Originally posted by Stevie Wonder Boy
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Linux bash vulnerability
Collapse
X
Collapse
-
-
-
Only affects people who can't use vi on the command line!
We've removed it from proper Unixes where some bell end has installed it, only pretend unix fanbois seem to depend on it so we've had to pander to them for this 20 year old exploit...Comment
-
I'm getting that Stek is old, and set in his ways.Knock first as I might be balancing my chakras.Comment
-
uh no .. hell no bash is the default shell. So everytime apache spawns a process it starts a bash shell. On an unpatched system you can use header variables to run anything you like on the target box.
Your vi supposition is clearly wrong and shows a pretty simple understanding of current linux os and processes.Comment
-
Originally posted by suityou01 View PostI'm getting that Stek is old, and set in his ways.
Sure it's serious, but is it end of the world stuff? Nope.
Are the vendors unable to cope with it? Nope.
Are fixes being rolled out at a decent pace? Yep.
Are some contractors with the relevant skills making money from what's happened? YupComment
-
The attack vector of choice is NAS boxes bizarrely. But I don't think the full hand has been played yet. Sensibly biding their time rather than peaking too soon.Knock first as I might be balancing my chakras.Comment
-
Originally posted by TykeMerc View PostThat's ok, we got that you're a hysterical, fantasist, brainless ****wit twat years ago, you just reinforce the view on a regular basis.
Sure it's serious, but is it end of the world stuff? Nope.
Are the vendors unable to cope with it? Nope.
Are fixes being rolled out at a decent pace? Yep.
Are some contractors with the relevant skills making money from what's happened? YupKnock first as I might be balancing my chakras.Comment
-
Originally posted by suityou01 View PostThe attack vector of choice is NAS boxes bizarrely. But I don't think the full hand has been played yet. Sensibly biding their time rather than peaking too soon.Comment
-
Originally posted by Stevie Wonder Boy View Postuh no .. hell no bash is the default shell. So everytime apache spawns a process it starts a bash shell. On an unpatched system you can use header variables to run anything you like on the target box.
Your vi supposition is clearly wrong and shows a pretty simple understanding of current linux os and processes.
It might be a shock to you but not everything is Linux, and not every Unix has bash as default, or even on the system. You might need your arrow keys working but most of us don't. Don't be lazy and expose yourself to this sort of thing, bash is not needed, nor is it a prerequisite for anything.Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Secondary NI threshold sinking to £5,000: a limited company director’s explainer Dec 24 09:51
- Reeves sets Spring Statement 2025 for March 26th Dec 23 09:18
- Spot the hidden contractor Dec 20 10:43
- Accounting for Contractors Dec 19 15:30
- Chartered Accountants with MarchMutual Dec 19 15:05
- Chartered Accountants with March Mutual Dec 19 15:05
- Chartered Accountants Dec 19 15:05
- Unfairly barred from contracting? Petrofac just paid the price Dec 19 09:43
- An IR35 case law look back: contractor must-knows for 2025-26 Dec 18 09:30
- A contractor’s Autumn Budget financial review Dec 17 10:59
Comment