Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,194,685 members, 7,955,552 topics. Date: Sunday, 22 September 2024 at 09:09 AM

Bash Shell Vulnerability Affects Linux, Unix And Mac OS X - Programming (2) - Nairaland

Nairaland Forum / Science/Technology / Programming / Bash Shell Vulnerability Affects Linux, Unix And Mac OS X (13257 Views)

Bash/shell Scripting In A Unix/linux Environment / Bash Shell Vulnerability Affects Linux,unix And Mac OS X / Iphone,ipad And MAC OS App Designers,where Art Thou? (2) (3) (4)

(1) (2) (3) (4) (Reply) (Go Down)

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Nobody: 7:28pm On Sep 26, 2014
undecided
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Austindark(m): 7:28pm On Sep 26, 2014
lilprinze: h
tanx for ur wonderful contribution
brief n to d point

4 Likes

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by DonaldGenes(m): 7:29pm On Sep 26, 2014
Wow! How come? However, iKnow Linux OS hardly get crack into and for years no Known virus Attack has been seen because of its excellent security features
Let me run the script on my Linux OS



Oh boy, ehh ,shiiiiiiit mehn

Some people have called this vulnerability, "worse than Heartbleed" and that is saying something but based on my understanding of the bug, the discussions on the bug-bash mailing list and experience as a user of GNU/Linux, I'd say this statement is very true. Shellshock is capable of much more than Heartbleed.

To give you an idea of how bad this is:
CERT/NIST reveal level 10 bash alert today, 24 September 2014
A level 10 alert for this bug, that has to get your heart pumping.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by omenka(m): 7:29pm On Sep 26, 2014
All I can see there is "13?bbvekla v kamierbhs kauierbvs k kla laoierhb nnay 32c nsdjkjk!! Ja u haheuyn hjaay kardashian aeyew"!!

What language is that

2 Likes

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Nobody: 7:30pm On Sep 26, 2014
victorazy:

Are we learning ABCD?
you never see anything
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by dabayomi(m): 7:30pm On Sep 26, 2014
Lemmi walk away ...
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Chidexter(m): 7:31pm On Sep 26, 2014
victorazy:

Is that the size of ur brain?
lol
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Rufex07(m): 7:31pm On Sep 26, 2014
many reading the post op posted will be like: I don't even understand anything he is saying.

But that's a serious issue brought to the public notice. thanks op.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by victorazy(m): 7:32pm On Sep 26, 2014
merieam16: tankz buh wz dat d explainatn

Where u dey make I see if we can relate!
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by kennedyugo: 7:32pm On Sep 26, 2014
Read it this morning. Great a patch has been released immediately. Linux still rules!

Ubuntu and Android all the way!

1 Like

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by kramer: 7:33pm On Sep 26, 2014
otijah: @op I swear u didn't even und what you posted, neigther do I, but all am saying iS no bash or born again Shell weapon formed against NL Shall prosper. Say amen by clicking like

Smh, Are you that desperate for likes?
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by XuteSleeks(m): 7:39pm On Sep 26, 2014
Now I see why the 'tech' threads hardly make front page. smiley

Important enlightenment though.

Thanks.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Nobody: 7:40pm On Sep 26, 2014
The Cross-site scripting (XSS) vulnerability has been on for a while now and has been used to bypass access controls to inject malicious scripts to servers. The malicious scripts can be used to do a lot of harm to the server even for use of botnets etc.

Solution is to scan your server for the vul and patch the shit. That's it.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by angelo82: 7:44pm On Sep 26, 2014
ikp4succes: how am i not sure that command will not bring d virus lol

Exactly it will bring it……Mac I am very sure of is not vulnerable to any virus…..
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by pat077: 7:45pm On Sep 26, 2014
i rep team #microsoft.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Enouwem(m): 7:47pm On Sep 26, 2014
Billyonaire: The Cross-site scripting (XSS) vulnerability has been on for a while now and has been used to bypass access controls to inject malicious scripts to servers. The malicious scripts can be used to do a lot of harm to the server even for use of botnets etc.

Solution is to scan your server for the vul and patch the shit. That's it.
XSS ?
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by ITbomb(m): 7:49pm On Sep 26, 2014
Where are the anti windows fanatics wit their unhackable OS.

