Username: Password:

Author Topic: Shellshock flaw in Unix systems  (Read 2254 times)

altuixde

  • Producer
  • *****
  • Posts: 779
Shellshock flaw in Unix systems
« on: September 25, 2014, 09:15:57 pm »
http://www.macworld.com/article/2687857/bigger-than-heartbleed-shellshock-flaw-leaves-os-x-linux-more-open-to-attack.html

This article explains the problem. Mac users should leave Remote Login off until Apple patches the flaw (or until you compile a patched version of Bash). Remote Login is in the Sharing pane of System Preferences. Patches for various Linux variants are already being pushed out.

I wonder what the fallout due to this flaw will be. Home computers won't be directly affected as much as servers that people access remotely.
« Last Edit: September 25, 2014, 09:49:17 pm by altuixde »

animagic4u

  • Producer
  • *****
  • Posts: 2810
  • #seiyuusports
    • Blog
Re: Shellshock flaw in Unix systems
« Reply #1 on: September 25, 2014, 10:37:37 pm »
I'm worried for my friends and professor's servers but personal computers should be okay.
I have no reason to remote log in to my computer (as it is a laptop) but hopefully all my uni's servers will be safe.

DeviantProtagonist

  • Producer
  • *****
  • Posts: 998
  • 本当にありがとう, あずみん.
Re: Shellshock flaw in Unix systems
« Reply #2 on: September 25, 2014, 11:18:47 pm »
Heartbleed issues in itself were already something fierce, so here's to hoping this doesn't escalate any further. Android looks to be in the clear, at least.
Suddenly, bow-wow-wow~. :3

altuixde

  • Producer
  • *****
  • Posts: 779
Re: Shellshock flaw in Unix systems
« Reply #3 on: September 26, 2014, 08:34:13 pm »
I should add that routers may be affected also, so it would be wise to check for an update (and keep checking if there isn't one) for your router. An update isn't necessary if your router wasn't vulnerable in the first place.

chikorita157

  • Member
  • ***
  • Posts: 234
  • わたし、気になります!
    • Chikorita157's Anime Blog
Re: Shellshock flaw in Unix systems
« Reply #4 on: September 28, 2014, 10:19:52 pm »
I have heard of this bug several days ago, but fortunately I already patched all my Macbook Pros and the Linux VPS that is hosting my Anime blog. But considering that there has been two large scale bugs with open source software, I think companies need to realize that open source does not equal security and that the open source community needs to do a better job auditing their source code.

Fortunately, I have patched immediately (and even wrote a script to automate it) so there won't be much of an effect.

animagic4u

  • Producer
  • *****
  • Posts: 2810
  • #seiyuusports
    • Blog
Re: Shellshock flaw in Unix systems
« Reply #5 on: September 28, 2014, 10:21:59 pm »
It's good that you patched your VPS so quickly. I still haven't patched my MacBook yet, but really don't feel like there's much risk on my personal laptop.

altuixde

  • Producer
  • *****
  • Posts: 779
Re: Shellshock flaw in Unix systems
« Reply #6 on: October 02, 2014, 12:15:22 am »
Apple has released patches for various versions of OS X:

http://www.macworld.com/article/2689432/apple-patches-bash-vulnerability-in-os-x.html

Last time I checked, this update was not showing up in Software Update or the Updates section of the Mac App Store. Downloading the package installer yourself is, for now, apparently the only way to apply Apple's patch.