Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial "Shellshock" bash exploit + temporary patch filter_list
Author
Message
RE: "Shellshock" bash exploit + temporary patch #21
(09-25-2014, 08:46 PM)Reiko Wrote: Aaaaand we're fucked
Img

Even moar fucked https://github.com/rapid7/metasploit-fra.../pull/3891

Reply

RE: "Shellshock" bash exploit + temporary patch #22
(09-26-2014, 03:45 PM)Dyme Wrote: Even moar fucked https://github.com/rapid7/metasploit-fra.../pull/3891

It belongs to the Skildren now... :p
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

Reply

RE: "Shellshock" bash exploit + temporary patch #23
(09-26-2014, 05:13 PM)roger_smith Wrote: It belongs to the Skildren now... :p

Even worse...

http://farlight.org/index.html?file=plat...Advisory=0

Now anyone with the ability to install pnscan and run a Perl script will be mass pwning. RIP in peace, hacking community.

Reply

RE: "Shellshock" bash exploit + temporary patch #24
(09-26-2014, 05:13 PM)roger_smith Wrote: It belongs to the Skildren now... :p

That just made my day.

[+] 1 user Likes Eclipse's post
Reply

RE: "Shellshock" bash exploit + temporary patch #25
(09-26-2014, 05:38 PM)Dyme Wrote: Even worse...

http://farlight.org/index.html?file=plat...Advisory=0

Now anyone with the ability to install pnscan and run a Perl script will be mass pwning. RIP in peace, hacking community.
What the fuck was this guy trying to achieve making tools like this and releasing them for everyone to use. The fact he includes the scanner in the description of the exploit makes it soo much worse.
#MakeSinisterlySexyAgain

Reply

RE: "Shellshock" bash exploit + temporary patch #26
Uh... wat?

[Image: S2OkreG.png]
[Image: BXqGARG.png]

Reply

RE: "Shellshock" bash exploit + temporary patch #27
(09-27-2014, 01:11 AM)Equinox Wrote: Uh... wat?

[Image: S2OkreG.png]

Unless there's a malicious DHCP server on a network you're trying to connect to, you're fine for the moment. It's more dangerous to people running remotely accessible systems.

Update as soon as possible anyway.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: "Shellshock" bash exploit + temporary patch #28
For once, on this VERY rare occasion, Windows/Windows Server is safe.

EDIT: This exploit's been around since the 90's?

Reply

RE: "Shellshock" bash exploit + temporary patch #29
(09-27-2014, 01:14 AM)Reiko Wrote: Unless there's a malicious DHCP server on a network you're trying to connect to, you're fine for the moment. It's more dangerous to people running remotely accessible systems.

Update as soon as possible anyway.

Ah, okay, was a little confused for second (t'was on my personal computer).
[Image: BXqGARG.png]

Reply

RE: "Shellshock" bash exploit + temporary patch #30
(09-26-2014, 03:41 PM)OldWolf Wrote: iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP

X-Random-HTTP-Header: () { fake function all this is ignored;}; your filter is bypassed

Sorry, it's not that easy.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

[+] 1 user Likes Reiko's post
Reply