Skip to content

Latest commit

 

History

20 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

NEXUS

NEXUS is a portable and immersive CTF system where you face off against a conversational AI embodying a "final boss". Solve cybersecurity challenges while NEXUS reacts to your every move in real time.

How does it work?

NEXUS merges a classic technical CTF with an interactive narrative driven by an adaptive AI.

In practice:

  • You identify yourself via an NFC badge (Mifare Classic 1K)
  • NEXUS challenges you through multiple Dockerized challenges (web, crypto, reverse, pwn, steganography, prompt injection, lockpicking…)
  • Every action that impacts the system triggers a reaction from NEXUS: tone shift, ASCII art change, difficulty adjustment
  • A real-time scoreboard tracks your progress and ranks you against other players

The AI adapts across 3 difficulty levels and will never give you hints, it's here to defeat you.

Getting Started

Prerequisites

  • Raspberry Pi 5 (8 GB RAM)
  • Touchscreen connected via micro-HDMI
  • NFC reader + Mifare Classic 1K badges
  • Docker & Docker Compose installed on the Pi

Quickstart

Start each challenge level individually using Docker Compose:

# Level 1 — Web panel (port 5000)
docker compose -f levels/level1/docker-compose.yml up -d

# Level 2 — SSH escalation (port 2222) + SQL injection panel (port 5001)
docker compose -f levels/level2/docker-compose.yml up -d

# Level 3 — NEXUS CIPHER multi-vulnerability chain (port 5002)
docker compose -f levels/level3/docker-compose.yml up -d

Usage

Challenge structure

levels/
├── level1/          ← Web panel — XSS & SQLi (port 5000)
│   ├── Dockerfile
│   ├── docker-compose.yml
│   └── app/
├── level2/
│   ├── ssh/         ← SSH + privilege escalation (port 2222)
│   └── sqli/        ← SQL injection vault (port 5001)
├── level3/          ← NEXUS CIPHER — Path Traversal, JWT Forgery, Blind SQLi & SSTI chain (port 5002)
│   ├── Dockerfile
│   ├── docker-compose.yml
│   └── app/
└── nfc/             ← NFC badge challenges (physical, ACR122U + MIFARE Classic 1K)
    ├── level1/      ← Badge initialization
    ├── level2/      ← Encoded credential
    └── level3/      ← Time-based rolling code

Each level directory contains a writeup (.md) describing the vulnerability chain and solution.

NEXUS interaction UI & NFC backend

NEXUS itself is one screen everyone can see and two you actually type into, all served by a shared backend:

  • frontend/index.html — the NEXUS kiosk board (avatar, tone, HUD, all 6 challenges). Read-only, no buttons — nothing to click.
  • frontend/submit.html — where a player submits a flag found on one of the web levels above.
  • frontend/nfc-station.html — the NFC operator page (badge encode/verify, credential + rolling-code entry), at the physical reader.
  • nfc/ — the hardware-optional Python NFC subsystem (ACR122U/PCSC + mock reader, MIFARE Classic 1K layout, the three NFC level implementations) and nfc/api_server.py, the shared Flask backend all three pages talk to.
pip install -r nfc/requirements.txt
NEXUS_NFC_MOCK=1 python3 -m nfc.api_server   # serves all three pages + API on :5050

See docs/NFC.md for setup, architecture, and how to develop without any NFC hardware attached.

Get involved

You're invited to join this project! Check out the contributing guide.

If you're interested in how the project is organized at a higher level, please contact the current project manager.

Our PoC team ❤️

Developers


Aurélien Schirmann

Valentin Bassot

Manager


Timothée Pasteau-Berthaud

Organization

LinkedIn logo Instagram logo Twitter logo Discord logo

Website logo

🚀 Don't hesitate to follow us on our different networks, and put a star 🌟 on PoC's repositories

Made with ❤️ by PoC

About

No description, website, or topics provided.

Resources

Contributing

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages