Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial "Shellshock" bash exploit + temporary patch filter_list
Author
Message
RE: "Shellshock" bash exploit + temporary patch #11
Also, this seems to affect more than bash, as the test code I posted worked on Fish.
#MakeSinisterlySexyAgain

Reply

RE: "Shellshock" bash exploit + temporary patch #12
(09-25-2014, 05:59 PM)Reiko Wrote: You have a router in your house. If it's not a cheap piece of trash VxWorks router, you're vulnerable too.

Well then fuck. It's a D-Link running default firmware. I really need an upgrade...

EDIT: Nice addition to OP. Tongue
(This post was last modified: 09-25-2014, 06:02 PM by Eclipse.)

Reply

RE: "Shellshock" bash exploit + temporary patch #13
(09-25-2014, 05:57 PM)Adorapuff Wrote: Do you mean router or modem? Because my router connects to my modem which connects to the ISP from what I understand. DD-WRT is only accessible from my local net as I it is running on a router.

The router is making DHCP requests. A malicious or compromised ISP, or even a middleman, could exploit this bug through a crafted response to those.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

[+] 1 user Likes Reiko's post
Reply

RE: "Shellshock" bash exploit + temporary patch #14
Here's the lame piece of shit I made yesterday when this was disclosed. Uses socat to listen for a chippy shell: http://goo.gl/3DHqgt

Spoiler:
[Image: yduND1o.png]

Reply

RE: "Shellshock" bash exploit + temporary patch #15
(09-25-2014, 06:45 PM)Dyme Wrote: Here's the lame piece of shit I made yesterday when this was disclosed. Uses socat to listen for a chippy shell

Spoiler:
[Image: yduND1o.png]

Change User-Agent to some random, arbitrary header so you have less chance of getting logged. Otherwise this looks good.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: "Shellshock" bash exploit + temporary patch #16
(09-25-2014, 06:47 PM)Reiko Wrote: Change User-Agent to some random, arbitrary header so you have less chance of getting logged. Otherwise this looks good.

Done.

Reply

RE: "Shellshock" bash exploit + temporary patch #17
Aaaaand we're fucked
[Image: IIzBrkx.jpg]
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: "Shellshock" bash exploit + temporary patch #18
(09-25-2014, 08:46 PM)Reiko Wrote: Aaaaand we're fucked
-snip-

Annnd im scared. Might as well not be on the internet for a while~

Reply

RE: "Shellshock" bash exploit + temporary patch #19
Interesting thing, pretty fucked up.
Unleash the lead from my pistol into my head bumpin' crystal

Reply

RE: "Shellshock" bash exploit + temporary patch #20
there is a iptables patch here
http://cultofthedyingsun.wordpress.com/2...nort-rule/

###################DUMP###################
Initially (pre-patching bash), I thought of a possible way to mitigate this via an iptables rule, using the –string parameter, however, i haven’t fully tested it yet, but i think you’ll get the idea:

iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP
I also wrote a quick snort rule to detect shellshock exploit attempts:
blah
###################DUMP###################

Reply