Originally posted by stek
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Linux bash vulnerability
Collapse
X
Collapse
-
-
Yep. Apart from Ubuntu and Debian flavours. Please don't make me say it again.Originally posted by stek View PostAll bash is, even on SPARC Solaris.Knock first as I might be balancing my chakras.Comment
-
CGI scripts? How very 1990's. How many servers are you running that might be affected Suity? None? At ease then, soldier.Comment
-
Quoted for posterity.Originally posted by administrator View PostCGI scripts? How very 1990's. How many servers are you running that might be affected Suity? None? At ease then, soldier.
Knock first as I might be balancing my chakras.Comment
-
Yes but bash is installable on said Unix-like operating systems and probably is installed under the mass of crap that gets shovelled in with a 'default' install on these OS's but isn't the default shell, and might never be invoked by a user but it's still there.Originally posted by suityou01 View PostYep. Apart from Ubuntu and Debian flavours. Please don't make me say it again.
It's not like Ubuntu just gets dash (thanks Unix) or IRIX just gets zsh, is it?
I spent all today trawling through various Unixes and Unix-like OS's and you can't assume that because AIX doesn't come with bash it's not been added or because we all prefer ksh on Solaris and HP-UX bash isn't there either.Comment
-
It probably has been exploited, but those who've been doing it have kept quiet.Originally posted by Unix View PostIt's been out there for 20 years yet no-one has exploited it yet, funny that.
It's storm in a teacup.Comment
-
From what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.Comment
-
Too right, we're in Change Control/Downtime hell now, be weeks before anything's done lol!Originally posted by administrator View PostFrom what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.Comment
-
Maybe so. I hope you're right but I think you're assuming a cgi exploit is the only possible attack vector.Originally posted by administrator View PostFrom what I can see it reads a bit like the heartbleed thing from earlier in the year. That was a storm in a tea-cup. Checking and patching machines keeps a lot of bods in works. Worryworts such as yourself help to maintain management's need for this. Keep up the good work, your contribution to the cause is greatly appreciated.
I agree with the analysts, we ain't seen nothing yet.Knock first as I might be balancing my chakras.Comment
-
Aye, as I understand it on Ubuntu dash is the default but bash is still there. But best ask Suity, he is the expert on these thingsOriginally posted by stek View PostYes but bash is installable on said Unix-like operating systems and probably is installed under the mass of crap that gets shovelled in with a 'default' install on these OS's but isn't the default shell, and might never be invoked by a user but it's still there.
It's not like Ubuntu just gets dash (thanks Unix) or IRIX just gets zsh, is it?
I spent all today trawling through various Unixes and Unix-like OS's and you can't assume that because AIX doesn't come with bash it's not been added or because we all prefer ksh on Solaris and HP-UX bash isn't there either.
Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Is your Director’s Loan Account (DLS) a target of HMRC’s closer look at close companies? May 29 04:45
- Contractors, are you making any of the five big limited company bank account mistakes of 2026? Today 05:51
- ‘Welcome’ increase in HMRC mileage rates for contractors using their own cars for work Yesterday 05:18
- King’s Speech 2026 including a welcome Late Payments Bill still leaves contractors short May 26 04:42
- Getting a mortgage when you're a contractor. The system wasn't built for you. Is that finally changing? May 22 06:11
- How deepfake AI contractors threaten umbrella company supply chains under JSL May 20 06:31
- Mileage rates review: Will the first AMAP rethink in 15 years benefit contractors? May 19 05:57
- What is a Forward Deployed Engineer (FDE), and are FDE jobs for IT contractors ripe? May 18 04:43
- IT contractor demand lunged towards growth in April 2026 May 13 04:48
- What does PGMOL’s win over HMRC mean for contractors? May 12 07:25

Comment