-
Notifications
You must be signed in to change notification settings - Fork 379
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
ee47c8a
commit ed5717c
Showing
365 changed files
with
1,562 additions
and
331 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes
File renamed without changes
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
github: wreiske | ||
custom: https://www.paypal.me/wreiske |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
shellshocker | ||
============ | ||
|
||
The code behind https://shellshocker.net/ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,214 @@ | ||
<!DOCTYPE html> | ||
<html lang="en"> | ||
|
||
<head> | ||
<meta charset="utf-8"> | ||
<meta http-equiv="X-UA-Compatible" content="IE=edge"> | ||
<meta name="viewport" content="width=device-width, initial-scale=1"> | ||
<meta name="description" content="Shellshock Statistics"> | ||
<meta name="keywords" content="Shellshock,BASH,vulnerability,exploit,zeroday,heartbleed,linux,osx,sh,gnu,fix,ubuntu,centos,redhat,shellshocker,upgrade,4.3,apache,nginx,cgi,mavericks,yosemite,fedora,test,tester,logo,bashbleed,bashbug,vulnerable,hack,aftershock,check,checker,patcher,patch,stats,one liner,CVE-2014-6271,CVE-2014-7169,CVE-2014-7186,CVE-2014-7187,CVE-2014-6277,CVE-2014-6278"> | ||
<meta name="author" content="@williamreiske"> | ||
<link rel="icon" href="shellshocker.png"> | ||
<meta property="og:image" content="https://shellshocker.net/shellshocker.png" /> | ||
|
||
<title>Shellshock :: About Us</title> | ||
|
||
<!-- Bootstrap core CSS --> | ||
<link href="//cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/css/bootstrap.min.css" rel="stylesheet"> | ||
<!-- Bootstrap theme --> | ||
<link href="//cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/css/bootstrap-theme.min.css" rel="stylesheet"> | ||
<link href="//cdnjs.cloudflare.com/ajax/libs/font-awesome/4.2.0/css/font-awesome.min.css" rel="stylesheet"> | ||
<link href="/theme.min.css?rev=92914-300pm" rel="stylesheet"> | ||
|
||
<!-- HTML5 shim and Respond.js IE8 support of HTML5 elements and media queries --> | ||
<!--[if lt IE 9]> | ||
<script src="https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js"></script> | ||
<script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script> | ||
<![endif]--> | ||
</head> | ||
|
||
<body role="document"> | ||
|
||
<!-- Fixed navbar --> | ||
<div class="navbar navbar-inverse navbar-fixed-top" role="navigation"> | ||
<div class="container"> | ||
<div class="navbar-header"> | ||
<button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target=".navbar-collapse"> | ||
<span class="sr-only">Toggle navigation</span> | ||
<span class="icon-bar"></span> | ||
<span class="icon-bar"></span> | ||
<span class="icon-bar"></span> | ||
</button> | ||
<a class="navbar-brand" href="#"> | ||
<img border="0" height="20" src="/shellshocker.png" alt="#Shellshocker" /> #Shellshocker</a> | ||
</div> | ||
<div class="navbar-collapse collapse"> | ||
<ul class="nav navbar-nav"> | ||
<li> | ||
<a href="/">Home</a> | ||
</li> | ||
<li> | ||
<a href="/#websitetest">Website Tester</a> | ||
</li> | ||
<li> | ||
<a href="/#systemtest">System Tester</a> | ||
</li> | ||
<li> | ||
<a href="/#fix">The Fix</a> | ||
</li> | ||
<li> | ||
<a href="/#api">API</a> | ||
</li> | ||
<li> | ||
<a href="/#comment">Comment</a> | ||
</li> | ||
<li> | ||
<a href="/sitestats">Stats</a> | ||
</li> | ||
<li class="active"> | ||
<a href="/about">About Us</a> | ||
</li> | ||
</ul> | ||
</div> | ||
<!--/.nav-collapse --> | ||
</div> | ||
</div> | ||
|
||
<div class="container theme-showcase" role="main"> | ||
<script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script> | ||
<!-- shellshocker.net --> | ||
<ins class="adsbygoogle" style="display:block" data-ad-client="ca-pub-1808672741905857" data-ad-slot="8928803123" data-ad-format="auto"></ins> | ||
<script> | ||
