githubEdit

Shellshock CGI

Overview

  • Affects Bash versions up to 4.3

  • Exploits improper handling of environment variables

  • Common in CGI scripts, IoT devices


Discovery

Find CGI Scripts

gobuster dir -u http://TARGET/cgi-bin/ -w /usr/share/wordlists/dirb/small.txt -x cgi,sh,pl

# Common CGI paths
/cgi-bin/
/cgi-sys/
/cgi-mod/

Common Vulnerable Scripts

/cgi-bin/test.cgi
/cgi-bin/status
/cgi-bin/admin.cgi
/cgi-bin/test-cgi
/cgi-bin/printenv

Test for Vulnerability

Via User-Agent Header

Via Referer Header


Exploitation

Command Execution

Reverse Shell

Alternative Reverse Shell


Nmap Script


Metasploit


Local Test

Last updated