Links32
Tag cloud
Picture wall
Daily
RSS Feed
  • RSS Feed
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filters

Links per page

  • 20 links
  • 50 links
  • 100 links

Filters

Untagged links
page 3 / 3
56 results tagged hack  ✕
shellshocker https://shellshocker.net/
Mon Sep 29 11:36:14 2014 archive.org
thumbnail

shellshocker
What is #shellshock?

Shellshock (CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187) is a vulnerability in GNU's bash shell that gives attackers access to run remote commands on a vulnerable system. If your system has not updated bash in since Tue Sep 30 2014: 1:32PM EST (See patch history), you're most definitely vulnerable and have been since first boot. This security vulnerability affects versions 1.14 (released in 1994) to the most recent version 4.3 according to NVD.

You can use this website to test if your system is vulnerable, and also learn how to patch the vulnerability so you are no longer at risk for attack.

You can test if a system is vulnerable by using the form below. Just provide a http or https url and test away!
Url

Please test responsibly. All tests details are logged. Do not test against websites that you do not have permission to test against. All data is archived in case of abuse.

Here is an example script that is vulnerable. Place this in your /cgi-bin/shockme.cgi and try hitting it with the shock tester.

!/bin/bash

echo "Content-type: text/html"
echo ""
echo "https://shellshocker.net/"

Last updated Friday September 26th at 4:43PM EST: This website tester will now wait for a valid response before returning the state of the vulnerability. If the server responds with a 500 we assume you're vulnerable and we display the response immediately without waiting. If we get any other response code we will wait 3 seconds for a reply from your server and display if you're vulnerable or not.
Testing Your System

To test your system, you can simply run this one liner below to find if you're vulnerable.

curl https://shellshocker.net/shellshock_test.sh | bash

You can view the source of shellshock_test.sh on GitHub.

If you want to test each exploit individually without running the script above, feel free! They are listed below.
Exploit 1 (CVE-2014-6271)

There are a few different ways to test if your system is vulnerable to shellshock. Try running the following command in a shell.

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

If you see "vulnerable" you need to update bash. Otherwise, you should be good to go.
Exploit 2 (CVE-2014-7169)

Even after upgrading bash you may still be vulnerable to this exploit. Try running the following code.

env X='() { (shellshocker.net)=>\' bash -c "echo date"; cat echo; rm ./echo

If the above command outputs the current date (it may also show errors), you are still vulnerable.
Exploit 3 (???)

Here is another variation of the exploit. Please leave a comment below if you know the CVE of this exploit.

env X=' () { }; echo hello' bash -c 'date'

If the above command outputs "hello", you are vulnerable.
Exploit 4 (CVE-2014-7186)

bash -c 'true <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF' ||
echo "CVE-2014-7186 vulnerable, redir_stack"

A vulnerable system will echo the text "CVE-2014-7186 vulnerable, redir_stack".
Exploit 5 (CVE-2014-7187)

(for x in {1..200} ; do echo "for x$x in ; do :"; done; for x in {1..200} ; do echo done ; done) | bash ||
echo "CVE-2014-7187 vulnerable, word_lineno"

A vulnerable system will echo the text "CVE-2014-7187 vulnerable, word_lineno".
Exploit 6 (CVE-2014-6278)

shellshocker='() { echo You are vulnerable; }' bash -c shellshocker

You shouldn't see "You are vulnerable", if you're patched you will see "bash: shellshocker: command not found"
Exploit 7 (CVE-2014-6277)

bash -c "f() { x() { ;}; x() { ;} <<a; }" 2>/dev/null || echo vulnerable

If the command outputs "vulnerable", you are vulnerable.

