18. Attacking CPI Applications Shellshock
1. Vulnerability Overview
CVE-2014-6271 - Shellshock
2. Enumeration
Discover CGI Scripts (Gobuster)
gobuster dir -u http://10.129.204.231/cgi-bin/ -w /usr/share/wordlists/dirb/small.txt -x cgiVerify CGI Script Accessibility (cURL)
curl -i http://10.129.204.231/cgi-bin/access.cgi3. Exploitation
Confirm Vulnerability (cURL)
Execute a Reverse Shell (cURL)
Set Up a Netcat Listener
4. Mitigation
Update Bash
Firewalling
Decommission Vulnerable Hosts
5. Key Takeaways
6. Commands Summary
Last updated