(adsbygoogle = window.adsbygoogle || []).push({}); | ||
</script> | ||
<br /> | ||
<div class="panel panel-default"> | ||
<div class="panel-heading"> | ||
<h3 class="panel-title"><i class="fa fa-users"></i> About Us</h3> | ||
</div> | ||
<div class="panel-body"> | ||
<div class="container-fluid"> | ||
<div class="col-xs-6 col-md-2"> | ||
<p><a href="https://twitter.com/williamreiske" class="twitter-follow-button" data-show-count="false" data-dnt="true">Follow @williamreiske</a> | ||
<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0],p=/^http:/.test(d.location)?'http':'https';if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src=p+'://platform.twitter.com/widgets.js';fjs.parentNode.insertBefore(js,fjs);}}(document, 'script', 'twitter-wjs');</script></p> | ||
<p><img src="/me.jpg" style="border: 1px solid #000;" class="img-rounded" width="128" alt=""/></p> | ||
</div> | ||
<div class="col-xs-6 col-md-2"> | ||
<p><a href="https://twitter.com/mieehr" class="twitter-follow-button" data-show-count="false" data-dnt="true">Follow @mieehr</a> | ||
<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0],p=/^http:/.test(d.location)?'http':'https';if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src=p+'://platform.twitter.com/widgets.js';fjs.parentNode.insertBefore(js,fjs);}}(document, 'script', 'twitter-wjs');</script></p> | ||
<p><img src="/mie.jpg" style="border: 1px solid #000;" class="img-rounded" width="128" alt=""/></p> | ||
</div> | ||
<div class="col-xs-6 col-md-2"> | ||
<p><a href="https://twitter.com/shellshockernet" class="twitter-follow-button" data-show-count="false" data-dnt="true">Follow @shellshockernet</a> | ||
<script>!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0],p=/^http:/.test(d.location)?'http':'https';if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src=p+'://platform.twitter.com/widgets.js';fjs.parentNode.insertBefore(js,fjs);}}(document, 'script', 'twitter-wjs');</script></p> | ||
<p><img src="/shellshocker.png" style="border: 1px solid #000;" class="img-rounded" width="128" alt=""/></p> | ||
</div> | ||
<div class="col-xs-12 col-md-6"> | ||
<p>This site was developed by the health IT team at <a target="_blank" href="https://www.mieweb.com/?from_shellshock">Medical Informatics Engineering</a>. When we learned about the shellshock vulnerability, our rapid response team pulled the proverbial all-nighter to protect our infrastructure. This site is intended to share what we learned, spread the word and help other individuals and organizations avoid getting "shellshocked." We encourage you to <a target="_blank" href="https://github.com/wreiske/shellshocker">contribute</a> and comment.</p> | ||
<p>-Thanks</p> | ||
<i>William Reiske, | ||
Software Engineer, | ||
Medical Informatics Engineering</i> | ||
</div> | ||
</div> | ||
</div> | ||
</div> | ||
<div class="panel panel-default"> | ||
<div class="panel-heading"> | ||
<h3 class="panel-title"><i class="fa fa-code-fork"></i> <span id="contributers_count">Contributers</span></h3> | ||
</div> | ||
<div class="panel-body"> | ||
<div class="container-fluid"> | ||
<p>Below is a list of some pretty awesome people around the world that have helped make shellshocker.net a better place for everyone. If you'd like to help out, please check out the <a target="_blank" href="https://github.com/wreiske/shellshocker">GitHub project</a>. Give it a star, fork it, do your magic, and send in a pull request. The world will thank you!</p> | ||
<span id="contributers"><i class="fa fa-spinner fa-spin"></i> Loading contributers list from GitHub.</span> | ||
</div> | ||
</div> | ||
</div> | ||
|
||
<a name="comment"></a> | ||
<div class="panel panel-default"> | ||
<div class="panel-heading"> | ||
<h3 class="panel-title"><i class="fa fa-comments"></i> Comments</h3> | ||
</div> | ||
<div class="panel-body"> | ||
|
||
<div id="disqus_thread"></div> | ||
<script type="text/javascript"> | ||
/* * * CONFIGURATION VARIABLES: EDIT BEFORE PASTING INTO YOUR WEBPAGE * * */ | ||
var disqus_shortname = 'shellshocker'; // required: replace example with your forum shortname | ||
|
||
/* * * DON'T EDIT BELOW THIS LINE * * */ | ||
(function() { | ||
var dsq = document.createElement('script'); | ||
dsq.type = 'text/javascript'; | ||
dsq.async = true; | ||
dsq.src = '//' + disqus_shortname + '.disqus.com/embed.js'; | ||
(document.getElementsByTagName('head')[0] || document.getElementsByTagName('body')[0]).appendChild(dsq); | ||
})(); | ||
</script> | ||
<noscript>Please enable JavaScript to view the <a href="http://disqus.com/?ref_noscript">comments powered by Disqus.</a> | ||
</noscript> | ||
<a href="http://disqus.com" class="dsq-brlink">comments powered by <span class="logo-disqus">Disqus</span></a> | ||
</div></div> | ||
<!-- /container --> | ||
<script type="text/javascript"> | ||
var addthis_share = addthis_share || {} | ||
addthis_share = { | ||
passthrough: { | ||
twitter: { | ||
via: "shellshockernet" | ||
} | ||
} | ||
} | ||
</script> | ||
<script async src="//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js"></script> | ||
<!-- shellshocker.net --> | ||
<ins class="adsbygoogle" style="display:block" data-ad-client="ca-pub-1808672741905857" data-ad-slot="8928803123" data-ad-format="auto"></ins> | ||
<script> | ||
(adsbygoogle = window.adsbygoogle || []).push({}); | ||
</script> | ||
<p style="text-align:center"><small>Like the site? bitcoin: <a href="bitcoin:16fRZC2r4Nwn6fxMnXfPvNdJLgWpvaiVTG">16fRZC2r4Nwn6fxMnXfPvNdJLgWpvaiVTG</a></small></p> | ||
</div> | ||
<!-- Bootstrap core JavaScript | ||
================================================== --> | ||
<!-- Placed at the end of the document so the pages load faster --> | ||
<script src="//cdnjs.cloudflare.com/ajax/libs/jquery/1.11.1/jquery.min.js"></script> | ||
<script src="//cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.2.0/js/bootstrap.min.js"></script> | ||
<script type="text/javascript" src="//s7.addthis.com/js/300/addthis_widget.js#pubid=ra-5423ce5b6319e090" async></script> | ||
<!-- Piwik --> | ||
<script type="text/javascript"> | ||
var _paq = _paq || []; | ||
_paq.push(['trackPageView']); | ||
_paq.push(['enableLinkTracking']); | ||
(function() { | ||
var u="//shellshocker.net/analytics/piwik/"; | ||
_paq.push(['setTrackerUrl', u+'piwik.php']); | ||
_paq.push(['setSiteId', 1]); | ||
var d=document, g=d.createElement('script'), s=d.getElementsByTagName('script')[0]; | ||
g.type='text/javascript'; g.async=true; g.defer=true; g.src=u+'piwik.js'; s.parentNode.insertBefore(g,s); | ||
})(); | ||
</script> | ||
<noscript><p><img src="//shellshocker.net/analytics/piwik/piwik.php?idsite=1" style="border:0;" alt="" /></p></noscript> | ||
<!-- End Piwik Code --> | ||
|
||
<script> | ||
//This has to be at the end of the page because all the scripts are loaded async | ||
//https://api.github.com/repos/wreiske/shellshocker/contributors | ||
$(function(){ | ||
var jqxhr = $.getJSON("https://api.github.com/repos/wreiske/shellshocker/contributors", function(data) { | ||
$("#contributers_count").html(data.length + ' Contributers to ShellShocker.net'); | ||
$("#contributers").html('<div class="row">'); | ||
$.each(data, function( index, value ) { | ||
$("#contributers").append('<div class="col-xs-6 col-md-3"> <div class="thumbnail"><a href="'+value.html_url+'"><img src="'+value.avatar_url+'" alt="'+value.login+'"></a><div class="caption"><h3>'+value.login+'</h3><p><a target="_blank" href="'+value.html_url+'" class="btn btn-primary" role="button">GitHub</a> <a target="_blank" href="https://github.com/wreiske/shellshocker/commits?author='+value.login+'" class="btn btn-default" role="button">'+value.contributions+' contributions</a></p></div></div></div>'); | ||
|
||
}); | ||
$("#contributers").append('</div>'); | ||
}) | ||
.fail(function() { | ||