Let me get on the practicals, I will be back
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by DonaldGenes(m): 7:50pm On Sep 26, 2014
pat077: i rep team #microsoft.

Microsoft OS is not always secured, do you know I can remotely shut down your system if I know your IP address?

Have you seen that simple CMD promt code before?
C:\shutdown /i

1 Like

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by jjwaterfalls(f): 7:53pm On Sep 26, 2014
otijah: @op I swear u didn't even und what you posted, neigther do I, but all am saying iS no bash or born again Shell weapon formed against NL Shall prosper. Say amen by clicking like

I didn't undestand it either. sad
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by barsharl(m): 7:54pm On Sep 26, 2014
grin do you mean bash anything bashable? Anyways, that's my nickname *winks
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by ITbomb(m): 7:55pm On Sep 26, 2014
DonaldGenes:

Microsoft OS is not always secured, do you know I can remotely shut down your system if I know your IP address?

Have you seen that simple CMD promt code before?
C:\shutdown /i
Guy you no fit, shutting down a private ip address node needs more than that
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by 360command: 7:56pm On Sep 26, 2014
No matter the level of security, hackers and scammers must find way enter.

1 Like

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by chmod777: 7:57pm On Sep 26, 2014
Kali kali kali. Metasploit metasploit!
the quieter u become the more u are able ti hear. This post is actually not for everyonr.
For othrs, pls note that vulnerability in any system was never as a result of design incompetence.
DonaldGenes: Wow! How come? However, iKnow Linux OS hardly get crack into and for years no Known virus Attack has been seen because of its excellent security features
Let me run the script on my Linux OS



Oh boy, ehh ,shiiiiiiit mehn

Some people have called this vulnerability, "worse than Heartbleed" and that is saying something but based on my understanding of the bug, the discussions on the bug-bash mailing list and experience as a user of GNU/Linux, I'd say this statement is very true. Shellshock is capable of much more than Heartbleed.

To give you an idea of how bad this is:
CERT/NIST reveal level 10 bash alert today, 24 September 2014
A level 10 alert for this bug, that has to get your heart pumping.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by DonaldGenes(m): 7:58pm On Sep 26, 2014
merieam16: Wat er dis 1ce sayin undecided,sumbori pls explain


In Bash, You can Literally define an environment variable which is a function.. You get it now? Lol

proof-of-concept of this attack:
$ env x='() { :;}; echo vulnerable'  bash -c "echo this is a test


Ask your boyfriend to show you what that means
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Johnnoo(m): 8:00pm On Sep 26, 2014
Agent Smith
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by DonaldGenes(m): 8:03pm On Sep 26, 2014
ITbomb:
Guy you no fit, shutting down a private ip address node needs more than that
I can IT. I tried it on my sister

You can do that by adding the list of computers that you wish to and set the parameters Luke time to prompt the other computer that the system will shutdown in like say 5mins....


That's all
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by ClintonNzedimma(m): 8:04pm On Sep 26, 2014
victorazy:

Is that the size of ur brain?

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by merieam16(f): 8:08pm On Sep 26, 2014
DonaldGenes:


In Bash, You can Literally define an environment variable which is a function.. You get it now? Lol

proof-of-concept of this attack:
$ env x='() { :;}; echo vulnerable'  bash -c "echo this is a test


Ask your boyfriend to show you what that means
tankz grin
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Nobody: 8:09pm On Sep 26, 2014
Enouwem: [img]http://1.bp..com/-VQ8KDBhjMDM/VCPBgN-AVvI/AAAAAAAAgd8/TLel5x_Xmeo/s728/bash-shellshock.png[/img]

