Originally posted by stek
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Linux bash vulnerability
Collapse
X
Collapse
-
-
Yep. Apart from Ubuntu and Debian flavours. Please don't make me say it again.Originally posted by stek View PostAll bash is, even on SPARC Solaris.Knock first as I might be balancing my chakras.Comment
-
CGI scripts? How very 1990's. How many servers are you running that might be affected Suity? None? At ease then, soldier.Comment
-
Quoted for posterity.Originally posted by administrator View PostCGI scripts? How very 1990's. How many servers are you running that might be affected Suity? None? At ease then, soldier.
Knock first as I might be balancing my chakras.Comment
-
Yes but bash is installable on said Unix-like operating systems and probably is installed under the mass of crap that gets shovelled in with a 'default' install on these OS's but isn't the default shell, and might never be invoked by a user but it's still there.Originally posted by suityou01 View PostYep. Apart from Ubuntu and Debian flavours. Please don't make me say it again.
It's not like Ubuntu just gets dash (thanks Unix) or IRIX just gets zsh, is it?
I spent all today trawling through various Unixes and Unix-like OS's and you can't assume that because AIX doesn't come with bash it's not been added or because we all prefer ksh on Solaris and HP-UX bash isn't there either.Comment
-
It probably has been exploited, but those who've been doing it have kept quiet.Originally posted by Unix View PostIt's been out there for 20 years yet no-one has exploited it yet, funny that.
It's storm in a teacup.Comment
-
From what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.Comment
-
Too right, we're in Change Control/Downtime hell now, be weeks before anything's done lol!Originally posted by administrator View PostFrom what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.Comment
-
Maybe so. I hope you're right but I think you're assuming a cgi exploit is the only possible attack vector.Originally posted by administrator View PostFrom what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.
I agree with the analysts, we ain't seen nothing yet.Knock first as I might be balancing my chakras.Comment
-
Aye, as I understand it on Ubuntu dash is the default but bash is still there. But best ask Suity, he is the expert on these thingsOriginally posted by stek View PostYes but bash is installable on said Unix-like operating systems and probably is installed under the mass of crap that gets shovelled in with a 'default' install on these OS's but isn't the default shell, and might never be invoked by a user but it's still there.
It's not like Ubuntu just gets dash (thanks Unix) or IRIX just gets zsh, is it?
I spent all today trawling through various Unixes and Unix-like OS's and you can't assume that because AIX doesn't come with bash it's not been added or because we all prefer ksh on Solaris and HP-UX bash isn't there either.
Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers

Comment