Re: Shellshock, bug bash ...
"Davide D'Amico" <[email protected]> Fri, 26 Sep 2014 08:09:19 +0100
| Newsgroups | gmane.os.freebsd.italian.varie |
|---|---|
| Message-ID | <CAHykR+K0JSk5RfVy2d1P1fC02BZHY8WsW_3CVu-hW+ffW5eBug@mail.gmail.com> |
--===============4642977403254497714== Content-Type: multipart/alternative; boundary=001a11c37e8c8b82310503f2984d --001a11c37e8c8b82310503f2984d Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Non credo colpisca apache di per s=C3=A8, quanto i server (routerini, etc e= tc) con script cgi che usano bash. On 26 Sep 2014 08:00, "Gianmarco Giovannelli" <[email protected]> wrote: > >A "deadly serious" bug potentially affecting hundreds of millions of > >computers, servers and devices has been discovered. > > > >The flaw has been found in a software component known as Bash, which > >is a part of many Linux systems as well as Apple's Mac operating system. > > > >The bug, dubbed Shellshock, can be used to remotely take control of > >almost any system using Bash, researchers said. > > > >Experts said it was more serious than the Heartbleed bug discovered in > April. > > > >"Whereas something like Heartbleed was all about sniffing what was > >going on, this was about giving you direct access to the system," Prof > >Alan Woodward, a security researcher from the University of Surrey, > >told the BBC. > > > >"The door's wide open." > > > >Some 500,000 machines worldwide were thought to have been vulnerable > >to Heartbleed. But early estimates, which experts said were > >conservative, suggest that Shellshock could hit at least 500 million > machines. > > > >The problem is particularly serious given that many web servers are > >run using the Apache system, software which includes the Bash component. > > > Fonti varie sul web: > https://www.us-cert.gov/ncas/current-activity/2014/09/24/ > Bourne-Again-Shell-Bash-Remote-Code-Execution-Vulnerability > http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html > > Io uso tcsh e non mi tange, pero' sembra che affligga anche altri > componenti third party (tipo apache, che non uso comunque :-) > > > Best Regards, > Gianmarco Giovannelli , "Unix expert since yesterday" > http://utenti.gufi.org/~gmarco/ > > > _______________________________________________ > Varie mailing list > [email protected] > http://mailman.gufi.org/mailman/listinfo/varie > --001a11c37e8c8b82310503f2984d Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <p dir=3D"ltr">Non credo colpisca apache di per s=C3=A8, quanto i server (r= outerini, etc etc) con script cgi che usano bash.<br> </p> <div class=3D"gmail_quote">On 26 Sep 2014 08:00, "Gianmarco Giovannell= i" <<a href=3D"mailto:[email protected]">[email protected]</a>> wrot= e:<br type=3D"attribution"><blockquote class=3D"gmail_quote" style=3D"margi= n:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">>A "deadl= y serious" bug potentially affecting hundreds of millions of<br> >computers, servers and devices has been discovered.<br> ><br> >The flaw has been found in a software component known as Bash, which<br= > >is a part of many Linux systems as well as Apple's Mac operating sy= stem.<br> ><br> >The bug, dubbed Shellshock, can be used to remotely take control of<br> >almost any system using Bash, researchers said.<br> ><br> >Experts said it was more serious than the Heartbleed bug discovered in = April.<br> ><br> >"Whereas something like Heartbleed was all about sniffing what was= <br> >going on, this was about giving you direct access to the system," = Prof<br> >Alan Woodward, a security researcher from the University of Surrey,<br> >told the BBC.<br> ><br> >"The door's wide open."<br> ><br> >Some 500,000 machines worldwide were thought to have been vulnerable<br= > >to Heartbleed. But early estimates, which experts said were<br> >conservative, suggest that Shellshock could hit at least 500 million ma= chines.<br> ><br> >The problem is particularly serious given that many web servers are<br> >run using the Apache system, software which includes the Bash component= .<br> <br> <br> Fonti varie sul web:<br> <a href=3D"https://www.us-cert.gov/ncas/current-activity/2014/09/24/Bourne-= Again-Shell-Bash-Remote-Code-Execution-Vulnerability" target=3D"_blank">htt= ps://www.us-cert.gov/ncas/<u></u>current-activity/2014/09/24/<u></u>Bourne-= Again-Shell-Bash-<u></u>Remote-Code-Execution-<u></u>Vulnerability</a><br> <a href=3D"http://www.troyhunt.com/2014/09/everything-you-need-to-know-abou= t.html" target=3D"_blank">http://www.troyhunt.com/2014/<u></u>09/everything= -you-need-to-<u></u>know-about.html</a><br> <br> Io uso tcsh e non mi tange, pero' sembra che affligga anche altri compo= nenti third party (tipo apache, che non uso comunque :-)<br> <br> <br> Best Regards,<br> Gianmarco Giovannelli ,=C2=A0 "Unix expert since yesterday"<br> <a href=3D"http://utenti.gufi.org/~gmarco/" target=3D"_blank">http://utenti= .gufi.org/~<u></u>gmarco/</a><br> <br> <br> ______________________________<u></u>_________________<br> Varie mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a><br> <a href=3D"http://mailman.gufi.org/mailman/listinfo/varie" target=3D"_blank= ">http://mailman.gufi.org/<u></u>mailman/listinfo/varie</a><br> </blockquote></div> --001a11c37e8c8b82310503f2984d-- --===============4642977403254497714== Content-Type: text/plain; charset="iso-8859-1" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline _______________________________________________ Varie mailing list [email protected] http://mailman.gufi.org/mailman/listinfo/varie --===============4642977403254497714==--