B7N*AKRA+VsYTH&}4x%4Ke^%j+!lluV*?c{SwBZ(m(~ zN0yHx%yV~Txeu~@NS60NZh|}nnSW1~Z$ny!WjO^mf*QQ#Igm}r{A$Qv?2iV>a;(t@ zkmBs>gFHid1v83H{#%yuxnXQkvPpccJt*gZVWE|$5H+UB4&9dJCTc7wa10@yt+0Lw-cB`zRgR08UOY&l7s2lVskgJEaH+vO6ubXDipdChi`?d8 z`0|Ozq13q5(YB&oK9lwrxp@P17v*X+oc>YdGCN}*W|1V~nMrxBTyvR0QhMToBA$M# zaVGX!qmNO|!YY1=4g-rXW*>dI&}Wni zB*g$JQRy?r|F>Y-(Tl%g?0`xi?X5IXf2C(E`JKwaz}O%;7Rme~IRZYT=|y$)`LsIV L<4b6NV8(v|UK>B7 delta 3194 zcmZ`*4Qx}_6@K?Qe@+~*v7Kj!BzAsi6GmbuapJ&m`%DNJDO19LO-OV}BsP`|q_CED zY>5)e(qS2IDW_keiW+XDBTO>Y#aVT6RvrD0{lzp^q;bZIWOXn` zL9wOq|3!?(BSuNDYq3~P&vt$K+D9FuU$_6VTReN+aBHNPx^$&>J3=LrLwZ6lGYTBb zrFV5Z*o$;cC$R|cNls~{Sc;83&$Sb&Hj2tAbX{j*zvn>e44j;FMl_Q<)y+Pkwp15g z2CEe;Lz;!Xs)l-94K)kgnPy`@qV;J56iqu$2h*+8o9?7vr5Bi{5Q#6_q1<-8Ac#Vg zE~eL4@}v^YDa-0G6@6|3gp{9_RV^Joqh~TC+LK|(ZcajV6b5=6XloLhO78+41KOE{ zrqfNJGeCQjP(9`ACCbwqvip-z1APr>BhY~)bR~5I?E*TOgqrAWpl<;kPeRS~cc52+ zUPwZ%l$|M&A=8i@O+qE|0o|Bs7`j?=IrW6GC?nG)2zQhi6i1c|+N$hl&zxSUlRjs2p+x!r7;A7Dn^I4TNjvvbgYB41y55NEKfqLXIlP~) zS(?}kRa)1wgS5w*yP*ScFcNE7RFqKPo_{FHC_k~taJy#M0>gBrjzcF~VGcDc27*)Y z2-Bdo_{lttB|he^(+txO;65qReXGO&IX(<<90T;|R3B@GUvutHaWDg+zFAC#B>oIb zAQ%}&Nrff?u-- z>j4$otYnp}o=f+aoO|QWj>nuklAZfC=V#&k+_H03+<5{JW_B-UoR{oer8=*^QL$_v z!|`5vBaz#s{FD8BU6z*Ty=2NKbD zh4vy*Y`jMet4n$&@daL*Z}&aS6YiVWwjrXKV#PrF#-HN-NtKHRY{ilhl>Bw&(C1j$HSm(8EvXemIYQTdVzHwcdSyz-+Ns zK>ALk0T)K3;X1FwKQ*I^J;UK(!)JjoKVTC$7Nh*D90;CA;zsqg4)d^99=4rZ!ZmGL z*zfbOzBy$hKTPLP1^ivlAzt6O>he$6M>{kZm*x`UE?J=9Aiv7T?@(KQ0UM;={2Vq- zKhJk~ui*Y0fs-)GueNi1gx!o)ai>t~oB!KtnWLNe&YB-{w)!pff3q>{d)6Tc{%>px zPWg9j3(om>`h$zR0^#!gfOj;OJq#S3$%wh`(9;F2qVJ2LHws!9b!K*+b)IK5UD!l5 zMQ`rjds9)~Ld?lqiZTi5nN<`%%U;M|K<3_76n-aW-BA<+ZrHm>a~$OGy!H zruLGp><4tFL`v;MqUNECC0jG_?j@!RW*J_BFcp^rR95aXd2na&mbjgr)L!mjZVHyW z5NxE}AwCf3Z{-!H()jhow~jX>*()3-TZXJ^{KDpKn6_0kv14?q!oeD;u+ogFcd|Mv zbVcZoqLYm7D8k-$ORCkX(+kJIlGreMD?Z3J+FrS}vfm`D(ULozuu@3;%sq-51rL2# z>9UU%$;k$FtP{*aDVeGy<|KcWRc964kPv^t`TZhdzE)z@5*r|U zwaf1I$qBP655zeas0|z^9R_EhNLFpxYA*;MLo&f64AMlki;dB3^lmEjNcO~!VVo#r zt7Txp57>5Czx*cEurh&Xd&DC#Bc1a6l}*vX8i{!*Sn~pAXSF{QudSvNwcirY+UQR0 z7I7e-Hh75NwrXIIfj-U?Pm3*Ht$yX#!0h(%T>S4#||+tlWjXs|9YWL$4f8S?tt z8I6l6LjzB>GHfW5U8d$V&7~P14Bj5l#8VFZ9~w=K>9UG6#_OP#j>smY^s|^pd~h?juz^@O9fwwKQrDglYg^< ZLiIOz_49Qa_5>Y)R^ZdL9P-PK{{p^S(<1-? diff --git a/integrated-security/web-overflow/_3/integration-web-overflow.c b/integrated-security/web-overflow/_3/integration-web-overflow.c index d7a76594..ab927b2a 100644 --- a/integrated-security/web-overflow/_3/integration-web-overflow.c +++ b/integrated-security/web-overflow/_3/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_4/integration-web-overflow b/integrated-security/web-overflow/_4/integration-web-overflow index b8e4691ac9a1427978f5618dc451e74b205e8155..aa5f16f31fa273b9fb51c42383f50785cf96c6e6 100755 GIT binary patch delta 3313 zcmZ`+eNa@_6~A{sV3&aGb6NH+AndY!0F_->78V`Rx8jyHAp=Bc>r@M-i4vlTG*UFJ zBMg#eXJtgrIFn3G2U9zxDalCqBT6+{`VmYgjnT0dQ%JGZaT$~XB107NdhUC>u#)u7 zzWed}opauK=brnq=lpcUPuqD;rxyq-a!p9hiOk<>Yhok}2RH26o@Mf&2RLeXpH<1D za7%RZm|_!!51%cM`65B;gxgs~2#02Bb*IZR-RXkV=?0&o+VcM_ z216EupjB2UG#t$=U-!l*kG9?