Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Bash Shell Scripting for Pentesters

You're reading from   Bash Shell Scripting for Pentesters Master the art of command-line exploitation and enhance your penetration testing workflows

Arrow left icon
Product type Paperback
Published in Dec 2024
Last Updated in Feb 2025
Publisher Packt
ISBN-13 9781835880821
Length 402 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Steve Campbell Steve Campbell
Author Profile Icon Steve Campbell
Steve Campbell
Arrow right icon
View More author details
Toc

Table of Contents (22) Chapters Close

Preface 1. Part 1: Getting Started with Bash Shell Scripting
2. Chapter 1: Bash Command-Line and Its Hacking Environment FREE CHAPTER 3. Chapter 2: File and Directory Management 4. Chapter 3: Variables, Conditionals, Loops, and Arrays 5. Chapter 4: Regular Expressions 6. Chapter 5: Functions and Script Organization 7. Chapter 6: Bash Networking 8. Chapter 7: Parallel Processing 9. Part 2: Bash Scripting for Pentesting
10. Chapter 8: Reconnaissance and Information Gathering 11. Chapter 9: Web Application Pentesting with Bash 12. Chapter 10: Network and Infrastructure Pentesting with Bash 13. Chapter 11: Privilege Escalation in the Bash Shell 14. Chapter 12: Persistence and Pivoting 15. Chapter 13: Pentest Reporting with Bash 16. Part 3: Advanced Applications of Bash Scripting for Pentesting
17. Chapter 14: Evasion and Obfuscation 18. Chapter 15: Interfacing with Artificial Intelligence 19. Chapter 16: DevSecOps for Pentesters 20. Index 21. Other Books You May Enjoy

Network exploitation

In this section, we’ll dive into exploiting command injection vulnerabilities in web applications that fail to filter user input before passing data on to operating system commands.

Network service exploitation

In September 2014, a critical vulnerability was discovered in the Unix Bash shell. This vulnerability, assigned the CVE-2014-6271 identifier and nicknamed Shellshock, sent shockwaves through the information security community due to its severity and widespread impact. Let’s dive into the technical details of this vulnerability and explore how it can be exploited.

The Shellshock vulnerability stems from a flaw in how Bash processes environment variables. Specifically, it allows an attacker to execute arbitrary commands by manipulating environment variables in a crafted manner.

In Bash, environment variables can be defined in the following format:

VAR=value

However, Bash also supports a feature called function exporting, which...

lock icon The rest of the chapter is locked
Visually different images
CONTINUE READING
83
Tech Concepts
36
Programming languages
73
Tech Tools
Icon Unlimited access to the largest independent learning library in tech of over 8,000 expert-authored tech books and videos.
Icon Innovative learning tools, including AI book assistants, code context explainers, and text-to-speech.
Icon 50+ new titles added per month and exclusive early access to books as they are being written.
Bash Shell Scripting for Pentesters
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Modal Close icon
Modal Close icon