On Wednesday CERT (US Computer Emergency Readiness Team) released an alert about a bug discovered in the Linux tool Bash.
From what I have read so far this looks like it could spread rapidly.As of Thursday, multiple attacks were already taking advantage of that vulnerability, a long-standing but undiscovered bug in the Linux and Mac tool Bash that makes it possible for hackers to trick Web servers into running any commands that follow a carefully crafted series of characters in an HTTP request.
If you run your own servers you may want to look into this.
Red Hat originally had a patch but that can be circumvented.
[quoter]But Kaspersky’s Schouwenberg recommended that server administrators still implement the existing patch; While it’s not a complete cure for the shellshock problem, he says it does block the exploits he’s seen so far. [/quote]
More on this can be found here: http://www.wired.com/2014/09/hackers...-ddos-attacks/
Hopefully most manufactures and the community as a whole will get working patches out quickly.
I have not yet had much time to do a lot of research into this, so if anyone has and can shed some light please do so.
Rick
Universal4


LinkBack URL
About LinkBacks
Reply With Quote