+zq(yOHyz74u9&*$<^cw6^+v&TK+(D^6ElIbl zd6>Yb3m;7s4?2|!Rz|%Q^~!;t;12>(ZSYKVBGg2ypf)-Qnxf6zFdAk-Y)E=RONfHp zfu87Mh}FcdG7AFYgsAaJmU?nkxJi&Y(O6T6(->icCN|C+fhwU0(Y=WNAOcmxK15F; zS{s2z!&``cis-=zR11GYbPmziBhXlwM|7<=HtvlGG#;|GM%aO9R|LwzPDGC(dM*Oh zLmQ$O5WN(E8sH+LcM%b1oDUfrQf*C_0SOo^+My;-_C8e5x) z;g}k2{#q2tZd<*acIFJTPTqw157dx zWxW2XL9gF4;`M!uhOaYt2lOYD(IMarS#%d{FeI&i5@Fv!uxw5g{jEFxC5nA)A)`OJ zGEsoU=ustuPSzmp_sn^H*HL2_+6~qr*aFRoiBO)Xv+PAlZ)>0-Z&C6Ok&+uw@;gp5 zlWGZ2w9_K9!F>oluJ=-;-j|Pn@&F9$#x@uZo$Yt$_p1$LD?wY4lnB)zVqLDie2SMRBYMUg7Pr zA7B@A0;T6?d*9>J6^hXrxSF)`NCocm3sW~UgYRi;ot0;Gi%bOrh~mp#{??(P#l*`( z7R_0ae4OB9A_j@kUr0&XIxZWG3K@J^Hi%y{v?s#i5S~V8@#=%67XKs@=aCp&hY3FN zrR3%a>SB=ka7SJEg5RKNCV`afmAnd0!cg*B+6>y1tc{6i2A4KDl7>rr6qWmS%S*{4 zEuSI>Lcv@V+CAVIQIG-8Etb|Fm17lrI1TkF$cVeldnA_W zKRqFB9-sNZzarkTMc!@Q-!E+|dX!3t`+Hk`*WFcHeGlA~Zr@y$w=H`b;ccav^XQ2t z_|YU>UQweMzTcahT20?K|C*ZiH@;;1@ymPnKELOA;;pPKx98e&&CZ;>7&vVy!AGZ-UlXRlu1S1TFMBXkR& zO1NoFrcE$!wbIYQva-Z9i+AP*C`Hwv97~jzl(LtYm=2mc|uo1Zl*s2CNK1g{_Qs!D(9> zt%H8s9uOP}5KyQO1dUJT7*WQOYfx%Q7q&(^D2<*Vg;0@OlH17% zlFi6UN#aTP3i&v$BWK`~Ts!Rs&S6N_6W;o5+6nl9Zihi>K>ytiyn{Isl}5a0)jJwZ z<)OfY?Xu%bf$wVqnrEZ|Fy+}z8KDbgSY}^HW&(Dh3=fA;rafJdXgpA*@+sDoaHJFZ z^O%2=SYz~@MpO7Y8WJRNI9r4;A1jazUrWPm9Lzq)Mn6ny2XM(OQ^cJ5AsAeomk z5qp!c%VmVKgKiohxoC-R!ip5s zQp84-@RJVLb{9Ax#I&kmsA{WqYl@{QL^MmLsoth`qX=cNvdy5P84*~ZO`AZfw{zdK zlSk>U^zOO$`_4J{ynE06Nyq3|j1F7**E$FbDt(F~A3tZU(su?$xsj8zoPrzS02TN^Rx6Oz3c%a+Z+yH`(TP`zaw85= zuG{thJf^cA)1cFIn-|X7J9d=q8tr>#<#qQDK08Tkwr_>~nrfR3UFCwq@W>!F5{8w+ z`I-){XK|iAV5gk>bJp2aHcMzRap(gkzqE`{U zph7KRC=x(lq&K8hr~pAkn~U_x^HrC%$BdPQMIJ)#N#9zLTw~lx*JA4pOrced#|imt zRmFYmzxK8MiCjN9!uu$gO~n>tg-F7wsS!I9sTvfLIz41WPTz^ z(g)ff!xhtpnp0m%QnYRHQ2(N|#}Q5#dT}p|+fg^1Xq;QYM9{1!B=a#en_aX6wwVRP zy9%B`k%_@Uv%5KkUJlJG9zHRk2bbbuhoYHgnysi4j&)rQ$J)~2=m+Td3kE+A*UTMs z2I?(q=x*3*Dc!IW;bop8I5kWfEwiu31qeTKn zE$(lZD_Yzm<{E{#`2fu?ad6+_2;IPA01eM0^zcw0D#RJ4`zmh3aBOH6hr%HKgiJV^ z8pDuC2H9SRF zT>F>MR#r9eHlDXj@jUw_j*}RgSC-+I3YBpqIyCvBKQ?sr>T;$WL>Aq>`~_QAHPNdO zyO6l~GdZhFY`d19xDF44e5gx-Xc zc8C88-gf8Eh>Wv~Y=X6LH8bm&QB3>mZ)VMNaNF)|Jj}G^lP~m4dm{LPgOJeoHbZ7Yp0bFGGa&2^2wppcX!^hf;eeJ)9CqL%s9GH*qQEg1z` zRYq&UUgf5P5USc_dkf>hX%gBgxZMdkgVzs`(2hQKqM}as+B>J-iRkd{%O| zs}p)_9n=faS`Y1nbF~ic0fB$i*74QZ>xV4{D@L%@Ie2TKDEHWf%gPvRuIr#j;8dN1 zwu7tQghM|~1K{$c;CGx8jNUZ5z3UZZ)}qmoBd8_NF{~|k#9CoX{igb1UX;D5D-Bsi za*wfxaU=1;pX)vK@k&um$ZZWVk@;`L&G=Xet+Qw>#EVkE7+Fss)v$ZrUYj>NNjZn? z4&g9@2+#(Bj)1MfWAg^Z94*UTS)B{egE~&whdOugk5f7tUcXw<-ZxX!S4c jfogngv2qzgk4u=lp*Fv6KA>Q$;Q;n3f=aIhLZah;*7T}W diff --git a/integrated-security/web-overflow/_4/integration-web-overflow.c b/integrated-security/web-overflow/_4/integration-web-overflow.c index f46c3a63..c9a515e1 100644 --- a/integrated-security/web-overflow/_4/integration-web-overflow.c +++ b/integrated-security/web-overflow/_4/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_5/integration-web-overflow b/integrated-security/web-overflow/_5/integration-web-overflow index 507b40fda9b7f4e0a032d2f416010820aa02b8cf..fd529785e9eeecfff717ff90cab961ea7ef8e1b9 100755 GIT binary patch delta 3331 zcmZ`+4Nz3q6~1?ug?R6FhW}=ra+n~G1_1gsqcka1Ad(6+r{k+?1GA2q)6t!lov1j>j4UMr12H~vJ(7!