>
>to check whether you are vulnerable, enter:
>env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
>
>(A new version of BASH came in this mornings update)
Didn't find your answer? Ask the community — no account required.
P
Phil Hobbs
Yup. For both CentOS 6.5 and Cygwin. Not that I run any web servers myself, of course....
Cheers
Phil Hobbs
Dr Philip C D Hobbs
Principal Consultant
ElectroOptical Innovations LLC
Optics, Electro-optics, Photonics, Analog Electronics
160 North State Road #203
Briarcliff Manor NY 10510
hobbs at electrooptical dot net
http://electrooptical.net
M
Maynard A. Philbrook Jr.
I find it ironic that people would call it a bug since it's been around for so long.
Just another back door exposed and another one will be created to fill its place.
Jamie
D
DecadentLinuxUserNumeroUno
On Sat, 27 Sep 2014 12:47:02 -0400, "Maynard A. Philbrook Jr." Gave us:
BASH has, but has the bug?
I think you lack a certain grasp of computer science with that claim.
P
Phil Hobbs
What's ironic about that?
Cheers
Phil Hobbs
Dr Philip C D Hobbs
Principal Consultant
ElectroOptical Innovations LLC
Optics, Electro-optics, Photonics, Analog Electronics
160 North State Road #203
Briarcliff Manor NY 10510
hobbs at electrooptical dot net
http://electrooptical.net
P
Phil Hobbs
People have been warning against using shell scripts for CGI since the early days of the Web, but some folks didn't get the message.
Cheers
Phil Hobbs
Dr Philip C D Hobbs
Principal Consultant
ElectroOptical Innovations LLC
Optics, Electro-optics, Photonics, Analog Electronics
160 North State Road #203
Briarcliff Manor NY 10510
hobbs at electrooptical dot net
http://electrooptical.net
M
Maynard A. Philbrook Jr.
As they say, it's not a bug , it's a feature.
I went and found an article on it and it appears to operate from values in the environment variable settings that bash should not be executing as commands.
I have such a suspicious personality, so I think every one is guilty of something. I can't blow this off as mere coincidence, since it's been around for so long.
After reading how other UNIX type OS's may have this same problem, it looks like a lot of copy and pasting of code! Wouldn't you have thought that the shell would of been fixed for other platforms using the UNIX style OS?
Jamie
M
Maynard A. Philbrook Jr.
Computer science, ha. Another yuppie...
Jamie
D
Don Y
Rather, copying of *ideas*. And, failing to see the flaws in those ideas (or, ways of protecting against them).
Why do we still see buffer overrun problems in code? C'mon, that's a no-brainer! Yet people still use fixed size buffers and don't take steps to ensure only "5 pounds" gets stuffed into that (5 lb) bag!
D
DecadentLinuxUserNumeroUno
On Sat, 27 Sep 2014 16:03:42 -0400, "Maynard A. Philbrook Jr." Gave us:
You're an idiot, and not far from fitting The SlowTard's description of you.
Try thinking before you spew. Perhaps gain a reprieve.
M
Maynard A. Philbrook Jr.
Oh I did all thinking that was required, you're still a yuppie!
Jamie
D
DecadentLinuxUserNumeroUno
On Sat, 27 Sep 2014 21:00:38 -0400, "Maynard A. Philbrook Jr." Gave us:
You are still retarded. I was out of school before the term was even coined. So much for your capacity to guess weight, circus clown.
J
Jan Panteltje
On a sunny day (Sat, 27 Sep 2014 12:47:02 -0400) it happened "Maynard A. Philbrook Jr." wrote in :
I dont use bash, but zsh shell, and that is positive too: # env x='() { :;}; echo vulnerable' bash -c "echo this is a test" vulnerable this is a test
So I remaned /bin/bash /bin/somethingelse # env x='() { :;}; echo vulnerable' bash -c "echo this is a test" env: bash: No such file or directory
logical...
and tried the test again with zsh: # env x='() { :;}; echo vulnerable' zsh -c "echo this is a test" this is a test
Seems zsh is clean. To bad a zillion scripts need bash, or have bash specified
so.... But they already know everything. eeeeh, almost... ? :-) oops need to check those logs again.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.