Skip to content

Instantly share code, notes, and snippets.

@alexanderkent
alexanderkent / CVE-2016-0777
Created January 16, 2016 15:53
CVE-2016-0777 roaming openssh exploit
http://pastebin.com/T2zjAdZ5
A quick warning: this fake exploit going around is entirely malicious, and will not exploit the bug, but instead do
bad things to your machine.
If you actually read it, on lines 59 and 60, you'll see this:
(*(void(*)())shellcode)();
exit(1);
This runs the "shellcode" on your own box. Since it requires root to run (because, it says,
Visit the Netflix website, where each genre has its own URL
(for example, here’s the one for Documentaries: www.netflix.com/browse/genre/6839).
Genre Codes A-Z:
Action & Adventure: 1365
Action Comedies: 43040
Action Sci-Fi & Fantasy: 1568