+x`pLwd?m(0( zgu!^3AfXl5KisfV#*6?<%P8J=y&{-X(&_G8OoHD&Jg)D4H^H> zV=&|~NCs^~(jOmRc0pf$plnU;zYlJ_dAj04%Z3l>m)aa#3S5N;$C#b9aU&DhB08bn zzk{%b|vqtrtRdML_DpG8@9H(+C@eoZ3f>GJq#YSKCRTZ-N;rG7)v z?$%jp5>Foig3Pg9&V=>9p7!yU!F)7p*V>g|HV-dvGlxGZ# zY1lW^A5%$j`naWbNdnH84$mT`r&c9vB&8FBnp3>qLS_26cy9!%rE;L#fc`K7)zNmK z2Y@z5pfPk1=qEsTMW6=y8_*e`uSB46bPwoCLtOl85oiMC8Z5L4XkP?sq9=g93iMb6 znn+zhhk%}pK+SXl=w+az5vYZ(08NdJiw{Piwt6lhMT#AQ>4An!Gsu>WP zh0yW(>qotQ&$!q35geZp@Fp5gs^Mc~GOyrGRAx>oeHgHBBv>;e%l^(y|CHrHv5+yI ze3e)QV&X-ufc7_n_IqZ$zB8~mN8RSE>>2C<5U$^yZ~iZpI16GTTT5S>)7>Ac(2?)x z9#IJry63T8z5dQgyb6Qp1LO6L9K(=Uu!Gu@lc_e@n6V9--p)X4;hg4QBQ?vQ`Mn~$ z(CP?q_#u@IZU=O~-LE3;zPd}?YNlJs=Au8{nKkx=j1#_N?2I&SQ;j!R%tcSl8UF{X z6<-kS2ZT50&5iiH%BbI#sTikRa?J7Vk^J>ut99}IZV{E);Jh5EaH7|0U$8wA+1G2e zQI*xg-=+qu`LQlFrX2x2;;}$g3|5MPb_QN3x_|EP>Xlj5-JUX|m%nptY%cLi z!NOe@$oq*5m52o~@v@SnomW+d$svc&sSfcqV_PCTj^Q+d$1iTp_xNX(I1b{{gGli4 zuaseq!xlmM7(43h7rY7ALIadKDs>g?r?EvVc{>?WSFBEk8!T1t4qnF zET8fUK*4+{Z65KAYuJeAqDbraYf%O7+@u|;i=KQ7Y-eD%aPS-9V5{ojs#p|VVsatZgVDM$Kjt1!aI9U^h9c(68`i@pt`I4ZW?3m@2~Tnao4Z&-E!BteKYmmuH2h|H&idbhmq)m z?_Z-+iyJlPZVcq7HSl-r1KifK^CylUKeuh$(_5Zq-nzP4XTBrfUX)iDOZ^!&h&iKg zGk$M)>WVBMfpC%fGqaaJgLzzulm0d2b~V~@tbk^;b%?^NXg@%E8trM~Sv9(&mu0z) z>a((R`m3_sLVL1Y8&_i%m}i0UB~4{~w6-`ZE=JE%0eyg{7=d+)H_!6Rw1T$+x`<~j zR*M(jXL)q(c*NbKh2ocF@c`v7sj>wzI!xDW5hwqP&>0`-S+YfMnhagXra~=@a-F8b zIEX~CDK#!xv?Dj2=TJ|slQ+|FZn{Rp=|ZlNr`WZ*iT^5Zokv?`g_yM}@YJm2} z5~t~#BuRO>lAY*Xqb8Syj+S`&vVrp@E20)ES4&B%s$N%7*-+ppa1;+1%Ae%}yH+=H zeu&PlaV~6*R(&*MI~4`#k|H@wTVo_e+#1S^651#^4SgZBk9s7RVKgL-(&v(EHkC?n zT!@lGHuqlfp>C%soC=3bD%V11frb;on5d#ewhE^qoY9AAeMJ=?q}PFkgE>T>SGWv0 zS(0Lal&EwW!ha(Wc1YnV#tNu((JPfk8m-KmO@2GBg`$j;ZLQ2dBb&!%Fg~barL@uG K;tx}gC;PuNe;j-O delta 3151 zcmZ`*e{56N6~6a5PVC?iKWyjOA&!4#ZNfJ8&x{Yrm368R;Z;diP|jLrh1!b2MA?QvCW`XGfF^#l9oWKw{zdK zlSkRE^zOOm`_4J{zI)Dn_hsXBEKZYFetwNeSW|jJ+TN&pTVGo$W2E+tOJ03wwW5T8 zr`}MiNYM(C7!{qOD8|QGujtO8C=Uv9o>Oom?56_XmbYrlTeZQj=->HKw_-Eu7UjVx z#JFzP|BIN-N6dm=({29!@E?ySQ@)Seo&HdHvFo|dCNJNCeVSUE4MPKqh*Er1l(iDqCF~93-2TP9-@6J zv;?jrI)~`63e|&MFF=*vP?l7o26zI|D55D9S`LGV?nCsH3gzK9h@M1rN`;!>pNL*Y z^sEZCKv}5(hEhXWR)q=>M6|uskUmp$QG3Mb)|Gk*xg~vVReGIqH(igTUtkH9J02tC zv-0Y@sK50U{b)f?r+7aFvuTaRSS^xBW;$hOB2$M#vYdx+nBu0v^|+z^rfrefr@2=p zN%}zhJX|tutULClB*nr@2L_j{KkX%(4S*BJph(Bk^!H68iuHf6m|+;EK7E z&OxJP9o+*vER`E~BOJ@*x|bv=KCiR#r^a&P}rO+S!H`{sbQ8 z<#*>8FW8SJ*}g1q&)aH~55Z}5u1=_-;|SScr&XYnFoZAmA8Ui5a#2nqCZcCC?XtN! zF8T$8*VYV;%F`y7H zB602ea#fAoPy&88AMiX<7|@S?J5>=o@k50XTONqmst{F3%x=Jn%>GMWW)^)h%WfsA zQY||94URHOS(Q?@Iq0lfPcOi}s&zvH3wV$Qm&g!1i&1o*cvh+XF}dD@Z{lpZAED86 znJ``tneZp94*$@FUG8ZH$HG@533kAy@mNf-Z*U~`5iZ;)zt#W?yMQq!b}=T=(yN61 zCJP%}klNW{n#3w#?>dR`My6z!KQWixii=lqd7infLK8g5ud?ww&}*-zr(oD#L9fA& z?T)}DyzR!(iA=DIY?6&Io4F?D6xaUxf3xNVxNdj09Awt=moN0~Xd?KMgOJd-w!~&a z+qT3OLQjQaOWPue`WFy>GFta#JMI*q>~u)Hk@-mTvvhnu^w;DFxFlaWdaYwcTg7Li8_pOFUkuj4}#0nsXaRV>FBUK3f8K0}SC5i3R3jdJITM=RzyU8j6 zqc8I~bmGJAaXZx4cxWGNt=Vk*39b(JcDb>99z>gD`gF}s9ll~Mf7T?*^h{o+pswD_ z`|%=Rt#IW!VOPC_`XE;CrCl&y@8Iqc__)4-ug%{{EJLgr!Pem5tvXTG*e%T37;I_i zq=(>GgM&uF)o8-0pQ3Hx@@C+7oD+<`EQY=56J*w+(UU`HCD1YKE%@EF!q&#kjY(dV zqp3R$DJO+LwEJ-*@xxymy|z)es3zpGhM0&B_$GlmA=G5iScng$fGc8}Kx$!6(>A;4z8;{>0!