<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>shellshock attack &#8211; diditho.com</title>
	<atom:link href="https://diditho.com/tag/shellshock-attack/feed/" rel="self" type="application/rss+xml" />
	<link>https://diditho.com</link>
	<description>&#34; Knowing is not enough we must apply. Willing is not enough we must do &#34; - Bruce Lee</description>
	<lastBuildDate>Tue, 09 Dec 2025 10:17:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://diditho.com/wp-content/uploads/2023/11/cropped-diditho-photo-logo-512-x-512-32x32.png</url>
	<title>shellshock attack &#8211; diditho.com</title>
	<link>https://diditho.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Shellshock Attack, Detection, Analysis, and Why Wazuh Proved Its Power</title>
		<link>https://diditho.com/2025/12/09/shellshock-attack-detection-analysis-and-why-wazuh-proved-its-power/</link>
					<comments>https://diditho.com/2025/12/09/shellshock-attack-detection-analysis-and-why-wazuh-proved-its-power/#respond</comments>
		
		<dc:creator><![CDATA[diditho]]></dc:creator>
		<pubDate>Tue, 09 Dec 2025 05:46:03 +0000</pubDate>
				<category><![CDATA[dev]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[shellshock attack]]></category>
		<category><![CDATA[wazuh]]></category>
		<guid isPermaLink="false">https://diditho.com/?p=10537</guid>

					<description><![CDATA[Overview At 02:04:43 UTC, 7 November 2025, our Wazuh SIEM raised a critical level-15 alert, Rule 31168, &#8220;Shellshock attack detected&#8221; This alert originated from an Nginx access log on agent, proxy-sg2-deb-12-pro-proxy-xxxx (IP 1xx.xxx.xxx.xxx). The source of the request was 193.26.115.195 (Netherlands). Wazuh immediately identified the payload as an active Shellshock exploit attempt (CVE-2014-6271). But here&#8217;s... <span class="more"><a class="more-link" href="https://diditho.com/2025/12/09/shellshock-attack-detection-analysis-and-why-wazuh-proved-its-power/">Continue reading <span class="meta-nav">&#8594;</span></a></span>]]></description>
		
					<wfw:commentRss>https://diditho.com/2025/12/09/shellshock-attack-detection-analysis-and-why-wazuh-proved-its-power/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
