Remote Code Exploitation through Bash

nodeX:~ # env VAR='() { :; }; echo Bash is vulnerable!' bash -c "echo Bash Test"
Bash Test
nodeX:~ # ssh nodeY
nodeY:~ # env VAR='() { :; }; echo Bash is vulnerable!' bash -c "echo Bash Test"
Bash is vulnerable!
Bash Test
nodeY:~ #

if you have some old / EOL release:

mkdir src
cd src
#download all patches
for i in $(seq -f "%03g" 0 25); do wget$i; done
tar zxvf bash-4.3.tar.gz 
cd bash-4.3
#apply all patches
for i in $(seq -f "%03g" 0 25);do patch -p0 < ../bash43-$i; done
#build and install
./configure && make && make install
cd .. 
cd ..
rm -r src

ModSecurity2 to Apache HTTP Server (CentOS)

ModSecurity supplies an array of request filtering and other security features to the Apache HTTP Server, IIS and NGINX. ModSecurity is a web application layer firewall. ModSecurity is free software released under the Apache license 2.0.

Postfix: systemd-services – mailgraph.service

File of service:

Activating service:

gate:/etc/systemd/system # systemctl enable mailgraph.service
ln -s ‘/etc/systemd/system/mailgraph.service’ ‘/etc/systemd/system/’
gate:/etc/systemd/system #

Content of unit file:
How do I set Skype status before login in

Not being able to set your status before logging in is something that, in effect, sucks. It double sucks when you consider how easy would be implementing that feature. So easy that you can, in fact, set your status before logging by just investing some seconds in modifying the file that stores all your account setup, called main.db.

