Shellshock

Does exactly what it says on the tin. Some of the nonsense contained herein may be very loosely related to The Sisters of Mercy, but I wouldn't bet your PayPal account on it. In keeping with the internet's general theme nothing written here should be taken as Gospel: over three quarters of it is utter gibberish, and most of the forum's denizens haven't spoken to another human being face-to-face for decades. Don't worry your pretty little heads about it. Above all else, remember this: You don't have to stay forever. I will understand.
Post Reply
paint it black
Black, black, black & even blacker
Posts: 4964
Joined: 11 Jul 2002, 01:00

http://www.bbc.co.uk/news/technology-29361794

should i be worried? I find it so hard to keep up with these things. Will windows defender cope

thanks in advance
Goths have feelings too
User avatar
markfiend
goriller of form 3b
Posts: 21181
Joined: 11 Nov 2003, 10:55
Location: st custards
Contact:

should i be worried?
Probably

you might need to upgrade things like router firmware...
The fundamental cause of the trouble is that in the modern world the stupid are cocksure while the intelligent are full of doubt.
—Bertrand Russell
User avatar
eastmidswhizzkid
Faster Than The Light Of Speed
Posts: 9857
Joined: 24 Mar 2005, 00:01
Location: WhizzWorld
Contact:

so this doesn't affect windows users? or does it if it the servers we are using are affected?
Well I was handsome and I was strong
And I knew the words to every song.
"Did my singing please you?"
"No! The words you sang were wrong!"

:bat:
paint it black
Black, black, black & even blacker
Posts: 4964
Joined: 11 Jul 2002, 01:00

my very limited understanding is that yes if the server is running windows you are at risk :roll:

no firmware update for my router yet #danger of PIB being involved in goth fappening remains high
Goths have feelings too
Bartek
Underneath the Rock
Posts: 6126
Joined: 17 Sep 2005, 10:47

For once it's not so bad have Windows (7). :?
User avatar
nowayjose
Utterly Bastard Groovy Amphetamine Filth
Posts: 539
Joined: 19 Mar 2006, 02:15
Location: Berlin

This bug only affects a few corner cases, where for example, a web server hands through unsanitized user-provided stuff to the environment variables of a CGI script (which is a very bad idea in the first place) and similar situations.

Windows isn't affected (unless you run something like Cygwin on it and have a scenario like the above).

Rather exaggerated in the mainstream press, as usual. The 'heartbleed' bug was much worse.
User avatar
markfiend
goriller of form 3b
Posts: 21181
Joined: 11 Nov 2003, 10:55
Location: st custards
Contact:

Yeah Windows is actually safe, it's a Linux/unix exploit

The thing is, your broadband router might be vulnerable, depending on the model and network. Who knows what crappy cgi scripts get stuck on them?
The fundamental cause of the trouble is that in the modern world the stupid are cocksure while the intelligent are full of doubt.
—Bertrand Russell
User avatar
Dan
Overbomber
Posts: 2012
Joined: 25 Sep 2002, 01:00
Location: Leeds

Are Mac's affected? (I want to know if this is the one time windows users are able to say to a mac user "get a pc")! :P
User avatar
lazarus corporation
Lord Protector
Posts: 3440
Joined: 09 May 2004, 17:42
Location: out there on a darkened road
Contact:

Dan wrote:Are Mac's affected? (I want to know if this is the one time windows users are able to say to a mac user "get a pc")! :P
OSX is just a fork of the (normally free) Unix OS - people are just paying for the Apple brand name on top of free software - so yes, it affects Macs as well.
User avatar
Dan
Overbomber
Posts: 2012
Joined: 25 Sep 2002, 01:00
Location: Leeds

lazarus corporation wrote:so yes, it affects Macs as well.
Image
User avatar
nowayjose
Utterly Bastard Groovy Amphetamine Filth
Posts: 539
Joined: 19 Mar 2006, 02:15
Location: Berlin

lazarus corporation wrote: OSX is just a fork of the (normally free) Unix OS - people are just paying for the Apple brand name on top of free software - so yes, it affects Macs as well.
Not quite... most of OSX is original and was developped by Apple and NeXT (Steve Jobs' previous firm before he re-joined Apple). It is however true that it sits on a substrate of free software that was taken from the BSD, Mach and Gnu projects (largely developped at US universities and paid for by the American taxpayer).
User avatar
Pista
Cureboi
Posts: 17588
Joined: 25 Jun 2006, 15:03
Location: Lost In A Forest
Contact:

I can't help but think that these issues should be kept out of the press really.
At least until fixes/ patches are issued.
Originally the story alluded that machines "could" be compromised & now, a few days after much media coverage, machines "have" been compromised.
But I am curious to know how many would have been attacked had the bug not been plastered all over the news.
Cheers.
Steve
Just like the old days

TheCureCommunity
User avatar
markfiend
goriller of form 3b
Posts: 21181
Joined: 11 Nov 2003, 10:55
Location: st custards
Contact:

Security through obscurity? But the problem is, you're just assuming the black hats haven't already found the bug. It was certainly the case that the Heartbleed bug was being exploited for months before any of the white hats even knew it was there.
The fundamental cause of the trouble is that in the modern world the stupid are cocksure while the intelligent are full of doubt.
—Bertrand Russell
User avatar
Pista
Cureboi
Posts: 17588
Joined: 25 Jun 2006, 15:03
Location: Lost In A Forest
Contact:

I'm pretty sure that the black hats (or at least a few of them) have already found it.
Also pretty sure that some of them are employed by cyber security firms, but then that's my tin foil hat view.I just can't help thinking that the media coverage just brings a few more chancers to the party who just want to cause a bit of mischief.
I'm sure that if you go trawling the deep web, there are prolly thousands of these type of exploits out there that aren't reported in the press.
Cheers.
Steve
Just like the old days

TheCureCommunity
User avatar
eastmidswhizzkid
Faster Than The Light Of Speed
Posts: 9857
Joined: 24 Mar 2005, 00:01
Location: WhizzWorld
Contact:

Pista wrote:I'm pretty sure that the black hats (or at least a few of them) have already found it.
Also pretty sure that some of them are employed by cyber security firms, but then that's my tin foil hat view.
i dont know about tin-foil hats. you meet some pretty diverse and interesting people hitch-hiking;i was once picked up by a guy who just about fitted the description of a black-hat working for a cyber-security outfiit. and if half of what he told me (or alluded to) was straight up then its way beyond conspiracy theories.
Well I was handsome and I was strong
And I knew the words to every song.
"Did my singing please you?"
"No! The words you sang were wrong!"

:bat:
User avatar
Pista
Cureboi
Posts: 17588
Joined: 25 Jun 2006, 15:03
Location: Lost In A Forest
Contact:

:eek:

*Reaches for the off button*
Cheers.
Steve
Just like the old days

TheCureCommunity
User avatar
markfiend
goriller of form 3b
Posts: 21181
Joined: 11 Nov 2003, 10:55
Location: st custards
Contact:

Add to this the rather mañana attitude of most system administrators, and you've got a match made in hell.

It's a wonder the Internet even works at all. ;D
The fundamental cause of the trouble is that in the modern world the stupid are cocksure while the intelligent are full of doubt.
—Bertrand Russell
User avatar
Pista
Cureboi
Posts: 17588
Joined: 25 Jun 2006, 15:03
Location: Lost In A Forest
Contact:

Cheers.
Steve
Just like the old days

TheCureCommunity
User avatar
eastmidswhizzkid
Faster Than The Light Of Speed
Posts: 9857
Joined: 24 Mar 2005, 00:01
Location: WhizzWorld
Contact:

Pista wrote:Obligatory

:D
you mean thats not how it works? :innocent:
Well I was handsome and I was strong
And I knew the words to every song.
"Did my singing please you?"
"No! The words you sang were wrong!"

:bat:
User avatar
Pista
Cureboi
Posts: 17588
Joined: 25 Jun 2006, 15:03
Location: Lost In A Forest
Contact:

:lol:

& if you type the word "google" into google, you'll break the internet
Cheers.
Steve
Just like the old days

TheCureCommunity
User avatar
eastmidswhizzkid
Faster Than The Light Of Speed
Posts: 9857
Joined: 24 Mar 2005, 00:01
Location: WhizzWorld
Contact:

:lol:
Well I was handsome and I was strong
And I knew the words to every song.
"Did my singing please you?"
"No! The words you sang were wrong!"

:bat:
Post Reply