@Lf*=zF!#R4tM7xOk}p%-nOFn~70Zc*m&Vw2k$>?z?%5~iEI zbQEr4?*o@#uoeFH@`j`gb47?5|Ejhk`_(sTMwSw`+Wmfk8sV7#A9M!xvv6feG zcG~(w?#fy?()tYdt`%;zKF+1=urcs5Ql|p~H@^n{7HFV#uo&n@XnUKN&zMDda=AKj zbQ5|50-S1#q>UR)Md?6r7lkRVD4lwwhhjph=;gbL6_+mj+^}{JrXO+OPoI&GmWVPE z&DTLI>=(WILwWQNjEe#NSY8{0MKQ2kI98qPh~*Rt4Ph})hrE0t{YhToFb$i$%fILI zYZSBtLYut$LjC$-VAE#&@tj7iuzjPjxGA95c|_Sk2OBy9`od2*CJePgQhhLvS|KTI pu-Fk;F8Esf-D2$`gdUTyP($H>{!W{MJp}tvs}3q!1%yP$e*xeUuM_|P diff --git a/integrated-security/web-overflow/_5/integration-web-overflow.c b/integrated-security/web-overflow/_5/integration-web-overflow.c index 8ce8542e..d7a15450 100644 --- a/integrated-security/web-overflow/_5/integration-web-overflow.c +++ b/integrated-security/web-overflow/_5/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_6/integration-web-overflow b/integrated-security/web-overflow/_6/integration-web-overflow index f1dfa195eff16ab0de7b94d83e4d5f8aeb8fc70a..a078a12e7ba6b095b041e201afad147285832d03 100755 GIT binary patch delta 3270 zcmZ`+4Nz3q6~1?W*j)m$&t=(NewSUWXk~w3VbO}dm26p4GGc_bj#?mXloD;UkxJS) z!q83K*-())W|CHCaK=uzjmd;C(*UE%lG0#0Hby74=wOO%Gg-!;K@4M$h}Ue}N;VmP?s)b%cr2ED*hr|+Cf z8YNnym&O#EB>b6+q_Mez7dwe|RuRXcotijToaKtMT<`~afg83-oM9U;c7`FOsL%g@ zim|w240Ou+^nsT@?)X#n+_zc_s!j~{G`(i6y>%a6Ru)<^Q7RD}Ay(2x^@L$ra8|j6 zhTyu=L_c9Q@Tvy-TXB3)tj~yOkID?6s?6%U=wpRmg#lb@7yS$x)lT}B$ZHkrlOnrI zZH7twMewIhGJ{^Ff`X(INiXjIDgHq;sS}>jWI%&P1x=bvXwz7^YbeYnu_g1zIzklW zOX$^9LW(wJnU&`eCq#|EEU_n5>m$=K0@Kk4Biey>6_>naK@Fi5!MnLAH@G9=BvD zL&L-`l?*!8fab7&E)cqm9@n7DXkR{uX8;bS9xitOw`912hKc1$xN6Mv{Y8RKe~o)u zG63UV$Nd@z2Pg4S7(@gufzU`lhD2f=(4LV2H5vN+-N+0Cqb(&1%u90ST4a9HV`Z$4 zC`Fy$NY>aMgdX<`%Kbin2-IwZ=?tUi!w2)u)p6&vuQ`{=o!cbmEheMqM+?qh;cmq@ zi1i|bPj)Rt9Fr{4yV*qN%o~mc`(e3#s@rVNIo8EyWqxvgEhn7qHd~kMmm^2I%@(LK zo9Nq6Z#F*DDa~m|REzUrl!&oP7HBZK-}Cs|E6|KFtM4yf)d{U=xH&5bH!9#ovoqyA z>|#zJ`_XLQ+h&_WF);&|G7Anh;WWquNBrXoGUERaOY0A6u!=pn2m7+Ko_!0g!RSj&;E%{2Y?cIWvrW-ipWUVVPzf>^gwSX>sQ0=?A$|7qf^K~8}`ql!ZA#1srL#J zZ=7RiAUnAN9XG9^gSgvUCIg|mSRkz4X(MC+^~oTrllNJVrS=7;A6A$DZ)>k;W&Tf3 ziigK1AqeNB6~|9o-}kCJD<0+&;`{E#&}CoU#?Z8{))$(q3v?FULwHN|iboiUHuk|C zxRBGJxOTVCom)@ewGL9t-UB~z{P2a{yPw0la!^Z6pfZ-BQ%V^qG`Bl&sD6Qg$MRb+62Y|JMD+n z1yyt$+6zqTQGBYQ?_|L?EjJmzQO(5LD7cH9+$sE)uwoHwyeGlFqC8p%M~j>&H&m3T zP*C_+k%P0wKXq&&SSf^jM;=$M<;4;Eu^%Y>YKw^6Ah5o}F#R2)4)%3-s+%H6~9qNco3k~EUI8a|He$tn2Q z?X(Qrc)3CBD~W-)fGajpGx&;)N+U+^E5@5uafZ@_x2Ju@2P`%5X-PPOUQ}Xc+rfXNwJ*Ani7um!%&Hn4#OR+aqc`OOX89l zCz4dm0z%Sp2{xm3@q3h@l@b*$))U zEHG8}ZG}D;)_8wLanijeh28*v^*ZQrxbLk;_SSMI_hmXSK3vQ&?A?JzuL<5M572M) zT`ym$S}NWSdA_Q8*kPO|NVD~Ki% zL2r;y0LuoaE|JlvVDpA5`XRi5SYk4V;o=6b&SmFC2TX}duP*VQ08TrO5=)FbpwbJ6 pEA=p1>6%Y|E8gr_83)Ug0{s*$ey>iyTEf=AR=<}%1xNkM{|mN>76AYN delta 3091 zcmZ`*eN0=|6~FfxgH250hi#rsz#o{kI0J0JU?+>)=TJ9}#0F85R@u^G{@BuFsYI00 zDjf(&Mu+Fn(VRwGCQXHoY?;=zw3aG@+7#5O&bD+*ql_h0wmDU+8HGe7Elo&>-p+l` zhL>i$(!1xL-#Nc?@4NThk92}gBJ6XBQ?