- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Anyone use bash?
Collapse
X
-
-
The problem is particularly serious given that many web servers are run using the Apache system, software which includes the Bash component.
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server? -
Comment
-
Comment
-
The exploit allows you to access the webserver remotely via bash....Originally posted by Bunk View Post
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server?Comment
-
But bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?Originally posted by stek View PostThe exploit allows you to access the webserver remotely via bash....Will work inside IR35. Or for food.Comment
-
I think the exploit can give extra privs in the manner of the old Emacs exploit.Originally posted by VectraMan View PostBut bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?Comment
-
CGI uses the system shell, which is usually bash. One nice (?) demo I saw last night involved changing the User-Agent header on a request. When processed by a vulnerable web server (e.g. one running PHP-as-CGI, or one with a cgi-bin script that parsed request headers) it allowed execution of arbitrary shell commands on the server.Originally posted by Bunk View Post
I'm no sandal-wearing Linux expert but isn't it part of the OS, not the web server?Comment
-
The web server is running as a logged-on user (usually something like www:www or apache:apache). It allows you to run arbitrary commands with the same privileges as that user, which is clearly a Bad Thing. In particular, even if the web server user is restricted to certain commands, it allows you to override those restrictions, and run whatever you like with a simple request to port 80.Originally posted by VectraMan View PostBut bash is a command line IIRC. Surely that means you need to have logged onto the machine to get the command line to do any damage?
If this was combined with a zero-day privilege escalation vulnerability within bash, then the bad guys could root a server with nothing more than a single request using curl. Not good
Comment
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- Umbrella company winding-up petitions in 2026: the practical guide for contractors Today 05:29
- Payments on Account deadline: what contractors must do before July 31st — maybe for the final few times Yesterday 08:01
- Andy Burnham's first 100 days: five things contractors need from the new PM Jul 27 00:53
- Starmer vs Burnham on housing: What their rival plans mean for your contractor mortgage Jul 22 00:59
- Burnham's housing vision vs. Starmer's home-buying reforms: what it means for your contractor mortgage Jul 22 00:59
- In Khalil v Innovate Transport, a limited company contractor wasn’t a worker and was on £2.30 — not £230 Jul 21 07:58
- Andy Burnham is PM: 5 new IT policies set to shape UK tech and its contractors Jul 20 06:29
- Taxed on money I haven't earned yet? Bold move, HMRC Jul 17 08:36
- The Fair Work Agency has got zero hours in its sights. Do you? Jul 16 08:44
- Cookie Policy Jul 15 11:50

Comment