Exaggeration or dangerous?

Anything goes in here.....
Post Reply
User avatar
tut
Barefoot Ninja
Posts: 22975
Joined: Tue Mar 15, 2005 5:53 pm
Location: Tut End, Glen of Newmill

Exaggeration or dangerous?

Post by tut » Thu Sep 25, 2014 8:52 pm

Usually do not get warnings for Linux and Mac.

http://www.bbc.co.uk/news/technology-29361794

tut

User avatar
Ferg
Posts: 3966
Joined: Fri Sep 04, 2009 11:56 pm
Location: Auld Reekie

Re: Exaggeration or dangerous?

Post by Ferg » Thu Sep 25, 2014 9:25 pm

CESG have rated this as high as HeartBleed in severity.

User avatar
robin
Jedi Master
Posts: 10546
Joined: Mon Mar 27, 2006 1:39 pm

Re: Exaggeration or dangerous?

Post by robin » Thu Sep 25, 2014 9:38 pm

In fact both use bash so in a sense both are vulnerable (as would be a windows machine running bash, though these are few and far between I suspect).

It's pretty technical and all of the exploits I have seen discussed rely on compromising a web server that uses bash to implement CGI scripts, a somewhat outmoded technique and anyone still doing it would surely be running inside some form of sandbox (if you run apache web server as super user and allow CGI scripts access to your root filesystem, you will get everything you deserve).

Systems that use bash are not inherently vulnerable - so just 'cos your macbook has bash (which it does) does not mean it's vulnerable - there is no network access to your macbook, and if there was, it would be protected by ssh, etc., etc., etc. You can exercise the vulnerability, if you want, just to prove to yourself that it exists ... let me know if you want to know how.

So it's a real issue but not one I would spend a lot of time worrying about unless I was running a server farm.

Cheers,
Robin
I is in your loomz nibblin ur wirez
#bemoretut

User avatar
tut
Barefoot Ninja
Posts: 22975
Joined: Tue Mar 15, 2005 5:53 pm
Location: Tut End, Glen of Newmill

Re: Exaggeration or dangerous?

Post by tut » Thu Sep 25, 2014 10:14 pm

I suspected that it would not be aimed at the average plug and play home user, but internet fraud, stolen identity, credit card and bank account accessing, all seem to be getting more prevalent with more people going electronic with no idea of how vulnerable they can be leaving themselves.

Hard to sympathise at times when they pass all their CC and bank details to someone who rings them up and asks for them. And look at the profit you can make buying plots of land in the Rain Forest, or shares in a new diamond mine in Olongapo.

tut

User avatar
robin
Jedi Master
Posts: 10546
Joined: Mon Mar 27, 2006 1:39 pm

Re: Exaggeration or dangerous?

Post by robin » Fri Sep 26, 2014 4:51 pm

Damn, I missed out on the Olongapo diamond mine ... did you manage to get some? Want to sell?

Cheers,
Robin
I is in your loomz nibblin ur wirez
#bemoretut

User avatar
tut
Barefoot Ninja
Posts: 22975
Joined: Tue Mar 15, 2005 5:53 pm
Location: Tut End, Glen of Newmill

Re: Exaggeration or dangerous?

Post by tut » Fri Sep 26, 2014 6:05 pm

Fcuk off, they will be worth a fortune. I was in Olongapo in 1967 on one of the biggest combined Forces Exercises ever carried out.

Main Street was bar, brothel, restaurant, Americans scored three dead from bar fights where they think that they can take on anybody, we lost one RM but took out five in return, great times.

tut

Post Reply