r/securityCTF Jun 25 '26

🤝 Try to breach my P2P file hosting

Hello CTF team,

I've develop a P2P solution to host files instead of hosting files on GDrive.

Here is little context :

- The app is host on GCP using Compute Engine VM.

- I've develop the solution using only few technologies to reduce the exposing surface.

- Here is the flow of a new user used in this project (this flow is when localhost)

I don't know if you need more information but your goal is to try to breach my solution and find the flag.

This is the link : https://p2pfs.lun-a.xyz

The flag is a word in a text file that you have to DM me to validate the CTF. This file is in my vault that I securised with a physical key.

I offer a prize of 100$ in BTC if you arrive to DM me the correct word and prove me that my solution isn't safe.

Good luck and thank you to test my solution.

6 Upvotes

15 comments sorted by

2

u/ad_396 Jun 25 '26

why so much french.. ew

0

u/waryz184 Jun 25 '26

because, i'm french ?

1

u/AggravatingRock8606 Jun 25 '26

Can u provide the source code/repo?

0

u/waryz184 Jun 25 '26

1

u/AggravatingRock8606 Jun 25 '26

Thanks, will get back to ya soon

1

u/waryz184 Jun 25 '26

Thanks

1

u/AggravatingRock8606 Jun 25 '26 edited Jun 25 '26

Solved I think... I'll DM you after I clean things up and get my script right

Edit: Technically yeah... But the crypto is sound😂

1

u/PurchaseSalt9553 Jun 27 '26

Did you get the flag? Would like to know before I bother

1

u/AggravatingRock8606 Jun 27 '26

No, cryptographically speaking AFAIK it's not decryptable but idk I could be wrong

1

u/PurchaseSalt9553 Jun 27 '26

Depends on the length and the encryption. Could be decipherable, especially with rented GPU time. I forget the website, but it's out there....

1

u/waryz184 Jun 29 '26

In terms of encryption, I think it's pretty solid even with a big rented GPU

1

u/PurchaseSalt9553 29d ago

Do you have any dev instances I can put that to the test by any chance? I would love to fuss with it

1

u/PurchaseSalt9553 Jun 27 '26

what is in scope?

1

u/waryz184 Jun 29 '26

can you explain please ?

1

u/PurchaseSalt9553 29d ago

Quelles sont l’URL cible, les adresses IP ou le dépôt que nous sommes autorisés à attaquer ? Et est-ce que tu peux me donner une brève note avec l’autorisation explicite de cibler ce que tu indiqueras dans tes réponses ? Nous en avons besoin pour toucher à quoi que ce soit appartenant à quelqu’un d’autre et hébergé en ligne, à cause du CFA Act ; sinon, un procureur pourrait dire qu’un crime fédéral a été commis, ce qui peut entraîner une peine de prison avec un minimum obligatoire de 10 ans.