Jump to content

Very compromising bug found in Bash utility, update: it seems to be worst that what it initially was

AlexGoesHigh

this one is bad gentlemen, to begin whit bash is...

GNU Bourne Again Shell (Bash), the command-line shell used in many Linux and Unix operating systems

which can be found in most GNU/linux OS's and unix systems, one of them being OS X, but what does the bug does,

The bug, discovered by Stephane Schazelas, is related to how Bash processes environmental variables passed by the operating system or by a program calling a Bash-based script. If Bash has been configured as the default system shell, it can be used by network–based attackers against servers and other Unix and Linux devices via Web requests, secure shell, telnet sessions, or other programs that use Bash to execute scripts.

in layman's terms it allows any kind of malicious scripts to be ran in the system and compromise everything in it, and due to its widespread use, this could affect as many servers/pc's that the heartbleed bug, there's no reason lose your shit, there's already a fix for it, which is already available for

Red Hat Enterprise Linux (versions 4 through 7) and the Fedora distribution

CentOS (versions 5 through 7)

Ubuntu 10.04 LTS, 12.04 LTS, and 14.04 LTS

Debian

and i'm assuming very soon for other distributions as well OSX, you can also confirm if your system is affect by running this in a terminal

There is an easy test to determine if a Linux or Unix system is vulnerable. To check your system, from a command line, type:

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
If the system is vulnerable, the output will be:
vulnerablethis is a test
An unaffected (or patched) system will output:
bash: warning: x: ignoring function definition attemptbash: error importing function definition for `x'this is a test

i'm not that much into linux but this does sound to be serious problem, which at least is already fixed, and not something threated as poorly as heartbleed, though i would run those prompts ASAP just to make sure

source: ars technica

update: it seems security experts are more concerned about this more that at first, mainly because the currently going patch just delays the attacks and not fixes the issue completely, you can read more at source since I'm on mobile atm, will format properly later when I can

source: http://www.theverge.com/2014/9/25/6843669/bash-shellshock-network-worm-could-cause-internet-meltdown

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

but windows is still just a really shitty os, right?

Yes. The very fact that you think this has anything to do with an OS is hilarious. Windows has had awful exploits too.

 

@IdeaStormer

 

This is when all the people who've been on zsh for years start giggling.

"You have got to be the biggest asshole on this forum..."

-GingerbreadPK

sudo rm -rf /

Link to comment
Share on other sites

Link to post
Share on other sites

Well it seems the fix for debian was out stupid fast as I don't have the vulnerability, and last updated I think yesterday.

Link to comment
Share on other sites

Link to post
Share on other sites

Except this is irrelevant for attackers when they can just do a FUD Java Drive-By.

Mein Führer... I CAN WALK !!

Link to comment
Share on other sites

Link to post
Share on other sites

Yes. The very fact that you think this has anything to do with an OS is hilarious. Windows has had awful exploits too.

@IdeaStormer

This is when all the people who've been on zsh for years start giggling.

What can zsh get you that bash can't?

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

What can zsh get you that bash can't?

Not much, but at least I don't have to deal with this vulnerability on my Linux boxes. I prefer the zsh language to bash also.

 

My OS X installation, however. I'm hoping 10.9.5.0.1 is released tomorrow to cover this. I tested it and it's vulnerable. Shame, Apple, shame! To be honest there's obviously not much they could have done about it, but seeing as this is the week of finding as many reasons as possible to hate them, I'm mad.

"You have got to be the biggest asshole on this forum..."

-GingerbreadPK

sudo rm -rf /

Link to comment
Share on other sites

Link to post
Share on other sites

New sensationalized, "gizmodoed" headline:

New Linux exploit could cause huge problems and many tears. 

Don't bend over in the shower. 

muh specs 

Gaming and HTPC (reparations)- ASUS 1080, MSI X99A SLI Plus, 5820k- 4.5GHz @ 1.25v, asetek based 360mm AIO, RM 1000x, 16GB memory, 750D with front USB 2.0 replaced with 3.0  ports, 2 250GB 850 EVOs in Raid 0 (why not, only has games on it), some hard drives

Screens- Acer preditor XB241H (1080p, 144Hz Gsync), LG 1080p ultrawide, (all mounted) directly wired to TV in other room

Stuff- k70 with reds, steel series rival, g13, full desk covering mouse mat

All parts black

Workstation(desk)- 3770k, 970 reference, 16GB of some crucial memory, a motherboard of some kind I don't remember, Micomsoft SC-512N1-L/DVI, CM Storm Trooper (It's got a handle, can you handle that?), 240mm Asetek based AIO, Crucial M550 256GB (upgrade soon), some hard drives, disc drives, and hot swap bays

Screens- 3  ASUS VN248H-P IPS 1080p screens mounted on a stand, some old tv on the wall above it. 

Stuff- Epicgear defiant (solderless swappable switches), g600, moutned mic and other stuff. 

Laptop docking area- 2 1440p korean monitors mounted, one AHVA matte, one samsung PLS gloss (very annoying, yes). Trashy Razer blackwidow chroma...I mean like the J key doesn't click anymore. I got a model M i use on it to, but its time for a new keyboard. Some edgy Utechsmart mouse similar to g600. Hooked to laptop dock for both of my dell precision laptops. (not only docking area)

Shelf- i7-2600 non-k (has vt-d), 380t, some ASUS sandy itx board, intel quad nic. Currently hosts shared files, setting up as pfsense box in VM. Also acts as spare gaming PC with a 580 or whatever someone brings. Hooked into laptop dock area via usb switch

Link to comment
Share on other sites

Link to post
Share on other sites

Well, I used Dash (Debian Almquist shell), so I'm not affected :P.

▶ Learn from yesterday, live for today, hope for tomorrow. The important thing is not to stop questioning. - Einstein◀

Please remember to mark a thread as solved if your issue has been fixed, it helps other who may stumble across the thread at a later point in time.

Link to comment
Share on other sites

Link to post
Share on other sites

but windows is still just a really shitty os, right?

My Ubuntu 14.04.1 install in VMWare which was updated last night is vulnerable to this.

 

Vuln.png

 

Just ran an update now and can confirm that it's fixed.

 

Fixed2.png

 

One of the big reasons why Linux is king of security over Windows, it gets updated nearly instantly once a serious issue arises.

Link to comment
Share on other sites

Link to post
Share on other sites

What can zsh get you that bash can't?

 

Well for starters...

 

1. Run every shell script known to man, well maybe not Zoidbert Shell :lol:  (Yes it exists) and Windows shell environments. By all shells I mean, ksh, csh, tcsh, bash, might of missed one or two.

2. You can configure it up the yin yang, so much that it will take you a good day to get it all configured just right, and by just right I mean to your very custom settings. Time well worth its weight in command shells.

3. If you think tab completion in bash is cool, well zsh has not only tab completion for file/programs but for program options B)  with man type explanations.

4. Its a modern shell, as in made for the future not the past.

 

Some References: http://www.zsh.org/

http://friedcpu.wordpress.com/2007/07/24/zsh-the-last-shell-youll-ever-need/

http://www.maclife.com/article/columns/terminal_101_better_shell_zsh

 

 

List of Command Shells: https://en.wikipedia.org/wiki/Comparison_of_command_shells

I roll with sigs off so I have no idea what you're advertising.

 

This is NOT the signature you are looking for.

Link to comment
Share on other sites

Link to post
Share on other sites

good thing my router and phone uses busybox

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

Well for starters...

1. Run every shell script known to man, well maybe not Zoidbert Shell :lol: (Yes it exists) and Windows shell environments. By all shells I mean, ksh, csh, tcsh, bash, might of missed one or two.

2. You can configure it up the yin yang, so much that it will take you a good day to get it all configured just right, and by just right I mean to your very custom settings. Time well worth its weight in command shells.

3. If you think tab completion in bash is cool, well zsh has not only tab completion for file/programs but for program options B) with man type explanations.

4. Its a modern shell, as in made for the future not the past.

Some References: http://www.zsh.org/

http://friedcpu.wordpress.com/2007/07/24/zsh-the-last-shell-youll-ever-need/

http://www.maclife.com/article/columns/terminal_101_better_shell_zsh

List of Command Shells: https://en.wikipedia.org/wiki/Comparison_of_command_shells

This is why I'm never embarrassed to ask questions. It's more valuable to be humble and learn than stay stubbornly in your own box.

Software Engineer for Suncorp (Australia), Computer Tech Enthusiast, Miami University Graduate, Nerd

Link to comment
Share on other sites

Link to post
Share on other sites

Except this is irrelevant for attackers when they can just do a FUD Java Drive-By.

It requires it is FUD.

Requires java.

Require you to run it.

Mostlikely are not compatible with linux.

sJDB have been fixed too, so it really is not that commonly used anymore.

Link to comment
Share on other sites

Link to post
Share on other sites

There is a patch out for Arch as well.

Don't think there is a patch for Cygwin.

 

Hopefully people will update their stuff quickly.

Link to comment
Share on other sites

Link to post
Share on other sites

New sensationalized, "gizmodoed" headline:

New Linux exploit could cause huge problems and many tears. 

Don't bend over in the shower. 

honestly blame the red hat guys even on their blog they made this sound like the end of the world... not in the title, but most publication would lose their shit whit what they where talking

https://securityblog.redhat.com/

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

@AlexGoesHigh

 

Thanks a lot for putting this here and detailing the vulnerability test... I would've ended up with a vulnerable laptop...

 

I'll notify my team about this too...

Link to comment
Share on other sites

Link to post
Share on other sites

For people running Ubuntu it's as simple as running

 

Sudo apt-get update

 

And then

 

Sudo apt-get upgrade.

 

All fixed, have fun!

CPU: Intel Core i7-4790k @ 4.7 1.3v  with a Corsair H80 w/Dual SP120s - Motherboard: MSI Z97 gaming 5 - RAM: 4x4 G.Skill Ripjaws X @ 1600 - GPU: Dual PowerColour R9 290- SSD: Samsung NVME SM951 256GB-- PSU: Corsair RM 1000  - Case: NZXT H440 Black/red - Keyboard: Coolermaster CM storm Quickfire TK, Cherry MX blues - Mouse: Logitech G502 - Heaphones: Beyerdynamic DT 770 - Monitors: 3x VE248H Eyefinity 1080P -  Phone: iPhone 6S Plus               Please post your specifications in your post, signature or even better, system page on your profile!

Link to comment
Share on other sites

Link to post
Share on other sites

This is why I'm never embarrassed to ask questions. It's more valuable to be humble and learn than stay stubbornly in your own box.

 

No! Ask questions, sure you stick your foot in your mouth but look now you have more info, we all learn it never stops.

I roll with sigs off so I have no idea what you're advertising.

 

This is NOT the signature you are looking for.

Link to comment
Share on other sites

Link to post
Share on other sites

Update op whit new info and source

this is one of the greatest thing that has happened to me recently, and it happened on this forum, those involved have my eternal gratitude http://linustechtips.com/main/topic/198850-update-alex-got-his-moto-g2-lets-get-a-moto-g-for-alexgoeshigh-unofficial/ :')

i use to have the second best link in the world here, but it died ;_; its a 404 now but it will always be here

 

Link to comment
Share on other sites

Link to post
Share on other sites

update: it seems security experts are more concerned about this more that at first, mainly because the currently going patch just delays the attacks and not fixes the issue completely, you can read more at source since I'm on mobile atm, will format properly later when I can

source: http://www.theverge.com/2014/9/25/6843669/bash-shellshock-network-worm-could-cause-internet-meltdown

 

Switching to a different shell isn't a viable solution? :huh:

I roll with sigs off so I have no idea what you're advertising.

 

This is NOT the signature you are looking for.

Link to comment
Share on other sites

Link to post
Share on other sites

New sensationalized, "gizmodoed" headline:

New Linux exploit could cause huge problems and many tears. 

Don't bend over in the shower. 

 

This section should have a "Sensationalist Writer of the Year" award. 

 

We have so many people who could actually work at Gizmodo based off sensationalism alone. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×