- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Anyone use bash?
Collapse
X
-
-
The problem is particularly serious given that many web servers are run using the Apache system, software which includes the Bash component.
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server? -
Comment
-
Comment
-
The exploit allows you to access the webserver remotely via bash....Originally posted by Bunk View Post
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server?Comment
-
But bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?Originally posted by stek View PostThe exploit allows you to access the webserver remotely via bash....Will work inside IR35. Or for food.Comment
-
I think the exploit can give extra privs in the manner of the old Emacs exploit.Originally posted by VectraMan View PostBut bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?Comment
-
CGI uses the system shell, which is usually bash. One nice (?) demo I saw last night involved changing the User-Agent header on a request. When processed by a vulnerable web server (e.g. one running PHP-as-CGI, or one with a cgi-bin script that parsed request headers) it allowed execution of arbitrary shell commands on the server.Originally posted by Bunk View Post
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server?Comment
-
The web server is running as a logged-on user (usually something like www:www or apache:apache). It allows you to run arbitrary commands with the same privileges as that user, which is clearly a Bad Thing. In particular, even if the web server user is restricted to certain commands, it allows you to override those restrictions, and run whatever you like with a simple request to port 80.Originally posted by VectraMan View PostBut bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?
If this was combined with a zero-day privilege escalation vulnerability within bash, then the bad guys could root a server with nothing more than a single request using curl. Not good
Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Loan Recall Case Study: Amanda Today 06:00
- How IR35 inflated an £8.5bn consultancy bill — and tests Burnham at the Budget Aug 28 07:47
- Autumn Budget 2026: FCSA’s 5 contractor asks of John Healey Aug 27 04:15
- Andy Burnham's Zoom gripe doesn’t apply to IT contractors, say recruiters Aug 26 03:41
- Check your Loan Recall paperwork for the Isle of Man: it could matter Aug 25 03:27
- Budget 2026: Contractor advisers ask for ‘IR35 reset’ Aug 24 04:57
- Why might an umbrella company fail to pay its total tax bill to HMRC? Aug 18 06:08
- Contractors, here are the late payment fixes that the Lords just turned down Aug 17 08:03
- How will HMRC's Direct Debit plan affect contractors paying VAT and PAYE? Aug 13 23:54
- HMRC's new 'reckless' tax offence: an IR35 game-changer for contractors? Aug 13 13:50

Comment