This question is a means of preventing automated form submissions by spambots.
What are the l a s t four characters of "ab847ae805dc98184168c1a"? You must also add "xx!1.." to the answer but type "1" as a word not a number.
Smilies
:clap: :crazy: :thumbdown: :thumbup: :wtf: :yawn: :tired: :relaxed: :grin: :smile: :wink: :sad: :eek: :shock: :???: :cool: :lol: :mad: :razz: :oops: :cry: :evil: :twisted: :roll: :!: :?: :idea: :arrow: :neutral: :mrgreen: :geek: :ugeek: :eh: :lolno: :problem: :shh: :shifty: :sick: :silent: :think: :wave:
   

If you wish to attach one or more files enter the details below.

!, 2014-09-28 22:18 »

I wonder if this has been an "intentional" bug? You never know these days. :???:

!, 2014-09-28 06:22 »

24818BP~The-Simpsons-Nelson-Haha-Posters.jpg
24818BP~The-Simpsons-Nelson-Haha-Posters.jpg (24.1 KiB) Viewed 4117 times

Steven W, 2014-09-27 02:11 »

I forgot the link where the first few quotes are from:

http://www.troyhunt.com/2014/09/everyth ... about.html

Shellshock Bash Bug

Steven W, 2014-09-27 02:05 »

Apparently a potentially very serious 25 year old bug has been found in the bash shell.

...There are other shells out there for Unix variants, the thing about Bash though is that it's the default shell for Linux and Mac OS X which are obviously extremely prevalent operating systems. That's a major factor in why this risk is so significant - the ubiquity of Bash - and it's being described as "one of the most installed utilities on any Linux system".


The potential is enormous - "getting shell" on a box has always been a major win for an attacker because of the control it offers them over the target environment. Access to internal data, reconfiguration of environments, publication of their own malicious code etc. It's almost limitless and it's also readily automatable. There are many, many examples of exploits out there already that could easily be fired off against a large volume of machines.


Mr. Robert Graham's test early test results are a bit frightening:

http://blog.erratasec.com/2014/09/bash- ... mable.html

As he points out, someone is already using what he found to deliver malware:

Someone is using masscan to deliver malware. They'll likely have compromised most of the system I've found by tomorrow morning. If they using different URLs and fix the Host field, they'll get tons more.

Top