-
Notifications
You must be signed in to change notification settings - Fork 13
Description
Entry Info
- Date:2026-01-15
- BGGP Challenge: 6, recycle
- Name: Charlotte Woodrow
- Contact Info: charlotte.woodrow@q3w3e3.dev
- Online Presence: q3w3e3 many places, puponsecurity on twitter
- Writeup Link: https://www.gaiaonline.com/journal/?mode=view&post_id=48177153&u=44309835 (backed up here: https://gist.github.com/q3w3e3/2c7809fa92c75c9cac9ca37ef5696ad7)
File Info
- Target File Type: Shell Script
- Target File Size: 24
- SHA256 Hash: e9db3ff2917ec1d2e6e88ed611d197a45667915f30c15ce4ba8374cc27a29a8e
File Contents
Please encode the file as Base64
JDA7Y3AgIiQwIiA2O2tpbGwgLTExICQk
Environment Info
Tested in macos 14.6.1 (23G93), GNU bash, version 3.2.57(1)-release (arm64-apple-darwin23), curl 8.13.0 (aarch64-apple-darwin23.6.0) libcurl/8.13.0 OpenSSL/3.5.4 zlib/1.3.1 brotli/1.2.0 zstd/1.5.7 libidn2/2.3.8 libpsl/0.21.5 nghttp2/1.68.0
Target Software and Version
bash, 3.2 but should work with any bash.
Environment Setup
requires: posix shell (tested in bash, should work in any posix shell), and curl (tested with 8.13, should work with relatively old, not sure how old),
this file must be named curl -L binary.golf --request-target 5%2f5, this can be done with touch "curl -L binary.golf --request-target 5%2f5"
Additional Info
Download, Replicate, Crash.
Example env/execution/verification of replication:
bggp6 %ls
curl -L binary.golf --request-target 5%2f5
bggp6 %sh curl\ -L\ binary.golf\ --request-target\ 5%2f5
Another #BGGP5 download!! @binarygolf https://binary.golf
zsh: segmentation fault sh curl\ -L\ binary.golf\ --request-target\ 5%2f5
bggp6 %sha256sum *
e9db3ff2917ec1d2e6e88ed611d197a45667915f30c15ce4ba8374cc27a29a8e 6
e9db3ff2917ec1d2e6e88ed611d197a45667915f30c15ce4ba8374cc27a29a8e curl -L binary.golf --request-target 5%2f5
NOTE: If this is an update to an existing entry, please include a link to your entry below this text. Reminder that authors can only update an entry once during BGGP.