#5UMn$J6^6_)lD7rHw%8i_y=M>xs{Z!zCS+8K$D+s@%f8)n06rZsQQErSu zoNIUezliB<#5CwN?dHo>r^l~EM|XNw6$gLw!uNi9^MlhobZe??HVl;;91f54Q6phk zDZHn7j2?u`8iA%*4PsslGI>_|9Mg_yt&kS;;4_VxzQF+P9Fm;y7H0yV)<-{r4y_k1 zpjQmN4EbjIOF7i5a;SO4o%vS!BUqn50_pt2u&=-ZeFaWPfavRpPN`56{1eej zh@MrU7APtdz))x?N~=%-LWpiGG$hYdUeF#fR_F@7gxrw6u`0RFxQA9_>o}&+8pk7q ze6hxU8}(m(O+T8`lOw#Jg4tATG1^5EO-+xKGm-M3kSyomTc(7mry3`;%d|Zj|2*@8 zBuO7?e+U;%8$8GEN>V(sbf{-Z>T*Pfiu!RcOqQc>bf|G*6%!$|fso9{u+i+It?-mt zD0)-DGbl0%IB0fnOktEmx0DE96k!CH5@DC(nP#5N=o3wBzYtAC($V;b82Bp&?}f|e zRyqfDmUVO=?6j0_*n@C9m1$p+q{P6^e@oIN+n+d|t%~7MG|bj%7<4p-=0s#E8lOSN z5R6;g50)uj+*Ua}N+=kJ_z&v(^gE)>`6>Fvkp?i79)x2wW zz-6_7MX>nK-Cic|&5|AWksnu+hZXXEBtN@Cwr9!H2w~5@l@aUI$DRL|lm2V$x-+ z;JB8X5LsKQ9_q-_RT%c|*l=q_8=dtd=KQqL0UWqWZOk|)2fme2SjOF3`ZCGWVWN^EfuxZ>Dlk5zR#{Y@~H_E?tfQ7w_F(!92%TQy7 z685_+Y-mB+$Trg{%mVhWr!d~YluY>xqwG;AUWKxsQC6V~Zsdck{U&sj+vzy;m6y<2 z_<6Y_a1n32lSm?y>>@kGTDY2-dPYiUfB(O&<^{M~?ri)q^OjG(@DnXVq5Td*!jEr> z&xE&ci7$k=h2u-xqeC@&5q_-2b2oZuPM7iCfQRidF7#z`)ZR{^v#|4R=Ol%{yS@We z6({uFS0(9nj5!AvD<1T$#`&nmTQh{Y*Mf2YH^b8?mrx!?xfgfVd6eDYakpwu&q-1z z^tjzx<26Z&!EtxMeg)@&L{=ML1v*lO&>!*pj8+QTLG0C(oUVLAhr_Jq&zeLe5i*mNBjBm=@_szbS;<|SPS{=JpgxG# zcxfA)tZ{I62z*jg%U5OZ6*kMP7{ONS;H^4Q*4RzT$^>kwZKZ>7tkywWz*T3$uD8)3 zxV$NNhjW6_m&UNyeS&PYX!K+dy#zXewFS>kD{QUXTsO>%ax`_NA!|tPm31#}B!2i) zo!2&2A*u~>TSH7ZQodfGP6*dqG#27RDd32hCXg!FSO2`tmz|Ovom~YS_7?-%AkY!8 zHF#~lkeD;e@|mp9S?E9?CmcYZ!3t5f;pHTkGgwo?lV8AegO`rMb*z2h@(Z@yi!JL& ziZBZZG2_cK^Z$d+z`jO-`XS!6bYTfRbR!y|*0J23r_10QZizNJ8vk(O*8G(o@U)emOTK{zP} z^b=Wa0v5%tx#b_`6&o(YChzhSd%jpfn<2c(tIy@H9}aBV zOkaa(#B$R&28){ldZSyE2}W4o9MI<;(zsx#XSCMMj&mJ`bf0VYT7u$ zASv6G5&gy))0z(H&?%jojD$Z#N0X(GVB1ua)EdlS3auH}5iQ_jh+=Pl=iXgdO?qbU z`Of)$zwbNWJ@-40?FsS05O1@YO=%JnMXedDJv8?>#@ZwWL+7&F*fmYF-tQGYZPoDjWJB^Sha>@KOphl^X{lA&5=m(!qUMxhu+kz!a!Mc$)lxaotw5iRL-n)`=rN%6 zacCmF0rUf)d*Vk_pY2Mk4g^1s{8*Od_x0bPQ)vt51|Q0D&_B_%cS7Ek8)!|b!=gDo1KdFC zf`2?AMEMqt&k5#F==pT#qLXpVzo&qir!p&5W>_$b z!3l(_`vW2WU?BKDhPou+_0*fbf)9|{GLP5MB1`7NrvV51A}c0jIn=!VpR#;fENw(s zs47aKxV~R2pd+S6*~SU z?r~K?f;)s290)a!U?>F92~8l_*MpE)q=_0cGH7LnDQ_#7f#&e8;wffNJaZA4Un_A4 zR#TY6PlKwBYyt7EEhXQdGQNuS zi#LdL0m8_hsff?38ui`s730hst||SC@%pjDHrtFNZDLj?Cue6o;p}0XW7>D(k%NbA zcB-^l`P)=uv#f4a=d>wozIGFXJTA*O%IRgB zJNYD<$O*6?j(5Lp%hzbG-=mK+XYTtZcK*pvckdp?X>A@?zp77FMZ!QaxHr^1Fff&P zv!R7MCzOvWrm2b~D6aohNz&$9szYtm;Y+GRyv@L-IFAE3pWyN1yN`SPgQ_?M#f_(s z;DetjVGhC;lXMb$?BpB#8mJKL9w#Xbb%(;L;L z!j5XVHM6Be*e740gzm7TNi85jlq<01bzJRCt< ztF6~Sym3zKiefJdGz~j~d$HPgjRb<#kw8elF`uzh@Xt=eJ9}5OL~36U{zLk*uhw=c zT4Ddph_ZQ{4^n7GYSA)v|Mh*lsy?RrYk0Z>9Te5r+a_fjJ?}t1Fc@%Q>s4NddR*cDVGHwKo_{#GkPayNFAjh#j z>LJC3a{zJx@*?CgjpolT82pbc_OrAkFAN5$l$t$#IjjR*WD&7OVCs-M+Dy%GQ zH%p4o_)5!CS?tF8C~jgM^yfl1?;vxLB`b}YoL^;~ju-S5S+o|!?<>NUuP8%n#kFon z(Qf<7=)}bQinCFJ@fwI1TX~r5#cunY=zTTD*%sxDP#rindIg-8d`VH`v{uRos5vvU zqtsh0;u}Sc*(@-&Tb&V;97J7fgG3{Qf#*{{X@w)gi`odcS_PR2+`C7U< zhLVXGWt8f?Ryt7@;7@iBmCe&lSFWv+R9UrrX+=$utH`yW+gQGZckfwT%XvFpUgDl! zpP>4v$HpuQ5++k}nKvg&N_TTKH_B+8d`ChD*7Oy<8s*#sCHB>OU%e@J$}*Jyf59eyFL^LzQz IbjUyZe`{$$BLDyZ delta 3231 zcmZ`*4NP0t6@J&|&%^{9+t?<6jZGWK0ye>5l0y3oA#o-uNLxBZO$JC?Q?gb9wP}rT;I-B;Nt!XVygtZw+Q@l;>nnqDdx@>c*MspOB5f)lVsNTN&o((Te zccpjFJ>U7xx#!(`?z=A@X5(QtVl&R>i2`p*F9>z7m;XXnmMvpK+3S})y1;5h36PO_ z0wZaPmXd-&(HTSr9%qH3I~zoKkdm_+1vk(^W;NC&S#?QP9sP=ZXdH4WoFSJe4~8hD z=_vVs5#z~-anfl!