Originally posted by stek
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Linux bash vulnerability
Collapse
X
Collapse
-
-
Although from the horses mouth
USN-2362-1: Bash vulnerability | Ubuntu
Ubuntu Security Notice USN-2362-1
24th September, 2014
bash vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 14.04 LTS
Ubuntu 12.04 LTS
Ubuntu 10.04 LTS
Summary
Bash allowed bypassing environment restrictions in certain environments.
Knock first as I might be balancing my chakras.Comment
-
Not really cos 99.99% of desktops that would normally use DHCP are hidden behind NAT. Safe, unless you've been pissing around with port forwarding on your NAT router.Originally posted by CheeseSlice View PostIf DHCP and Macs are affected, thats going to be a problem for some creative/digital businesses.
All it would take is a worm to set up rogue DHCP servers on each infected host and it would be a fast spreading Denial of service infection akin to Blaster or SQL Slammer.
I imagine businesses running mainly Macs are also going to take a relaxed approach to endpoint security, since its commonfolkloreknowledge "Macs dont get viruses"
I'd warrant there's next to no (if any) host on public IP's with a DHCP issued one. Of course that won't stop internal meddling.....Comment
-
Bash is on every Ubuntu box I have and I haven't ever explicitly installed it. Dash is simply the *default* shell, it doesn't mean others aren't on the system.Originally posted by stek View PostOr it was installed with the default install like is 99% likely, like I already said.
Like.Comment
-
Do it mid-Suity post!Originally posted by administrator View PostCheers stek, will give them a kick later!Comment
-
SQL Slammer made it behind plenty of firewalled networks. I was working at a very large firm when it spread fast across the corporate network. No idea how it got in, but it did.Originally posted by stek View PostNot really cos 99.99% of desktops that would normally use DHCP are hidden behind NAT. Safe, unless you've been pissing around with port forwarding on your NAT router.
I'd warrant there's next to no (if any) host on public IP's with a DHCP issued one. Of course that won't stop internal meddling.....
All it takes is for one user to be fooled to execute a file attached to an email, and then its in.Comment
-
I'm not googling SQL-slammer now! lol!Originally posted by CheeseSlice View PostSQL Slammer made it behind plenty of firewalled networks. I was working at a very large firm when it spread fast across the corporate network. No idea how it got in, but it did.
All it takes is for one user to be fooled to execute a file attached to an email, and then its in.
I've got some Mr Kipling Viennese Whirls.Comment
-
Or an unpatchable embedded system to be compromised.Originally posted by CheeseSlice View PostSQL Slammer made it behind plenty of firewalled networks. I was working at a very large firm when it spread fast across the corporate network. No idea how it got in, but it did.
All it takes is for one user to be fooled to execute a file attached to an email, and then its in.
I am telling you now, this will run and run.Knock first as I might be balancing my chakras.Comment
-
Already posted this in Technical earlier today, but I might as well tack it on here too for those who only see this thread: Troy Hunt: Everything you need to know about the Shellshock Bash bug
Comment
-
Already devoured it.Originally posted by NickFitz View PostAlready posted this in Technical earlier today, but I might as well tack it on here too for those who only see this thread: Troy Hunt: Everything you need to know about the Shellshock Bash bug
Knock first as I might be balancing my chakras.Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers

Comment