Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Shellshock Vulnerability Finally Patched as Exploits Emerge

    Written by

    Sean Michael Kerner
    Published September 30, 2014
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The Shellshock Bash (Bourne Again SHell) vulnerability that was first disclosed on Sept. 24 now has not one, but multiple publicly available patches.

      Initially, the Shellshock vulnerability was identified as single issue in CVE-2014-6271. While a patch was quickly available for CVE-2014-6271, that patch was incomplete and there were in fact other Shellshock vulnerabilities. One of the additional Shellshock vulnerabilities, identified as CVE-2014-7169, was not patched until late on Sept. 26.

      “It was found that the fix for CVE-2014-6271 was incomplete, and Bash still allowed certain characters to be injected into other environments via specially crafted environment variables,” Linux vendor Red Hat warned in an advisory. “An attacker could potentially use this flaw to override or bypass environment restrictions to execute shell commands.”

      Red Hat’s advisory added that the initial patch did not solve the issue of allowing unauthenticated access to certain applications and services, which could still be exploited by attackers.

      Bash provides a command-line shell for Unix and Linux systems and is also used in Apple’s Mac OS X. The Shellshock vulnerabilities are particularly risky in that if attackers exploit the flaws, they can remotely inject and execute arbitrary code on a vulnerable system.

      The Shellshock vulnerabilities are not just theoretical flaws either; they are being actively exploited by attackers. Security firm FireEye has reported what it called a “significant amount of overtly malicious traffic leveraging BASH.” Among the different Shellshock-related attacks that FireEye is now seeing are password stealing exploits as well as automated click fraud.

      Shellshock has been compared with the Heartbleed flaw that struck systems earlier this year. With Heartbleed, the open-source OpenSSL cryptographic library was found to be at risk. In the aftermath of Heartbleed, some pundits pointed to weakness in the open-source model. Others, including the Linux Foundation, rallied to provide new support to OpenSSL and other open-source efforts to improve security.

      The Bash program itself is also associated with the Free Software Foundation (FSF), which clearly sees open source as being able to deal with security incidents in an efficient manner.

      “Free software cannot guarantee your security, and in certain situations may appear less secure on specific vectors than some proprietary programs,” the FSF said in a statement. “As was widely agreed in the aftermath of the OpenSSL ‘Heartbleed’ bug, the solution is not to trade one security bug for the very deep insecurity inherently created by proprietary software—the solution is to put energy and resources into auditing and improving free programs.”

      While the Shellshock vulnerability was not fully patched until Sept. 26, Linux system administrators could have mitigated the vulnerability with another open-source technology known as SELinux (Security-Enhanced Linux). Originally an effort started by the National Security Agency (NSA) and landed in Linux kernels as far back as 2004, SELinux provides additional mandatory access controls for Linux.

      According to Red Hat’s resident SELinux expert Dan Walsh, a properly configured system would limit the risk of Shellshock exploits.

      “Now this is a horrible exploit but as you can see SELinux would probably have protected a lot/most of your valuable data on your machine,” Walsh blogged. “It would buy you time for you to patch your system.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×