Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

The Shellshock Bug In About Four Minutes (video)
youtube.com ^ | 9-25-2014 | Tom Scott

Posted on 09/25/2014 12:57:00 PM PDT by servo1969

Remember Heartbleed? Well, this is probably worse. Here's a (somewhat simplified) explanation of what Shellshock actually is. Don't worry: I haven't included instructions on how to actually exploit it. The moral of the story is: keep your security patches up to date!

(Excerpt) Read more at youtube.com ...


TOPICS: Business/Economy; Chit/Chat; Computers/Internet; Hobbies; Humor; Reference; Science; Society
KEYWORDS: bash; bug; hack; heartbleed; php; shellshock; unix

1 posted on 09/25/2014 12:57:00 PM PDT by servo1969
[ Post Reply | Private Reply | View Replies]

To: servo1969

“Worse” is subjective. It’s a more severe bug when it’s exploited, however being able to exploit it is more difficult.

In any event, “keep up with security patches” is always good advice.


2 posted on 09/25/2014 12:59:37 PM PDT by kevkrom (I'm not an unreasonable man... well, actually, I am. But hear me out anyway.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Ping


3 posted on 09/25/2014 1:22:31 PM PDT by raybbr (Obamacare needs a death panel.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kevkrom

25 years this was possible, and they just find it. Talking about patching everything is going to be difficult, if not impossible, considering all of the embedded systems out there.


4 posted on 09/25/2014 3:48:46 PM PDT by ImaGraftedBranch (...By reading this, you've collapsed my wave function. Thanks.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Still Thinking; ...

5 posted on 09/25/2014 3:55:00 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ImaGraftedBranch

The good news is that most embedded systems don’t use Bash, they use something smaller like ash, dash, BusyBox, etc.


6 posted on 09/25/2014 4:48:25 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: servo1969
> Don't worry: I haven't included instructions on how to actually exploit it.

You mean like this?

prompt$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
It's no secret how to exploit it. It's freakin' TRIVIAL to exploit it. But first, you have to get to it. That's the hard part.

This is a tempest in a teapot. No less a tempest, but this is a LOT harder to arrange to exploit than HeartBleed.

I'm a System Admin with a few hundred servers and workstations to patch -- it's a nightmare. That's my job...

But meanwhile, the freakin' technology twats writing these headlines sound like the world is ending. It's not. They're just pimping for webpage hits.

You want to know where the world is ending, look up the news on Ebola...

7 posted on 09/25/2014 4:53:30 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Being a dinosaur who gave-up with keeping-up with tech, I enjoy hitting these threads....it’s like those ‘English as a Second Language’ courses for us old phocks.....I try to learn sumpin, but quickly realize I’m beyond the curve.


8 posted on 09/25/2014 5:01:44 PM PDT by ErnBatavia (It ain't a "hashtag"....it's a damn pound sign, number sign, or octothorpe. ###)
[ Post Reply | Private Reply | To 7 | View Replies]

To: dayglored

Thanks for sharing...


9 posted on 09/25/2014 8:08:42 PM PDT by GOPJ ("The welfare of humanity is always the alibi of tyrants" - Albert Camus)
[ Post Reply | Private Reply | To 7 | View Replies]

To: GOPJ
Sure thing. That one liner of code, BTW, is a good test for whether your /bin/bash is vulnerable or not.

Just copy/paste that line at a Bash prompt and hit return. If it prints out:

vulnerable
this is a test
then your Bash has the flaw. OTOH, if it prints out:
bash: warning: x: ignoring function definition attempt
bash: error importing function definition for `x'
this is a test
then your Bash is safe from this bug.
10 posted on 09/25/2014 8:15:46 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: dayglored; GOPJ

... Minus the “prompt$” part, of course. That represents the shell prompt you’re entering the command at.


11 posted on 09/25/2014 8:17:03 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: dayglored

Thanks ... I suspect you’ve forgotten more about code than I’ll ever know. That said I’m thankful you’re here..


12 posted on 09/25/2014 8:39:10 PM PDT by GOPJ ("The welfare of humanity is always the alibi of tyrants" - Albert Camus)
[ Post Reply | Private Reply | To 10 | View Replies]

To: GOPJ
> Thanks ... I suspect you’ve forgotten more about code than I’ll ever know. That said I’m thankful you’re here..

You're very welcome, FRiend, and thank -you- for the kind words.

Fact is, I've been at this for 44 years now and have forgotten more about code than -I- ever knew, too. :)

13 posted on 09/25/2014 8:54:40 PM PDT by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: dayglored

I patched 114 various distributions of Linux systems for this bug and ran that same test today, but I changed the “this is a test part” to “System is not vulnerable.” Too bad I didn’t already have Chef configured... One of these days...


14 posted on 09/25/2014 9:50:13 PM PDT by scripter
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson