Shellshock CGI
Overview
Discovery
Find CGI Scripts
gobuster dir -u http://TARGET/cgi-bin/ -w /usr/share/wordlists/dirb/small.txt -x cgi,sh,pl
# Common CGI paths
/cgi-bin/
/cgi-sys/
/cgi-mod/Common Vulnerable Scripts
/cgi-bin/test.cgi
/cgi-bin/status
/cgi-bin/admin.cgi
/cgi-bin/test-cgi
/cgi-bin/printenvTest for Vulnerability
Via User-Agent Header
Via Cookie Header
Via Referer Header
Exploitation
Command Execution
Reverse Shell
Alternative Reverse Shell
Nmap Script
Metasploit
Local Test
Last updated