forked from netspooky/BGGP
-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Labels
BGGP EntryBGGP6This issue was created during BGGP6This issue was created during BGGP6Needs VerificationThis entry needs verificationThis entry needs verification
Description
Entry Info
- Date:2026-01-15
- BGGP Challenge: 6, recycle
- Name: Charlotte Woodrow
- Contact Info: charlotte.woodrow@q3w3e3.dev
- Online Presence: q3w3e3 many places, puponsecurity on twitter
- Writeup Link: https://www.gaiaonline.com/journal/?mode=view&post_id=48177153&u=44309835 (backed up here: https://gist.github.com/q3w3e3/2c7809fa92c75c9cac9ca37ef5696ad7)
File Info
- Target File Type: Shell Script
- Target File Size: 44
- SHA256 Hash: da5aa8a5b9df86a2bb3f4c53ad645de8e6fe815894773c4dad4edb5e055e731f
File Contents
Please encode the file as Base64
YHdnZXQgYmluYXJ5LmdvbGYvNS81O2NwICIkMCIgNjtraWxsIC0xMSAkJGA=
Environment Info
Tested in macos 14.6.1 (23G93), GNU bash, version 3.2.57(1)-release (arm64-apple-darwin23), GNU Wget 1.25.0 built on darwin23.6.0.
Target Software and Version
bash, 3.2 but should work with any bash.
Environment Setup
requires: posix shell (tested in bash, should work in any posix shell), and wget (tested with 1.25)
Additional Info
Download, Replicate, Crash, Polyglot (perl, sh)
Example env/execution/verification of replication:
bggp6_3 %ls
bggp6
bggp6_3 %xxd bggp6
00000000: 6077 6765 7420 6269 6e61 7279 2e67 6f6c `wget binary.gol
00000010: 662f 352f 353b 6370 2022 2430 2220 363b f/5/5;cp "$0" 6;
00000020: 6b69 6c6c 202d 3131 2024 2460 kill -11 $$`
bggp6_3 %sh bggp6
Prepended http:// to 'binary.golf/5/5'
--2026-01-15 17:22:00-- http://binary.golf/5/5
Resolving binary.golf (binary.golf)... 185.199.111.153, 185.199.108.153, 185.199.110.153, ...
Connecting to binary.golf (binary.golf)|185.199.111.153|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: https://binary.golf/5/5 [following]
--2026-01-15 17:22:00-- https://binary.golf/5/5
Connecting to binary.golf (binary.golf)|185.199.111.153|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 58 [application/octet-stream]
Saving to: ‘5’
5 100%[================================================================================================>] 58 --.-KB/s in 0s
2026-01-15 17:22:00 (871 KB/s) - ‘5’ saved [58/58]
zsh: segmentation fault sh bggp6
bggp6_3 %cat 5
Another #BGGP5 download!! @binarygolf https://binary.golf
bggp6_3 %sha256sum 6 bggp6
da5aa8a5b9df86a2bb3f4c53ad645de8e6fe815894773c4dad4edb5e055e731f 6
da5aa8a5b9df86a2bb3f4c53ad645de8e6fe815894773c4dad4edb5e055e731f bggp6
bggp6_3 %rm 5 6
bggp6_3 %perl bggp6
Prepended http:// to 'binary.golf/5/5'
--2026-01-15 17:22:26-- http://binary.golf/5/5
Resolving binary.golf (binary.golf)... 185.199.111.153, 185.199.108.153, 185.199.110.153, ...
Connecting to binary.golf (binary.golf)|185.199.111.153|:80... connected.
HTTP request sent, awaiting response... 301 Moved Permanently
Location: https://binary.golf/5/5 [following]
--2026-01-15 17:22:26-- https://binary.golf/5/5
Connecting to binary.golf (binary.golf)|185.199.111.153|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 58 [application/octet-stream]
Saving to: ‘5’
5 100%[================================================================================================>] 58 --.-KB/s in 0s
2026-01-15 17:22:26 (1.42 MB/s) - ‘5’ saved [58/58]
zsh: segmentation fault perl bggp6
bggp6_3 %cat 5
Another #BGGP5 download!! @binarygolf https://binary.golf
bggp6_3 %sha256sum 6 bggp6
da5aa8a5b9df86a2bb3f4c53ad645de8e6fe815894773c4dad4edb5e055e731f 6
da5aa8a5b9df86a2bb3f4c53ad645de8e6fe815894773c4dad4edb5e055e731f bggp6
bggp6_3 %
NOTE: If this is an update to an existing entry, please include a link to your entry below this text. Reminder that authors can only update an entry once during BGGP.
Metadata
Metadata
Assignees
Labels
BGGP EntryBGGP6This issue was created during BGGP6This issue was created during BGGP6Needs VerificationThis entry needs verificationThis entry needs verification