Re: Shellshock, bug bash ...

"Davide D'Amico" <[email protected]> Fri, 26 Sep 2014 08:09:19 +0100
Newsgroups gmane.os.freebsd.italian.varie
Message-ID <CAHykR+K0JSk5RfVy2d1P1fC02BZHY8WsW_3CVu-hW+ffW5eBug@mail.gmail.com>
--===============4642977403254497714==
Content-Type: multipart/alternative; boundary=001a11c37e8c8b82310503f2984d

--001a11c37e8c8b82310503f2984d
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Non credo colpisca apache di per s=C3=A8, quanto i server (routerini, etc e=
tc)
con script cgi che usano bash.
 On 26 Sep 2014 08:00, "Gianmarco Giovannelli" <[email protected]> wrote:

> >A "deadly serious" bug potentially affecting hundreds of millions of
> >computers, servers and devices has been discovered.
> >
> >The flaw has been found in a software component known as Bash, which
> >is a part of many Linux systems as well as Apple's Mac operating system.
> >
> >The bug, dubbed Shellshock, can be used to remotely take control of
> >almost any system using Bash, researchers said.
> >
> >Experts said it was more serious than the Heartbleed bug discovered in
> April.
> >
> >"Whereas something like Heartbleed was all about sniffing what was
> >going on, this was about giving you direct access to the system," Prof
> >Alan Woodward, a security researcher from the University of Surrey,
> >told the BBC.
> >
> >"The door's wide open."
> >
> >Some 500,000 machines worldwide were thought to have been vulnerable
> >to Heartbleed. But early estimates, which experts said were
> >conservative, suggest that Shellshock could hit at least 500 million
> machines.
> >
> >The problem is particularly serious given that many web servers are
> >run using the Apache system, software which includes the Bash component.
>
>
> Fonti varie sul web:
> https://www.us-cert.gov/ncas/current-activity/2014/09/24/
> Bourne-Again-Shell-Bash-Remote-Code-Execution-Vulnerability
> http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html
>
> Io uso tcsh e non mi tange, pero' sembra che affligga anche altri
> componenti third party (tipo apache, che non uso comunque :-)
>
>
> Best Regards,
> Gianmarco Giovannelli ,  "Unix expert since yesterday"
> http://utenti.gufi.org/~gmarco/
>
>
> _______________________________________________
> Varie mailing list
> [email protected]
> http://mailman.gufi.org/mailman/listinfo/varie
>

--001a11c37e8c8b82310503f2984d
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<p dir=3D"ltr">Non credo colpisca apache di per s=C3=A8, quanto i server (r=
outerini, etc etc) con script cgi che usano bash.<br>
</p>
<div class=3D"gmail_quote">On 26 Sep 2014 08:00, &quot;Gianmarco Giovannell=
i&quot; &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrot=
e:<br type=3D"attribution"><blockquote class=3D"gmail_quote" style=3D"margi=
n:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">&gt;A &quot;deadl=
y serious&quot; bug potentially affecting hundreds of millions of<br>
&gt;computers, servers and devices has been discovered.<br>
&gt;<br>
&gt;The flaw has been found in a software component known as Bash, which<br=
>
&gt;is a part of many Linux systems as well as Apple&#39;s Mac operating sy=
stem.<br>
&gt;<br>
&gt;The bug, dubbed Shellshock, can be used to remotely take control of<br>
&gt;almost any system using Bash, researchers said.<br>
&gt;<br>
&gt;Experts said it was more serious than the Heartbleed bug discovered in =
April.<br>
&gt;<br>
&gt;&quot;Whereas something like Heartbleed was all about sniffing what was=
<br>
&gt;going on, this was about giving you direct access to the system,&quot; =
Prof<br>
&gt;Alan Woodward, a security researcher from the University of Surrey,<br>
&gt;told the BBC.<br>
&gt;<br>
&gt;&quot;The door&#39;s wide open.&quot;<br>
&gt;<br>
&gt;Some 500,000 machines worldwide were thought to have been vulnerable<br=
>
&gt;to Heartbleed. But early estimates, which experts said were<br>
&gt;conservative, suggest that Shellshock could hit at least 500 million ma=
chines.<br>
&gt;<br>
&gt;The problem is particularly serious given that many web servers are<br>
&gt;run using the Apache system, software which includes the Bash component=
.<br>
<br>
<br>
Fonti varie sul web:<br>
<a href=3D"https://www.us-cert.gov/ncas/current-activity/2014/09/24/Bourne-=
Again-Shell-Bash-Remote-Code-Execution-Vulnerability" target=3D"_blank">htt=
ps://www.us-cert.gov/ncas/<u></u>current-activity/2014/09/24/<u></u>Bourne-=
Again-Shell-Bash-<u></u>Remote-Code-Execution-<u></u>Vulnerability</a><br>
<a href=3D"http://www.troyhunt.com/2014/09/everything-you-need-to-know-abou=
t.html" target=3D"_blank">http://www.troyhunt.com/2014/<u></u>09/everything=
-you-need-to-<u></u>know-about.html</a><br>
<br>
Io uso tcsh e non mi tange, pero&#39; sembra che affligga anche altri compo=
nenti third party (tipo apache, che non uso comunque :-)<br>
<br>
<br>
Best Regards,<br>
Gianmarco Giovannelli ,=C2=A0 &quot;Unix expert since yesterday&quot;<br>
<a href=3D"http://utenti.gufi.org/~gmarco/" target=3D"_blank">http://utenti=
.gufi.org/~<u></u>gmarco/</a><br>
<br>
<br>
______________________________<u></u>_________________<br>
Varie mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br>
<a href=3D"http://mailman.gufi.org/mailman/listinfo/varie" target=3D"_blank=
">http://mailman.gufi.org/<u></u>mailman/listinfo/varie</a><br>
</blockquote></div>

--001a11c37e8c8b82310503f2984d--


--===============4642977403254497714==
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

_______________________________________________
Varie mailing list
[email protected]
http://mailman.gufi.org/mailman/listinfo/varie

--===============4642977403254497714==--