$("#contributers").html('Error loading contributers... Connection issues?'); | ||
}); | ||
}) | ||
</script> | ||
</body> | ||
|
||
</html> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,86 @@ | ||
#!/bin/sh | ||
############################################################## | ||
# This is the ShellShocker.net bash updater script. | ||
# Version 1.2! | ||
# | ||
# Are you looking at this in your web browser, and would like to apply the bash patches? | ||
# Just open up your terminal and type: | ||
# | ||
# curl https://shellshocker.net/fixbash | sh | ||
######## | ||
# REV 4: Added prefix to configure for fedora systems. | ||
# REV 5: Bumped patch to 26 from 25. | ||
# REV 6: Bumped patch to 27 from 26. | ||
# REV 7: Not using sudo when logged in as root: https://github.com/wreiske/shellshocker/pull/15 | ||
# REV 8: Updated loops to download and apply up to latest patch: https://github.com/wreiske/shellshocker/pull/17 | ||
# REV 9: Added check for gcc to be installed. | ||
######## | ||
# This script will download bash 4.3 to your home directory, extract, download patches, patch, | ||
# install patches, and install the fixed bash. | ||
# - Mac: OS X | ||
# - Linux: x86 and x86_64 systems | ||
############################################################## | ||
echo "----------------------------------------------" | ||
echo "-- WELCOME TO THE SHELLSHOCKER BASH PATCHER --" | ||
echo "----------------------------------------------" | ||
echo "--- Revision 8, 092914-4:56PM ETC ---" | ||
echo "--- Provided by https://shellshocker.net/ ---" | ||
echo "----------------------------------------------" | ||
|
||
GCC=`which gcc` | ||
PATCH=`which patch` | ||
MAKE=`which make` | ||
if [ -z "$GCC" ]; then | ||
echo "Your system does not have the GNU gcc complier installed." | ||
echo "Please install the gcc complier and then run this script again." | ||
exit 1 | ||
fi | ||
if [ -z "$PATCH" ]; then | ||
echo "Your system does not have the GNU patch tool installed." | ||
echo "Please install the patch tool and then run this script again." | ||
exit 1 | ||
fi | ||
if [ -z "$MAKE" ]; then | ||
echo "Your system does not have the GNU make tool installed." | ||
echo "Please install the make tool and then run this script again." | ||
exit 1 | ||
fi | ||
|
||
echo "Creating folders..." | ||
cd ~/ | ||
mkdir bash-shellshocker | ||
cd bash-shellshocker | ||
echo "Downloading Bash..." | ||
wget -N https://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz | ||
echo "Downloading Bash patches..." | ||
i=0 | ||
while [ true ]; do i=`expr $i + 1`; wget -N https://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-$(printf '%03g' $i); if [ $? -ne 0 ]; then break; fi; done | ||
echo "Extracting bash from tar.gz..." | ||
tar zxvf bash-4.3.tar.gz | ||
cd bash-4.3 | ||
echo "Applying Patches..." | ||
for p in ../bash43-[0-9][0-9][0-9]; do patch -p0 < $p; done | ||
|
||
echo "Ready to install. Configuring..." | ||
./configure --prefix=/usr/local | ||
echo "Running make" | ||
make | ||
if [ `id -u` -eq 0 ] | ||
then | ||
echo "Running make install" | ||
make install | ||
cp -f /usr/local/bin/bash /bin/bash | ||
else | ||
echo "Running make install (You may need to type your sudo password here)" | ||
sudo make install | ||
sudo cp -f /usr/local/bin/bash /bin/bash | ||
fi | ||
|
||
echo "----------------------------------------------" | ||
curl --silent https://shellshocker.net/shellshock_test.sh | bash | ||
echo "Script provided by https://shellshocker.net/" | ||
echo "Please go leave a comment and let us know if this script worked for you!" | ||
echo "Follow us on twitter too, https://twitter.com/shellshockernet" | ||
echo "Send issue requests to https://github.com/wreiske/shellshocker/issues" | ||
echo "Want to help make shellshocker better? Contribute @ https://github.com/wreiske/shellshocker/" | ||
echo "-Thanks" |
Oops, something went wrong.