%+7gV-ebLIyLvzTc#E$3nU0-Da$IykTV}T-R4O^7Ck!xyz_9{) zPy0A~nXYK9EXI2h(>f`UW@9gM?O3{v;$j+orZuzQaUgvLPELATV#FuSvLAOp2G(wy{ z%519QNu`=o6y;$$`hpY)DLx{~S|)l%yRxjbGfSV-rb4we40H%+rwUD{_kg|&v`2+z z(hZ<9KnGN)j*4_vD%9z7MpUSt9tGM0G@?RtsSoG@pr=%*k$wyGB+y9}YNCGty$tl6 z3bjy9ww3hR`kc55wNeAn`fPplWa)JJF@q~B+am~b(gUla>kNC?dW?RC63TUK7KH!i z7TZ)&@e$RVOCD$i`_O{I zbaSRtVZNm>6A+0oy=->Z$5hO}=YUzFFn24=IA=D26AZUc2gA+rVCXES`kceh(iL+n zo1rSpI@U`&Ed`tQ01m|x9ZQlF9^CmaNt)m%78!0=3|nBhR;A_8@lKe-%}c@1MR*L; zDT{k;p~BMK=dM)@*Y3jof`;x`9D%F&Fu?I$K=)4dzGC<(=e~x684M53Vk#u@XIO%v z*f>%W5=1BR^QkA_P;vmw;Naxm>J{d+n%M&8H+){sIyA`;C!$yreSq%u3#k79Ahq>$1E&qiV_rSIljQl`Rw=t^9&CzDBCcmm=bQFgOe}#!-JPEuT)AutO$4HbH1-?!_$i4 zIT)_JB3ISmO(oz{$$;l!LO>t+`;?sqQHTOlVRSbnNT;GU_jQ>+kGY((ua;_3p zsg^AH4UTh@l9f`n32H4|&o0n`!gc-o=W*ovmV|zOI_u#)@m;0%$K`r&cm=a1MnQTy z){F}y*8CZ-!#}p6OYGussQJ_2Fh5{ZI2IH9s~imd4T&4%*V@m+UPX+FZf+T_=~BWr z@~{o_QawLRXHXyfUC$ui;H2yl^7mwod6n9w#3J&rfK7Nb3ii+7O8Ys$V*XV~u z4*wxu z?b|~0fhPi?rS{-(#j}7PZz=yWcxWao;hCdHiaRw8x1%SDI~et3_q^kbF#1EuqfDR- z*ROYs-jJk|h?@2vNxA^}omolZ^Nd3N2=be^B#GaO56wxE9(U}6ShMwz?WoTd$Tx6c zo`E#u)D1x%hP(hdN;>yiHceG-ll?YgV>RSfiheVm_>3g=&@Q*zUUpNGI^mIOg&6P* zo}@9i!?hOkU&rbS&8rPZG)*}f+E2Cm%q)Sk{)A`lHhtnQW{eiyYgh$YO5JRLHkNKJ z`Xv%fO$wfT86UZ;$R(-`@>naFgoUrg&G`KZY_Mo8f)~flPGZ$o z79o4J$L?(qQ)XE{m*kwIE^wT*ADkYSDBEx=%I$shOfU)qG*#_kLv#zhmr8tAd+O&g zNfdJALg86%hxM!PRt+l?c(w<9R%W0v-^c7C_10LKk3u#3FgvULf#%8@I#&B_%{w-l ztKFiB6wxOCi!i(UcbT zH*_?$Xr54*WwJj4hd>jI<;xqm~Ye9^KI-dX!F! ze%*Ld8>dClzg$YTEZGqS76|mS9-0bxjH!YcF)B7}L!)Q;Z+|vVL7OPh=+UJr+DH2v zx3X7h3Rr6ShG?ak-@eqCx;y>uE{YFFxLvB|%D2FmdJ#@jRn bHcP18K(k-BP^VxI(m`m&4T_de0nzb4#dOTr diff --git a/integrated-security/web-overflow/_7/integration-web-overflow.c b/integrated-security/web-overflow/_7/integration-web-overflow.c index 98867fed..7ea0e5e5 100644 --- a/integrated-security/web-overflow/_7/integration-web-overflow.c +++ b/integrated-security/web-overflow/_7/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_8/integration-web-overflow b/integrated-security/web-overflow/_8/integration-web-overflow index ff025210bd29548ee2062956d7590b6be4f8e219..aa6951a990ae2eb3766ff80847ef76a33ecf2e91 100755 GIT binary patch delta 3424 zcmZ`+3s6+o89rwpu!|tO!m_)7u&}->`v7!_6}>BNSyLU~ZJe5bX`_^AqA^y}#sP|? zZa0kJKhBtmPEChS>C|K-bn0U?S=vTyC(%5tMF$Nw$+(Va0UtvYd;6VxcVRW@nZ4&f z=lj3^KmR@VKaV{Y=6zw_Vl$gEBqoYlGgjR?{rAS|6a_=)qTARpUhQ;{nY;b%I<*&< z%%t`?L=qlbk=nPFOG+ayhcz*r8o1T$iLpE}mWTep&zai_RZd%>q%_(nq^TU?K41F6OMm+1jt|DQe)iq)=__yUyF;&Pr`faNDjpnT4pz@iOkg>5O1qMW z=&IJr&x)EPT{VAG>F-qPlL~rBXQPjGHvMhbIH*IDK_0z_pQm+tH-B5PW7jR72`yha>@KOphl=X{lA&d`W2}qvn)mu+m&ZYFaP>)lxaojXjA8bxrhedN@BDlfk zS^pd-MEMwWQ=(X)ZsIfO@oc;~toJ8Y#)p(`VQu>oI<1es& z@dnWjKp5FG7V$@_Mt!$J#W?$hYfQf>Q9rcTW}CRLMa;_RD$y-=Qj-Wks_(r;QN<=HtFWjjBQf+7x-Y^wDpB4Qj-!|N8N-dRA5R56kk6a@uNh zryfNUIRW;=;m&t#g&NKEd-Q4cq`D>8`A0w9y?Yp^xoKGas*gDsP49*TkG(jb;PKPDk9+*9syGhCjVF-c zeOHt)`(TSn`ZM;}(Kq-VTnh$NYE(eigCLO+?