Bitcoin Forum
November 09, 2024, 02:31:58 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bash bug  (Read 1832 times)
linelec (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 100


View Profile WWW
September 25, 2014, 03:44:43 PM
 #1

~$  env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test




https://twitter.com/ErrataRob/status/514834901766397953
kcud_dab
Legendary
*
Offline Offline

Activity: 1652
Merit: 1002


Bitcoin enthusiast!


View Profile
September 25, 2014, 03:55:14 PM
 #2

Oui sympatique cette faille.. quelques exemples :

https://twitter.com/cnbrkbolat/status/514889775724363776 <-- privilege escalation via VMWare sous OS X

https://gist.github.com/anonymous/929d622f3b36b00c0be1 <-- surement un trojan / logiciel malveillant (l'idée est de le dl un fichier et de l'exécuter)

linelec (OP)
Full Member
***
Offline Offline

Activity: 210
Merit: 100


View Profile WWW
September 26, 2014, 11:41:50 AM
 #3

Oui sympatique cette faille.. quelques exemples :

https://twitter.com/cnbrkbolat/status/514889775724363776 <-- privilege escalation via VMWare sous OS X

https://gist.github.com/anonymous/929d622f3b36b00c0be1 <-- surement un trojan / logiciel malveillant (l'idée est de le dl un fichier et de l'exécuter)


Oh mon Dieu ! Attention a vos bitcoins   Grin


Could the Bash bug cause an internet MELTDOWN?
Hackers scramble to exploit Shellshock flaw as experts warn your details may be at risk


http://www.dailymail.co.uk/sciencetech/article-2770512/Could-Bash-bug-cause-internet-MELTDOWN-Hackers-scramble-exploit-Shellshock-flaw-experts-warn-details-risk.html


kcud_dab
Legendary
*
Offline Offline

Activity: 1652
Merit: 1002


Bitcoin enthusiast!


View Profile
September 26, 2014, 11:59:06 AM
 #4

Un autre ex d'exploit

https://www.trustedsec.com/september-2014/shellshock-dhcp-rce-proof-concept/ <-- attaque via un DHCPd sur un réseau local

superresistant
Legendary
*
Offline Offline

Activity: 2156
Merit: 1131



View Profile
September 26, 2014, 01:29:19 PM
 #5

http://stackoverflow.com/questions/26037618/how-to-get-a-php-variable-from-one-file-to-another-maybe-using-jquery-javascript

Tapez dans le shell :

Code:
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

Si vous voyez :

Code:
vulnerable

Corrigez la faille (Ubuntu/Mint/ElementaryOs):

Code:
sudo apt-get update

sudo apt-get install --only-upgrade bash

Pour Debian :

Code:
mkdir src
cd src
wget http://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz
#download all patches
for i in $(seq -f "%03g" 0 25); do wget http://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-$i; done
tar zxvf bash-4.3.tar.gz
cd bash-4.3
#apply all patches
for i in $(seq -f "%03g" 0 25);do patch -p0 < ../bash43-$i; done #build and install
./configure && make && make install
sangoku
Hero Member
*****
Offline Offline

Activity: 616
Merit: 501



View Profile WWW
December 10, 2014, 12:01:56 PM
 #6

Un lien, peu de texte explicatif, attention, ton post va se faire deleter par kcud_dab.
Son argument pour effacer les miens, c'est un seul lien et très peu de texte explicatif

DΛSH is digital cash. Transactions are obscured in the blockchain, making them private from the wallet. You can send Dash to family or friends, or pay for goods or services, anywhere in the world. DΛSH Anonymous and Untraceable. The Perfect Digital Cash And The Best Way To Protect Your Privacy https://www.dashpay.io DΛSH is 59.5 times faster with syncing and updating  than Monero.
My DΛSH Address: XgF6sNzGHU58dn36WsC16no9FHct6nPeZD
superresistant
Legendary
*
Offline Offline

Activity: 2156
Merit: 1131



View Profile
December 10, 2014, 12:59:00 PM
 #7

Un lien, peu de texte explicatif, attention, ton post va se faire deleter par kcud_dab.
Son argument pour effacer les miens, c'est un seul lien et très peu de texte explicatif


Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!