If you've tested your system, please leave a comment below. Don't forget to include your bash version and what OS you're running. Type bash --version for bash, and cat /etc/release for your OS.

shellshocker unix linix vulnerability hack security Bash
Indexeus http://indexeus.org/
Mon Aug 4 09:17:03 2014 archive.org

Indexeus
Account recovery, People Search & Consultancy made easy!

hack database Indexeus
Computrace http://korben.info/computrace-lojack-absolute.html
Tue May 20 16:49:28 2014 archive.org
thumbnail

Le mouchard universel présent sur les PC, Mac et appareils Android « Korben

Hack Virus NSA Backdoor Malware antivirus
Pirater, c'est voler ? http://korben.info/pirater-cest-voler.html
Thu Apr 17 14:05:48 2014 archive.org
thumbnail

« Korben

Pirater Video Hack
Heartbleed : Faille critique pour OpenSSL, correctifs disponibles en urgence | UnderNews http://www.undernews.fr/alertes-securite/heartbleed-faille-critique-pour-openssl-correctifs-disponibles-en-urgence.html
Wed Apr 9 16:06:20 2014 archive.org
thumbnail

Heartbleed : Faille critique pour OpenSSL, correctifs disponibles en urgence | UnderNews

OpenSSL Hack Faille Security debian Patch
Faille routeurs Linksys et Netgear http://korben.info/le-port-32764-ouvert-sur-les-routeurs-linksys-et-netgear-est-une-backdoor.html
Tue Mar 4 12:40:03 2014 archive.org
thumbnail

Le port 32764 ouvert sur les routeurs Linksys et Netgear est une backdoor «

Backdoor linksys Hack Port
TeamCymruSOHOPharming.pdf https://www.team-cymru.com/ReadingRoom/Whitepapers/2013/TeamCymruSOHOPharming.pdf
Tue Mar 4 09:31:57 2014 archive.org

Threat'Intelligence'Group
A Team Cymru EIS Report:
Growing Exploitation of Small
OfCice Routers Creating Serious Risks

www.team-cymru.com!

!Growing!Exploitation!of!Small!
OfCice!Routers!Creating!Serious!Risks!

Team Cymru SOHO Hack
Switch from Google's location service to Mozilla's own in Firefox http://www.ghacks.net/2014/02/03/switch-googles-location-service-mozillas-firefox/
Tue Feb 4 12:07:14 2014 archive.org
thumbnail

Switch from Google's location service to Mozilla's own in Firefox | Ghacks

Ghacks Hack Firefox
[Root Me : Hacking ] http://www.root-me.org/
Sun Jan 19 22:51:24 2014 archive.org

Bienvenue [Root Me : plateforme d'apprentissage dédiée au Hacking et à la Sécurité de l'Information]

Hack RootMe Learn
NewbieContest : Hacking http://www.newbiecontest.org/index.php?page=news
Sun Jan 19 22:49:26 2014 archive.org
thumbnail

NewbieContest : Challenge informatique francophone

Hack Web
Cracker une clé WPA facilement... http://korben.info/cracker-cle-wpa.html
Tue Jan 14 15:49:57 2014 archive.org
thumbnail

Korben

Hack Wifi WPA
Top 10 des pirates informatiques arrêtés en 2013 http://www.undernews.fr/hacking-hacktivisme/top-10-des-pirates-informatiques-arretes-en-2013.html
Tue Jan 14 13:05:45 2014 archive.org
thumbnail

Top 10 des pirates informatiques arrêtés en 2013 | UnderNews

Top10 Hacker Hack Pirates
Kali Linux Official http://docs.kali.org/category/introduction
Mon Jan 13 14:20:19 2014 archive.org

Kali Linux Official Documentation

Hack LiveCD Linux BackTrack
From a Site Compromise to Full Root Access http://blog.sucuri.net/2013/07/from-a-site-compromise-to-full-root-access-bad-server-management-part-iii.html
Thu Jan 9 11:09:44 2014 archive.org
thumbnail

– Bad Server Management – Part III | Sucuri Blog

Root Hack Secu
Exploiter puis corriger l’exploit root local sur Linux http://blogmotion.fr/systeme/root-exploit-kernel-9488
Mon Jan 6 17:58:00 2014 archive.org
thumbnail
Exploit Hack Root Linux
Failles les plus connues et exploitées sur les sites web http://www.crazyws.fr/securite/les-failles-les-plus-connues-et-exploitees-sur-les-sites-web-O560R.html
Tue Apr 30 20:40:52 2013 archive.org

~ Cr@zy WS

Failles hack Web
page 3 / 3
1639 links, including 7 private
Shaarli - The personal, minimalist, super fast, database-free, bookmarking service by the Shaarli community - Theme by kalvn