>c_N?VGp1;QH~48#g|;;W-vuwQ8B$>+(8EJtZl0uwWSt z6tu5-^`yW*W=OO!PuyATo-+yEo#|>i(lTG5Z_TU)-hKW|nB-D6KcBWsJ>nY%L+8u~v zGwkCf7Yz~5Gt}VB_q!3zJRQ1$@ut@_6=_M@S-R9@0~4&j;SrzBja(YjPtgj!4bYc( z*3wmH4&O}=olf3E1(Pc64DrXK0YSM_?85lNoeh)f4CaB@MeklrM#x*_Hn-u36UDC7 zxW3VrqI^D$T8rGghPsOKH5yL;E^?V2u@hKigDBIez?E+i*e;E&eB?Ot=m$( z-M%a~F>$}*Y}8=9dg3Kk9wB>)+deIJUyXA%#W(}B4jdc30?zJ2Nm1jpR?3H{IWx2U z)Kwzl8$^xSE4A9=x8E3%r777WVq6YwTcH$JD6#}v&P22grB+@~Z? zCQ0>CgN<1fBuuvCGS?X*#sEtBl|*`e@ym(&uDr=9exh23HbPv I)Eb!jKmMCR5&!@I delta 3229 zcmZ`*4NP0t6@J&|&%`8lY-5`MwlQrW18jo9gy7~GLgP$q5Vds5mJE>AWn`^H)}|2~ z6w-t&uJJ~460NCJg>t`!B|lwJ_3j}`w)SClDZLea4+9$j#?q6Epv zJi);fMN3M-py&)D4Ue-_(VYQN9wgTg_FIFFH$dw8xw^7o!&1a=E+ZM@OhzTV%H*R5CfFC-gCcz_A>9 zPx}OWiLPm_Y=ZYBrnFH!#l~LX+VNBy#l#f)RBL9x<3Q>RoSgKw#zfv!FZ+<%Q#~{d zRvTFQG&6fu4s}`%H4EICW@A60O=&|EOB)%_r$Z+Q8X-m> zrPr79q>{}kit;cOeNGaD6t{@7mX4m$?hGsK%Ft&ut57XPferv|Q=zH!9?*AzcB;^H zx&?FwXrBtzQJ&69xjKE;pbFK~H-I(*9a5ods0U~_&~qx(NWTSo7U-A?HPJtSUIltl zg<2>p(@OeGeO63`S}6duHd8-*ws1Q2xS=2;(<2CT(j%*eHyHM^5{%wJ39WH#6@>q; z$-f8vwJ+%>llt(G(Z|SaT5B=ni$Z8(d?=5LiDC%Ja)~yZBBq`aEa-kyODKFj{$oj! z-cS7@T`|=ZpZY?Q!VOD@dX}X9j!-nK17~4058P0+a()#T0kd8Z;vZ41+4V>h*oPJr zrkgXJ3iB<68Hb2R=q0nec0$Gcdlr~3g}Fyz#yGPcoKU1?IuvP$g~IP+s?Rw53|%uf zu^B42Y+(CnmnElWFW~S*ymd*EBK^DmB}t?F#3I8Tis5k>Zj@^|bg~WRNW)SnJOz&^ zowK;t=PE4CL+)C|aN|DQCpC1>;s{>HhXIc70(x+&4-~^MIrnEcn4w7jET%#de}W|x zo)|$&LY(MKb~bfp8(iIBhWf|$SFA8EtC@{pe$D6QtV3fAaZW4Ncn_cl{a#l4-M&vQ zn}sY^i|^9CW#=6UXU9X%o7K*Pit}@DetyMSn{XZngqgi78Q;S3U4FNXvh%u|Wh?fm z+OFYtYu?F0zAnqlLu$&0k50{z!!KqpPip$o@oDqvJI~&rnnnu|Jd{XNdMKVE0yvhtO$4HGrq5C!_$i4 zSr~5oRIaN2+e*N1CjwrA2?2fZ+oOuugijYDRz4K5N-^ZZaB~wXGWJh7%@};K%d3^B zO0{IjZ*Y>El&qApjZ;%@37e$u+zq{5^Eh%nOF}O{owaZteOjsg5xL$2M=)Fb1W4bX zXuyRr(eNp+!#^~mi|^)exZ#sflpnBh9E(x@RSt#!io^}_YjyFk*AZj1gIl7N?Mm1> z9yTy9)$+r10rkP(^#bDckI62>+-0xg;!#|_!(CQ^f`h!5kKdy9ynJ?!`tq{b4f;i% z!+!<$-+4F*qx@>Sz(?54_(tv&NqzIHt>$^UmFKKH%-Qm{F!-&;Xy7@AAOxS<9-a!e zY!A-|pA3eVT0+s%X8=FZSo}rk&`d_$Ge=wU+cbf@!)Nka8FglMzT-U2Xw>yhN-cPE z=ZRaAbQUpF{v%0~kl&k?BtFXt$X6i0en*n{ow#{UlJvM?AH|B5K(?Sd8zEoAarptH z8E0+)@-XBi& zg2_q2lds~#m}UsLY4}Xxfefrgq4Acx zI$!G0+!yHM(lTRF;yUA7$(w=fWe%e)LzFdsf%7&(+sm5RQ94!TV2$J|H(}~0Sv9#l z6ZCtHlMLP%!rt*(WvfN26OMvqWh3Y<_(0oeNBOq$L8B-~Q+HZnjgb7gdk{AWKKgUH zr+lD5R2$^6Rxk+*Ux}OX^Ap@?(OLvAq!l@G%_bshEY&2K( zxMnDiYWy$2^tRusnO#eN@t3h;TJ*O9+F9)}PMAe`a=8dGxnT|0(IqR|M_qN> z*vm8yEV+CGv{>iQOcumK0oBx3>5{+n*s*%QF1f2-Iu9+mE7i1E?_WLxMfiE+ZJL5x aCDd-P!LM7WRts?##~s diff --git a/integrated-security/web-overflow/_8/integration-web-overflow.c b/integrated-security/web-overflow/_8/integration-web-overflow.c index 02fb9cad..8d159d7e 100644 --- a/integrated-security/web-overflow/_8/integration-web-overflow.c +++ b/integrated-security/web-overflow/_8/integration-web-overflow.c @@ -69,6 +69,7 @@ void send_file(int client_fd, char *path) response.head += sprintf(response.head, "Content-Length: %d\n", file_stat.st_size); response.head += sprintf(response.head, "\n"); response.head += read(file_fd, response.head, file_stat.st_size); + REQUIRE(!strstr(response.content, "pwn.college"), 403); write(client_fd, response.content, response.head-response.content); close(file_fd); diff --git a/integrated-security/web-overflow/_9/integration-web-overflow b/integrated-security/web-overflow/_9/integration-web-overflow index 4fcca9f6574354c09f01efbe57b25b832f79025c..731e20eee3a4a6f8d063d55515d6e670c6eb97ba 100755 GIT binary patch delta 3272 zcmZ`+4^ULc8Q;A>+#LbA=W)C{{vLN&k;?sn!