Website Security & Threat Management
Inside Shellshock: How hackers are using it to exploit systems

Inside Shellshock: How hackers are using it to exploit systems

10/1/2014 · John Graham-Cumming

What this post added

This post details Cloudflare's immediate response to the Shellshock vulnerability, including the rollout of WAF protection for Pro, Business, and Enterprise customers, followed by protection for Free plan customers. It analyzes attack vectors, sources, and common exploitation techniques (e.g., arbitrary code execution via User-Agent, data exfiltration via `cat /etc/passwd` or email, reconnaissance via `ping` or `wget`). It highlights the technical details of how the vulnerability works by passing environment variables into bash and the importance of patching bash itself.

Read the original post ↗