![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Just Doing My Own Thing
Industry Role:
Join Date: Jan 2011
Location: London, Spain, New Zealand, GFY - Not Croydon...
Posts: 25,106
|
Major security alert - Linux etc...
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
https://gfy.com/showthread.php?t=1150685
Heads up though, it doesn't look like the patch fixed it completely yet. http://www.reddit.com/r/netsec/comme...l_exploitable/
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
( ͡ʘ╭͜ʖ╮͡ʘ)
Industry Role:
Join Date: Mar 2004
Posts: 20,010
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Too lazy to set a custom title
Industry Role:
Join Date: Oct 2006
Location: Earth
Posts: 30,989
|
ah that sucks
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
♥♥♥ Likes Hugs ♥♥♥
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
|
https://access.redhat.com/node/1200223
If you're affected, mod_security is the best way to stop this right now. If you're not using mod_security, iptables can protect you a little better than doing nothing. iptables -I INPUT -m string --hex-string '|28 29 20 7B|' --algo bm -j DROP
__________________
I like pie. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Oct 2010
Location: Portugal
Posts: 1,262
|
To test if your version of Bash is vulnerable to this issue, run the following command:
$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test" If the output of the above command looks as follows: vulnerable this is a test you are using a vulnerable version of Bash. The patch used to fix this issue ensures that no code is allowed after the end of a Bash function. Thus, if you run the above example with the patched version of Bash, you should get an output similar to: $ env x='() { :;}; echo vulnerable' bash -c "echo this is a test" bash: warning: x: ignoring function definition attempt bash: error importing function definition for `x' this is a test
__________________
StagCMS - Adult CMS - user friendly adult content management system - speed up your websites with no SQL connections ICQ: 63*23*43*113 ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: May 2011
Location: San Diego
Posts: 328
|
already found people pinging to check for the exploit in my server logs ;[
update your servers asap! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,384
|
Code:
yum clean all && yum update bash
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |