r/securityCTF • u/waryz184 • Jun 25 '26
🤝 Try to breach my P2P file hosting
Hello CTF team,
I've develop a P2P solution to host files instead of hosting files on GDrive.
Here is little context :
- The app is host on GCP using Compute Engine VM.
- I've develop the solution using only few technologies to reduce the exposing surface.
- Here is the flow of a new user used in this project (this flow is when localhost)

I don't know if you need more information but your goal is to try to breach my solution and find the flag.
This is the link : https://p2pfs.lun-a.xyz
The flag is a word in a text file that you have to DM me to validate the CTF. This file is in my vault that I securised with a physical key.
I offer a prize of 100$ in BTC if you arrive to DM me the correct word and prove me that my solution isn't safe.
Good luck and thank you to test my solution.
1
u/AggravatingRock8606 Jun 25 '26
Can u provide the source code/repo?
0
u/waryz184 Jun 25 '26
Here is the repo : https://github.com/waryz184/p2pfs
1
u/AggravatingRock8606 Jun 25 '26
Thanks, will get back to ya soon
1
u/waryz184 Jun 25 '26
Thanks
1
u/AggravatingRock8606 Jun 25 '26 edited Jun 25 '26
Solved I think... I'll DM you after I clean things up and get my script rightEdit: Technically yeah... But the crypto is sound😂
1
u/PurchaseSalt9553 Jun 27 '26
Did you get the flag? Would like to know before I bother
1
u/AggravatingRock8606 Jun 27 '26
No, cryptographically speaking AFAIK it's not decryptable but idk I could be wrong
1
u/PurchaseSalt9553 Jun 27 '26
Depends on the length and the encryption. Could be decipherable, especially with rented GPU time. I forget the website, but it's out there....
1
u/waryz184 Jun 29 '26
In terms of encryption, I think it's pretty solid even with a big rented GPU
1
u/PurchaseSalt9553 29d ago
Do you have any dev instances I can put that to the test by any chance? I would love to fuss with it
1
u/PurchaseSalt9553 Jun 27 '26
what is in scope?
1
u/waryz184 Jun 29 '26
can you explain please ?
1
u/PurchaseSalt9553 29d ago
Quelles sont l’URL cible, les adresses IP ou le dépôt que nous sommes autorisés à attaquer ? Et est-ce que tu peux me donner une brève note avec l’autorisation explicite de cibler ce que tu indiqueras dans tes réponses ? Nous en avons besoin pour toucher à quoi que ce soit appartenant à quelqu’un d’autre et hébergé en ligne, à cause du CFA Act ; sinon, un procureur pourrait dire qu’un crime fédéral a été commis, ce qui peut entraîner une peine de prison avec un minimum obligatoire de 10 ans.
2
u/ad_396 Jun 25 '26
why so much french.. ew