$U{(o#e`ykf>4GI?)1Yqm*c)O^Bwg zBMiahdSOJqai*D?8Jw~0r8SulIum3tIZ_&EYhsdGiw;_Bo8~C$APPei`}*yBckm?b z4!67C@B4kfw{Q2`eM@hcj)iH5g)^E2!iroIQg>{{uMBm`5{AYlm!W%!Y;*%hUH)N> zY$aM^lx>Pl68g^$z@V;8pNRbHm&3o+X8cLtwK^yN$c+B#M_KR_b)hvAr4oZ9#73H_kuWR^&Z@W4 z5L{F9^kY_opsAxjm+V7Q-7leC8Vh`)v1o5&j19U~CU9%r^a9jtUGz^(4fnNW}S_@g2HSPn=-#|AVfvJ zfNotSr07$Y*#rS`LbUkHl6rDgzFv?zI;<(A>UmhJPe~0bP&HH_x(Cs3D^M-$Mf3!s z4GL5TuOoU6(Sr)q03RVbhv+K`GzIP>y3&x6`ZEQZ2E_&*b|4y2pd9Q(^i@QA6{rc? z5$#8GSb>`1ETY#D9Z{e>+(0xtIVClwK&?Ib$-mKd8tr_QTQT*cfdgUCOQh7xro-oT65-_M-UDT#Wu}}Vz_O`-$b#GZDbseM|P}2 z$M{QX1|6?McQ`N?3|+*CE6`zfET6+O0F9}8i^KmRJ1(JPe7PDfoAdm?m!Z>N;hvTq zz_{0NzXro?llUkcLW9iNso=B_jhiXBhMMAT!t&Z7N-0UQjaEBJ=BB8)LOb zDe9b%y|KLrJs9`0GVbanSwb!5_|q(_{&m~w%wEk^WuWf%7XYdqq`M~qxdyK#m}Y}EB;P)oI%ILYE1C4tI{yX zFcv52&v>HFzrin1nlaENk4oMJ$6+*UC2avicG0>Fl)IHtASJA%ZC zVRi=F8XUWhNk`7{Gqv;V0-Z$gtu0&xQ`>z$KJmM z=X2^*S8n%sa%<^3wti~eci;!k?>@U{&(ph~Cc$mnHoH7dkIm~YO@_Yw$8l*10iFE~ z!;TxGcp8mSIAdSFq8=A=C4TBVFuAL-9lic#V|xMHb6{|6(nhX}Vl(V? zIJD%ZDDHzchc9;>lMXB~9#K`MCaKFbDLOsLMraU!#nW)vk*iue3wIrvv;oWo4%!Q= z3##ZCv=s2#5qzqt=VZZ?dTug)r<#ekQScPIxKsEwVZ|!dcvFJ?#d)+4jupF5ZlE|% zrK0fnVkc*df9%*&uu=&5&OEMMFGv>q=(92cTb!F{1Wr2hXd?_bcY{!p4pEf`1lQZ@ z4o<+k$}%vz$58y1n@3K*$E-Gx2(~;Ok*tSEIc)J%dAc}3(o|Mzl137j!v}FAIR$_4 zxU7SALFthCYGNX8;7WLE0e^{EZN}02OYm-0lA-4D{ zX%wubE^A@@Vwm9UjdLcU9yu0x5jhdNAi42FDV1|rQ^Jv67$|koLAZrA&YhRHCa#%r zB1y$8AS4}^U<-N|zeg#0DPf~+@$$48Ui1Ey&cOaMo}PkG*#X)Cbk$MSwruEJ^&QnR zD@?8WhRT==YkV(IoOBL~4kOY2=r8$(GTD?#1fM^2%m278Qcy*3c!@8^cfQW3*fY)l~`ij0hK;@ prP2r^mG1fEx8dE6l`*hBEYeTF8t@s6t7U8rY!CS8BXBIR{J+XL6f6J$ delta 3091 zcmZ`*eQZJ z6tN`=ftkfJ-crukMyIKvP1kno+O$!p5K)#)Q{8QJqX?y>Vw#&zM#`U`_UM8u6(tBf z^#otbQM9ZiMn$J6a`AIkDY`Qt%8jg?;}qNo{Z!x^GhU4uuSR&C{(~PbReXj^MY%By zF|OV9|01R`5mTVkw43?vJ?HH&9O>WKdf_)y`l!8|9tlxOFsFcO=#?xLMKLO7Cw zkMf#p*r2k-DT;Dai*->JL@7Qd%32=Q6rRc#V0*sa(5gZ;kU;b(q8%z!3-2L%8qqEl zng>@AokjGZ3e`c0PJm*a-Y}>__3#ZuBZv;E&{fcjXb++zDwK!cBl-rS6DrgM|3vf> zqUTho1q=lO=nM3QlnNCffarz-{pi`Ui`rwx()oXkCrPo;;^E#!soN1w82WK9jF+HqI8i^pf{B1xPe}SB*kE?i7I@k$ z7~WFwG>UW_4w>B>k{IRiZ6(4N28`fRBJ5B+Q_Qm&eZuj!i{W@E6^^}+fxl$%Zn$i2 zp|en9SxfiAc1zLvT?ogL>GnlQibuEqTaw1v{>1TYQ4AZ=FjJ#p(D4p5$3u(Z*c37n zFk*2(T&#F;570G=VdgHoSBqSDQTOAmf}i!0eXtp_8pkVjnunH`q*CFisbR{D7il-=X>B~>@EE> zboy>Ggx5nd^cl;;Kel3(eu}}d(5K-9+hCKpEymdy9FF}R2X2&q>i`RT4`Yn)WR^sI zrxNztENoz2+Q2r`8O#FquV*k`bV8>5jZtltqPj12;x1F201w~~=)B^Qo zZu$&tE89c|;bfVh9l%~qqmyM%=HoCc`Ew=_NrX&g?`Yj+(>-z zml}_4xKvad#K%Ee*wP-BFi&DT5F-;)lu(x)<&6}B$ES+5i9QM}%v`(Ny zV5{@kya6$5mgSy|&pGHsA153@pMg?Qw&CR@m$O(?!joUZWSxf&!*#5^;PMH!?29eq zNDP<-gqZPVv<0nS{gXPhQo=^t?-QsIPWV2iQ?R#QpgxGz@5kP0!%w-(Yv5SJ)7(2& zxY4kY8!CbI{^!v2wqM}pR>NQY)wBW@{Ot&BYxM9*vnY2iXBf7wL#JPWk;d?-ah)k= z)F0SMVS>vU9eT8b;(}7q!?)%tlvX@4Sh)+6k2>(-X5=GzqKrf`dC&m;qDME7K?mTJ z=+}*9v@uu^{Y!~s&6kO|NWowq?SjdmhtDqmAg|bP8JavxPwctX3fc_8CXX(gzdkt7 zw28h1lZa)fZx|Mu{5qpslnF*y*X-A2AJVvBsAU(`3#U-aE=nUTH2aqlz8s%StXzcP b;}RxnFyz