YOUREWINNER.COM
 
   

CVE-2014-6271: remote code execution through bash
 
#1 24-09-2014, 21:34:12 PM
  • Guest
Wow this is bad, update your VPS folks!!

OS X users: update your bash with homebrew or wait for Apple to release an update!!

Many CGI scripts (bash, PHP, etc) calling shell commands are vulnerable
dhclient can be exploited on the local network with a malicious DHCP server
sshd can be exploited through the SSH_ORIGINAL_COMMAND environment variable

Ubluntu users are less at risk since they use /bin/dash as the default shell

Don't lose faith in open-source, folks.
Remember that if this was closed software we might have never found out about the bug and only the blackhats would know!!

Stay safe out there!!

http://arstechnica.com/security/2014/09/bug-in-bash-shell-creates-big-security-hole-on-anything-with-nix-in-it/


#2 24-09-2014, 21:41:06 PM
You wouldn't have to worry about this if you were running Windows; the most secure platform.



scuzzyneighbour
#3 26-09-2014, 15:15:21 PM
0 Members and 1 Guest are viewing this topic.