Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is investigating an alert from a web application firewall (WAF) indicating a potential attack. The WAF logs show multiple requests to a web application where the 'User-Agent' header contains a string like '() { :;}; /bin/bash -c "echo pwned"'. This pattern is associated with attempts to execute arbitrary commands on the server. What type of vulnerability is being exploited?
- AShellshock (Bash vulnerability)
- BCross-Site Scripting (XSS)
- CSQL injection
- DDirectory traversal
Show answer & explanationAnswer & explanation
Correct answer: A. Shellshock (Bash vulnerability)
The string '() { :;}; /bin/bash -c "echo pwned"' is the signature payload for the Shellshock vulnerability (CVE-2014-6271), which exploited a flaw in the Bash shell. This flaw allowed attackers to execute arbitrary shell commands by appending specially crafted strings to environment variables, often passed via HTTP headers like User-Agent. The WAF alert correctly identified this specific command injection attempt.
Why the other options are wrong
- B. XSS injects client-side scripts into web pages, not server-side shell commands.
- C. SQL injection targets databases with SQL code, not shell commands in HTTP headers.
- D. Directory traversal attempts to access files outside the web root and does not involve injecting shell commands into HTTP headers.
Shellshock (Bash Vulnerability)
A critical vulnerability (CVE-2014-6271) in the Bash shell that allowed attackers to execute arbitrary commands by appending specially crafted strings to environment variable definitions.
- Impacted web servers, DHCP clients, SSH servers, and other services using Bash.
- Exploited by injecting code into HTTP headers (e.g., User-Agent, Referer).
- Allowed for remote code execution (RCE) without authentication.
Memory trick: Command injections trick systems into running bad orders.