Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Mon Sep 29, 2014, 12:03 PM Sep 2014

Worse Than Heartbleed? Meet ShellShock: A New Security Threat For OS X and Linux

http://www.makeuseof.com/tag/worse-than-heartbleed-meet-shellshock-a-new-security-threat-for-os-x-and-linux/

Matthew Hughes
On 26th September, 2014
Linux, Mac OS X, Security Matters

A serious security issue with the Bash shell – a major component of both most UNIX-like operating systems – has been discovered, with significant implications for computer security worldwide.

The issue is present in all versions of the Bash scripting language up to version 4.3, which effects a majority of Linux machines, and the entirety of computers running OS X. and can see an attacker exploiting this issue to launch their own code.

Curious about how it works and how to protect yourself? Read on for more information.

What Is Bash?

Bash (standing for Bourne Again Shell) is the default command line interpreter used on most Linux and BSD distributions, in addition to OS X. It is used as a method of launching programs, using system utilities and interacting with the underlying operating system by launching commands.

much more at link above
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Worse Than Heartbleed? Meet ShellShock: A New Security Threat For OS X and Linux (Original Post) steve2470 Sep 2014 OP
For some Linux distributions this has already been patched. The test in RKP5637 Sep 2014 #1
my pleasure, I'm always happy to help my fellow DU'ers.... steve2470 Sep 2014 #2
Apple needs to get on the ball with this one. TM99 Sep 2014 #3
It took me about 5 minutes to fix the problem myself justiceischeap Sep 2014 #5
Yeah, I fixed it myself as well, but TM99 Sep 2014 #7
Thanks for this. Just updated bash. justiceischeap Sep 2014 #4
bump nt steve2470 Sep 2014 #6

RKP5637

(67,111 posts)
1. For some Linux distributions this has already been patched. The test in
Mon Sep 29, 2014, 12:12 PM
Sep 2014

the link you sent is great!!! Thanks for posting this !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

steve2470

(37,457 posts)
2. my pleasure, I'm always happy to help my fellow DU'ers....
Mon Sep 29, 2014, 12:17 PM
Sep 2014

whether it's weather geekery or computer geekery

 

TM99

(8,352 posts)
3. Apple needs to get on the ball with this one.
Mon Sep 29, 2014, 12:23 PM
Sep 2014

Over the last 48 hours, Linux distro after Linux distro have been pushing out patches and updates for this.

Mac OS X is still vulnerable, and Apple has yet to push through their update system, a fix.

I use all three systems - Mac, Windows & several Linux distro's. Open Source does have some advantages with a community that is fixing these flaws and vulnerabilities almost as quickly as they are found. Windows has gotten better. Apple, well, seems more focused on 'bendgate' right now.

 

TM99

(8,352 posts)
7. Yeah, I fixed it myself as well, but
Mon Sep 29, 2014, 01:45 PM
Sep 2014

the majority of Apple users can't and won't know how to do. Until they push a fix out through Apple Updates, millions of systems are going to vulnerable.

Additionally, to fix this manually by the user requires install XCode. That's a pretty big deal for most Apple users who are just not tech savvy.

Latest Discussions»General Discussion»Worse Than Heartbleed? Me...