• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Linux bash vulnerability

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #11
    Originally posted by Unix View Post
    There is a patch for it so just a matter of updating your bash via your package manager job done.

    HTH
    There is no patch for RHEL yet.

    Linux makers released patches to protect against attacks on Wednesday, though security researchers uncovered flaws in those updates, prompting No. 1 Linux maker Red Hat Inc to advise customers that the patch was "incomplete."

    "That's a problem. It's been a little over 24 hours and we're still in the same boat," said Mat Gangwer, lead security consultant at Rook Security. "People are kind of freaking out. Rightfully so."
    So that's all good then just patch and job done.

    Oh wait

    Joe Hancock, a cybersecurity expert with insurer AEGIS in London, said in a statement that he is concerned about the potential for attacks on home broadband routers and controllers used to manage critical infrastructure facilities.

    "In some areas this will be a challenge to fix, as many embedded devices are not designed with regular updates in mind and will never be able to be patched," Hancock said.
    Ah dammit those pesky embedded systems.

    "There is a lot of speculation out there as to what is vulnerable, but we just don't have the answers," said Marc Maiffret, chief technology officer of cybersecurity firm BeyondTrust. "This is going to unfold over the coming weeks and months."
    Nah it's ok, Unix says job done.
    Knock first as I might be balancing my chakras.

    Comment


      #12
      Originally posted by suityou01 View Post
      There is no patch for RHEL yet.



      So that's all good then just patch and job done.

      Oh wait



      Ah dammit those pesky embedded systems.



      Nah it's ok, Unix says job done.
      It's been out there for 20 years yet no-one has exploited it yet, funny that. It's storm in a teacup.

      Comment


        #13
        Originally posted by Unix View Post
        It's been out there for 20 years yet no-one has exploited it yet, funny that. It's storm in a teacup.
        Quoted for posterity.
        Knock first as I might be balancing my chakras.

        Comment


          #14
          Originally posted by suityou01 View Post
          Quoted for posterity.
          Yeah all those 1993 CGI sites getting hacked, lets hope so, it will encourage them to upgrade. Most routers / embedded devices use busybox which doesn't have the issue.

          HTH

          Comment


            #15
            Originally posted by Unix View Post
            Yeah all those 1993 CGI sites getting hacked, lets hope so, it will encourage them to upgrade. Most routers / embedded devices use busybox which doesn't have the issue.

            HTH
            Quoted for posterity.
            Knock first as I might be balancing my chakras.

            Comment


              #16
              Originally posted by suityou01 View Post
              Quoted for posterity.
              It's nothing to worry about and I th,.dfdf,______

              HAHA FU I HACKED YOUR BOX!!!!!!!!

              Comment


                #17
                No patch for Debian, as yet, as far as I can tell?
                I was an IPSE Consultative Council Member, until the BoD abolished it. I am not an IPSE Member, since they have no longer have any relevance to me, as an IT Contractor. Read my lips...I recommend QDOS for ALL your Insurance requirements (Contact me for a referral code).

                Comment


                  #18
                  Originally posted by Scruff View Post
                  No patch for Debian, as yet, as far as I can tell?
                  Ubuntu and Debian flavours are unaffected.
                  Knock first as I might be balancing my chakras.

                  Comment


                    #19
                    YouPorn still works. Panic ye not

                    Comment


                      #20
                      Originally posted by suityou01 View Post
                      Ubuntu and Debian flavours are unaffected.
                      All bash is, even on SPARC Solaris.

                      Comment

                      Working...
                      X