A Critical remotely exploitable vulnerability has been discovered in the
widely used Linux and Unix command-line
shell, known as Bash , aka the GNU
Bourne Again Shell, leaving countless
websites, servers, PCs, OS X Macs, various
home routers, and many more open to the
cyber criminals.
Earlier today, Stephane Chazelas publicly
disclosed the technical details of the
remote code execution vulnerability in
Bash which affects most of the Linux
distributions and servers worldwide.
REMOTELY EXPLOITABLE SHELLSHOCK
The vulnerability (CVE-2014-6271)
affects versions 1.14 through 4.3 of GNU
Bash and being named as Bash Bug, and
Shellshock by the Security researchers on
the Internet discussions.
According to the technical details, a
hacker could exploit this bash bug to
execute shell commands remotely on a
target machine using specifically crafted
variables. “In many common
configurations, this vulnerability is
exploitable over the network, ” Stephane
said.
This 22-year-old vulnerability stems from
the way bash handles specially-formatted
environment variables, namely exported
shell functions. When assigning a function
to a variable, trailing code in the function
definition will be executed.
BASH BUG AFFECTS MILLIONS OF
SYSTEMS

While bash is not directly used by remote
users, but it is a common shell for
evaluating and executing commands from
other programs, such as web server or the
mail server. So if an application calls the
Bash shell command via web HTTP or a
Common-Gateway Interface (CGI) in a
way that allows a user to insert data, the
web server could be hacked.
In Simple words, If Bash has been
configured as the default system shell, an
attacker could launch malicious code on
the server just by sending a specially
crafted malicious web request by setting
headers in a web request, or by setting
weird mime types. Proof-of-concept code
for cgi-bin reverse shell has been posted
on the Internet.
Similar attacks are possible via
OpenSSH, “We have also verified
that this vulnerability is exposed in
ssh—but only to authenticated
sessions. Web applications like cgi-
scripts may be vulnerable based on
a number of factors; including
calling other applications through a
shell, or evaluating sections of code
through a shell.” Stephane warned.
But if an attacker does not have an
SSH account this exploit would not
work.
This is a serious risk to Internet
infrastructure, just like Heartbleed bug,
because Linux not only runs the majority
of the servers but also large number of
embedded devices, including Mac OS X
laptops and Android devices are also
running the vulnerable version of bash
Software. NIST vulnerability database has
rated this vulnerability “10 out of 10” in
terms of severity.
HOW TO CHECK FOR VULNERABLE
SHELL

To determine if a Linux or Unix system is
vulnerable, run the following command
lines in your linux shell:
env X="() { :;} ; echo
shellshock" /bin/sh -c "echo
completed"
env X="() { :;} ; echo shellshock"
`which bash` -c "echo
completed"

If you see the words "shellshock" in the
output, errrrr… then you are at risk.
BASH BUG PATCH
You are recommended to disable any CGI
scripts that call on the shell, but it does
not fully mitigate the vulnerability. Many
of the major operating system and Linux
distribution vendors have released the
new bash software versions today,
including:
Red Hat Enterprise Linux (versions 4
through 7) and the Fedora distribution
CentOS (versions 5 through 7)
Ubuntu 10.04 LTS, 12.04 LTS, and
14.04 LTS
Debian
If your system is vulnerable to bash bug,
then you are highly recommended to
upgrade your bash software package as
soon as possible.
Source: http://thehackernews.com/2014/09/bash-shell-vulnerability-shellshock.html?m=1
intereting, thanks so much for sharing this info
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by mindworx: 8:17pm On Sep 26, 2014
Am sure we'll be few that will comment on this thread grin

Well, first, i probably never checked what shell am using for over 2 or more years now ....
Am not a Sys Admin but all my work is on that black screen everyday .. So, lemme check my shell ...

****_***_Nig_App4:/*******/Release10216/FDM+$ echo $SHELL
/usr/bin/ksh
****_***_Nig_App4:/*******/Release10216/FDM+$

Oh .. K-shell ?

So, am not vulnerable, right?

Okies.
Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Nobody: 8:20pm On Sep 26, 2014
Worse than the heartbleed bug they say.

1 Like

Re: Bash Shell Vulnerability Affects Linux, Unix And Mac OS X by Enouwem(m): 8:25pm On Sep 26, 2014
otijah: @op I swear u didn't even und what you posted, neigther do I, but all am saying iS no bash or born again Shell weapon formed against NL Shall prosper. Say amen by clicking like
I am just wondering how foreigners will rate us if they ever see this. #smh

1 Like

(1) (2) (3) (4) (Reply)

Most Used Mysql Database Functions / How To Build A Forum Website Like Nairaland .com / After 10days Of Coding With Html, Css And Javascript Forum4africa Is Ready

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 41
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.