• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Collapse

You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:

  • You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
  • You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
  • If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.

Previously on "Linux bash vulnerability"

Collapse

  • suityou01
    replied
    Originally posted by DiscoStu View Post
    Hardly IT's 9/11
    Well you can proudly claim that. And well done you.

    Sadly we live in a world where reality does not really matter. The financial markets and wave after wave of printed money are testimony to this. We should all realise currency is worthless yet we keep ploughing money into a broken system.

    Not wanting to veer away from the point, this problem is very real and when the confidence is lost, a cold wind will blow for our industry.

    It's just that the rest of you chose not to believe it and would rather burn me at the stake for being a heretic.

    Such is the life of the truly enlightened.

    Leave a comment:


  • DiscoStu
    replied
    Originally posted by suityou01 View Post
    Hardly IT's 9/11

    Leave a comment:


  • stek
    replied
    Originally posted by suityou01 View Post
    There's a new variant out now, the SuityShock Bash vulnerability.

    It's similar to the old one, except you need two years experience before you can exploit it.

    Leave a comment:


  • suityou01
    replied
    The problem is still very much a big big problem.

    Ghost in the (Bourne Again) Shell: Fallout of Shellshock far from over | Ars Technica

    Leave a comment:


  • suityou01
    replied
    Originally posted by DiscoStu View Post
    Well Chicken Little, has the sky fallen yet?
    Let me check and get back to you.

    Leave a comment:


  • DiscoStu
    replied
    Originally posted by suityou01 View Post
    Aye. I think Darmie was being deliberately obtuse.

    Next users crafting their own DHCP packets will be basic end user stuff

    I understand IRC can also be used.

    In other news, VOIP systems can also be exploited.

    The attack vectors are not yet completely understood, the patches released so far have been ineffective and by now the hacking community has spread it's mucky seeds into every deep corner of the internet.

    This is IT's 9/11.

    I hate being right
    Well Chicken Little, has the sky fallen yet?

    Leave a comment:


  • suityou01
    replied
    Originally posted by Stevie Wonder Boy View Post
    he keeps the internet in a box under his bed with his HP-UX box. Meanwhile 50% of all Unix/Linux are RHEL and use bash.

    Nothing to flounder with that... btw I used to work for Sun.

    Do you somethimes feel the world is passing you by?
    Ouch

    Leave a comment:


  • Stevie Wonder Boy
    replied
    he keeps the internet in a box under his bed with his HP-UX box. Meanwhile 50% of all Unix/Linux are RHEL and use bash.

    Nothing to flounder with that... btw I used to work for Sun.

    Do you somethimes feel the world is passing you by?

    Leave a comment:


  • NonnyMouse
    replied
    Chill - there are fixes out there now. Just be careful in applying said fixes - don't let Apple sneakily upgrade you to xcode6

    Leave a comment:


  • stek
    replied
    Originally posted by suityou01 View Post
    Have you ever thought about after dinner speaking with such witty anecdotes?

    I suppose that will have to wait a bit while you fix the internet. Got any idea how long it will take to fix?
    This is Suity holding The Internet Wot I Just Fixed...

    Leave a comment:


  • suityou01
    replied
    Have you ever thought about after dinner speaking with such witty anecdotes?

    I suppose that will have to wait a bit while you fix the internet. Got any idea how long it will take to fix?

    Leave a comment:


  • stek
    replied
    Originally posted by suityou01 View Post
    So simply remove bash from every machine, embedded system and device on or just behind the internet and we're all fixed. Simples cheers Stek.
    No real need, it's not on proper Unix as used in the enterprise unless installed by inadequates, it's installed by default on numpty-unix-like systems tho, go figure. Makes me laugh to see Linuxites founder on AIX or HP-UX with no backspace or arrow keys and typing 'bash' in desperation only to get 'sh: bash: not found.'......

    Keeping me well paid though, can't complain, kerr-ching....

    Leave a comment:


  • suityou01
    replied
    Linux bash vulnerability

    Originally posted by stek View Post
    On Linux maybe so. Linux isn't even Unix...

    It might be a shock to you but not everything is Linux, and not every Unix has bash as default, or even on the system. You might need your arrow keys working but most of us don't. Don't be lazy and expose yourself to this sort of thing, bash is not needed, nor is it a prerequisite for anything.
    So simply remove bash from every machine, embedded system and device on or just behind the internet and we're all fixed. Simples cheers Stek.

    Leave a comment:


  • stek
    replied
    Originally posted by Stevie Wonder Boy View Post
    uh no .. hell no bash is the default shell. So everytime apache spawns a process it starts a bash shell. On an unpatched system you can use header variables to run anything you like on the target box.

    Your vi supposition is clearly wrong and shows a pretty simple understanding of current linux os and processes.
    On Linux maybe so. Linux isn't even Unix...

    It might be a shock to you but not everything is Linux, and not every Unix has bash as default, or even on the system. You might need your arrow keys working but most of us don't. Don't be lazy and expose yourself to this sort of thing, bash is not needed, nor is it a prerequisite for anything.

    Leave a comment:


  • CheeseSlice
    replied
    Originally posted by suityou01 View Post
    The attack vector of choice is NAS boxes bizarrely. But I don't think the full hand has been played yet. Sensibly biding their time rather than peaking too soon.
    Looking back all those years to SQL slammer again. The windows security patch was actually released 6 months before the attack was unleashed causing widespread damage and disruption to businesses. The problem is so many organisations are still tulip at rolling out patches it wouldn't surprise me if something like this could happen again.

    Leave a comment:

Working...
X