Sinisterly
Tutorial "Shellshock" bash exploit + temporary patch - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Tutorial "Shellshock" bash exploit + temporary patch (/Thread-Tutorial-Shellshock-bash-exploit-temporary-patch)

Pages: 1 2 3 4


RE: "Shellshock" bash exploit + temporary patch - Adorapuff - 09-25-2014

Also, this seems to affect more than bash, as the test code I posted worked on Fish.


RE: "Shellshock" bash exploit + temporary patch - Eclipse - 09-25-2014

(09-25-2014, 05:59 PM)Reiko Wrote: You have a router in your house. If it's not a cheap piece of trash VxWorks router, you're vulnerable too.

Well then fuck. It's a D-Link running default firmware. I really need an upgrade...

EDIT: Nice addition to OP. Tongue


RE: "Shellshock" bash exploit + temporary patch - Reiko - 09-25-2014

(09-25-2014, 05:57 PM)Adorapuff Wrote: Do you mean router or modem? Because my router connects to my modem which connects to the ISP from what I understand. DD-WRT is only accessible from my local net as I it is running on a router.

The router is making DHCP requests. A malicious or compromised ISP, or even a middleman, could exploit this bug through a crafted response to those.


RE: "Shellshock" bash exploit + temporary patch - Dyme - 09-25-2014

Here's the lame piece of shit I made yesterday when this was disclosed. Uses socat to listen for a chippy shell: http://goo.gl/3DHqgt

Spoiler:
[Image: yduND1o.png]



RE: "Shellshock" bash exploit + temporary patch - Reiko - 09-25-2014

(09-25-2014, 06:45 PM)Dyme Wrote: Here's the lame piece of shit I made yesterday when this was disclosed. Uses socat to listen for a chippy shell

Spoiler:
[Image: yduND1o.png]

Change User-Agent to some random, arbitrary header so you have less chance of getting logged. Otherwise this looks good.


RE: "Shellshock" bash exploit + temporary patch - Dyme - 09-25-2014

(09-25-2014, 06:47 PM)Reiko Wrote: Change User-Agent to some random, arbitrary header so you have less chance of getting logged. Otherwise this looks good.

Done.


RE: "Shellshock" bash exploit + temporary patch - Reiko - 09-25-2014

Aaaaand we're fucked
[Image: IIzBrkx.jpg]


RE: "Shellshock" bash exploit + temporary patch - Kizaru - 09-25-2014

(09-25-2014, 08:46 PM)Reiko Wrote: Aaaaand we're fucked
-snip-

Annnd im scared. Might as well not be on the internet for a while~


RE: "Shellshock" bash exploit + temporary patch - Alan Turing - 09-25-2014

Interesting thing, pretty fucked up.


RE: "Shellshock" bash exploit + temporary patch - OldWolf - 09-26-2014

there is a iptables patch here
http://cultofthedyingsun.wordpress.com/2014/09/24/shellshock-exploit-snort-rule/

###################DUMP###################
Initially (pre-patching bash), I thought of a possible way to mitigate this via an iptables rule, using the –string parameter, however, i haven’t fully tested it yet, but i think you’ll get the idea:

iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP
I also wrote a quick snort rule to detect shellshock exploit attempts:
blah
###################DUMP###################