> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Shellshock (CVE-2014-6271)

> Cross-platform resources for Shellshock (CVE-2014-6271): curated HTB machines, PortSwigger labs and TryHackMe rooms with validated writeups and related skills.

# Shellshock (CVE-2014-6271)

This page aggregates **cross-platform resources to practice Shellshock (CVE-2014-6271)**: retired Hack The Box machines, PortSwigger Web Security Academy labs and TryHackMe rooms, plus curated resources (HackTricks, PortSwigger, etc.) and related skills.

## Curated resources

| Source     | Link                                                                                                                                                                                                                                                                                                                     |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| HackTricks | [https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable\_functions-open\_basedir-bypass.html](https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass.html) |
| Exploit-DB | [https://www.exploit-db.com/exploits/34900](https://www.exploit-db.com/exploits/34900)                                                                                                                                                                                                                                   |

## HTB machines practicing Shellshock (CVE-2014-6271) (3)

| Machine                                          | OS    | Difficulty                                           |
| ------------------------------------------------ | ----- | ---------------------------------------------------- |
| [Ariekei](/en/htb/machines/linux/insano/ariekei) | Linux | <span className="dbadge dbadge-insane">INSANE</span> |
| [Beep](/en/htb/machines/linux/facil/beep)        | Linux | <span className="dbadge dbadge-easy">EASY</span>     |
| [Shocker](/en/htb/machines/linux/facil/shocker)  | Linux | <span className="dbadge dbadge-easy">EASY</span>     |

## PortSwigger labs practicing Shellshock (CVE-2014-6271) (1)

| Lab                                                                                                | Difficulty                                             | Topic                              | Official                                                                            |
| -------------------------------------------------------------------------------------------------- | ------------------------------------------------------ | ---------------------------------- | ----------------------------------------------------------------------------------- |
| [Blind SSRF with Shellshock exploitation](/en/portswigger/labs/ssrf/blind-shellshock-exploitation) | <span className="dbadge dbadge-easy">APPRENTICE</span> | SSRF (Server-Side Request Forgery) | [Open](https://portswigger.net/web-security/ssrf/blind/lab-shellshock-exploitation) |

## Related skills

* [/en/skills/rce](/en/skills/rce)

***

← [Back to the full glossary](/en/glossary)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"Shellshock (CVE-2014-6271)","termCode":"shellshock","inLanguage":"en","url":"https://rootea.es/en/skills/shellshock","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Tactical pentesting glossary","url":"https://rootea.es/en/glossary"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"HTB machines practicing Shellshock (CVE-2014-6271)","numberOfItems":3,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/en/htb/machines/linux/insano/ariekei","name":"Ariekei"},{"@type":"ListItem","position":2,"url":"https://rootea.es/en/htb/machines/linux/facil/beep","name":"Beep"},{"@type":"ListItem","position":3,"url":"https://rootea.es/en/htb/machines/linux/facil/shocker","name":"Shocker"}]}`}
</script>

*Last updated: 2026-05-08*
