Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/352926/shellshock_crawler
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersExploitationInformation GatheringWeb Security
GitHub352926/shellshock_crawler

shellshock_crawler

Using google to scan sites for "ShellShock" (CVE-2014-6271)

View Repository
211 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Prerequisite

  1. sudo pip install shell
  2. install google python search. https://github.com/MarioVilas/google

Run

I use google to search first 1000 sites and try to get the /etc/passwd After tesing, there are many many many host that can be rooted!!!! By the way, this is only a proto, it has false positives.

Output like this: if second field is !!!, then You Can Get SHELL!

root@kitploit:~
$ python shellshock.py
0 --- http://nomad3.ncep.noaa.gov/cgi-bin/pdisp_sst.sh
1 --- http://nomad5.ncep.noaa.gov/cgi-bin/pdisp_gfs.sh?ctlfile=gfs_00z.ctl&povlp=noovlp&ptype=map&dir

References

http://vonnyfly.github.io/

https://www.invisiblethreat.ca/2014/09/cve-2014-6271/

Download Tool