![]() |
|
Tutorial "Shellshock" bash exploit + temporary patch - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Tutorial "Shellshock" bash exploit + temporary patch (/Thread-Tutorial-Shellshock-bash-exploit-temporary-patch) |
RE: "Shellshock" bash exploit + temporary patch - Dyme - 09-26-2014 (09-25-2014, 08:46 PM)Reiko Wrote: Aaaaand we're fucked Even moar fucked https://github.com/rapid7/metasploit-framework/pull/3891 RE: "Shellshock" bash exploit + temporary patch - roger_smith - 09-26-2014 (09-26-2014, 03:45 PM)Dyme Wrote: Even moar fucked https://github.com/rapid7/metasploit-framework/pull/3891 It belongs to the Skildren now... :p RE: "Shellshock" bash exploit + temporary patch - Dyme - 09-26-2014 (09-26-2014, 05:13 PM)roger_smith Wrote: It belongs to the Skildren now... :p Even worse... http://farlight.org/index.html?file=platforms/oday/cpanelpwn.pl&name=cpanel---remote---exploit&credit=iskandar&id=500015&isAdvisory=0 Now anyone with the ability to install pnscan and run a Perl script will be mass pwning. RIP in peace, hacking community. RE: "Shellshock" bash exploit + temporary patch - Eclipse - 09-26-2014 (09-26-2014, 05:13 PM)roger_smith Wrote: It belongs to the Skildren now... :p That just made my day. RE: "Shellshock" bash exploit + temporary patch - Adorapuff - 09-26-2014 (09-26-2014, 05:38 PM)Dyme Wrote: Even worse...What the fuck was this guy trying to achieve making tools like this and releasing them for everyone to use. The fact he includes the scanner in the description of the exploit makes it soo much worse. RE: "Shellshock" bash exploit + temporary patch - Equinox - 09-27-2014 Uh... wat?
RE: "Shellshock" bash exploit + temporary patch - Reiko - 09-27-2014 (09-27-2014, 01:11 AM)Equinox Wrote: Uh... wat? Unless there's a malicious DHCP server on a network you're trying to connect to, you're fine for the moment. It's more dangerous to people running remotely accessible systems. Update as soon as possible anyway. RE: "Shellshock" bash exploit + temporary patch - Silent Reaper - 09-27-2014 For once, on this VERY rare occasion, Windows/Windows Server is safe. EDIT: This exploit's been around since the 90's? RE: "Shellshock" bash exploit + temporary patch - Equinox - 09-27-2014 (09-27-2014, 01:14 AM)Reiko Wrote: Unless there's a malicious DHCP server on a network you're trying to connect to, you're fine for the moment. It's more dangerous to people running remotely accessible systems. Ah, okay, was a little confused for second (t'was on my personal computer). RE: "Shellshock" bash exploit + temporary patch - Reiko - 09-27-2014 (09-26-2014, 03:41 PM)OldWolf Wrote: iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP X-Random-HTTP-Header: () { fake function all this is ignored;}; your filter is bypassed Sorry, it's not that easy. |