RE: "Shellshock" bash exploit + temporary patch 09-26-2014, 03:41 PM
#20
there is a iptables patch here
http://cultofthedyingsun.wordpress.com/2...nort-rule/
###################DUMP###################
Initially (pre-patching bash), I thought of a possible way to mitigate this via an iptables rule, using the –string parameter, however, i haven’t fully tested it yet, but i think you’ll get the idea:
iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP
I also wrote a quick snort rule to detect shellshock exploit attempts:
blah
###################DUMP###################
http://cultofthedyingsun.wordpress.com/2...nort-rule/
###################DUMP###################
Initially (pre-patching bash), I thought of a possible way to mitigate this via an iptables rule, using the –string parameter, however, i haven’t fully tested it yet, but i think you’ll get the idea:
iptables -I INPUT -p tcp --dport 80 -m string --algo bm --string '() { :;};' -j DROP
I also wrote a quick snort rule to detect shellshock exploit attempts:
blah
###################DUMP###################


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)