Shellshock wormable. Consequences to not patching your server are big. 10-03-2014, 01:12 PM
#1
Well fuck. Those are the only two words I had to say when I noticed what one of my friends did. The creator of masscan, Rob Graham (A friend of mine from HOPE) took masscan and turned it into a shellshock scanner. What I noticed today while checking logs was that I got scanned by it and it could have responded. Someone out there is using the same method to deliver malware to the denizens of the internet, running unpatched systems. Patch your shit already XD
If your shit says that, well you are still vulnerable (If you haven't performed a patch). A nice temp fix would be to change the symbolic route from that to:
Dash, as far as I know, isn't vulnerable to this bug. I'll be working on a small scanner in python later after packing up my shit since I have to move so expect that later on in the day. On a side note that scanner might actually turn into an exploit or something. I'll share the code with anyone who wants it ( I do love criticism so hit me with all you got :P)
*Edit: Someone should create a worm that patches Bash. Seriously.
Code:
/bin/sh -> /bin/bashIf your shit says that, well you are still vulnerable (If you haven't performed a patch). A nice temp fix would be to change the symbolic route from that to:
Code:
/bin/sh -> /bin/dashDash, as far as I know, isn't vulnerable to this bug. I'll be working on a small scanner in python later after packing up my shit since I have to move so expect that later on in the day. On a side note that scanner might actually turn into an exploit or something. I'll share the code with anyone who wants it ( I do love criticism so hit me with all you got :P)
*Edit: Someone should create a worm that patches Bash. Seriously.
(This post was last modified: 10-03-2014, 01:13 PM by Null_Byte.)




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)






















