Bitcoin Forum
May 28, 2024, 09:33:49 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: A new Unix bug can pose bigger threat than Heartbleed  (Read 780 times)
RedDiamond (OP)
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
September 25, 2014, 12:54:04 PM
 #1

"A newly discovered security bug in a widely used piece of Linux software, known as "Bash," could pose a bigger threat to computer users than the "Heartbleed" bug that surfaced in April, cyber experts warned on Wednesday. Bash is the software used to control the command prompt on many Linux computers. Hackers can exploit a bug in Bash to take complete control of a targeted system, security experts said. The Department of Homeland Security's United States Computer Emergency Readiness Team, or US-CERT, issued an alert saying the vulnerability affected Unix-based operating systems including Linux and Apple Inc's Mac OS X"

http://www.nbcnews.com/tech/security/new-bash-bug-could-pose-bigger-threat-heartbleed-n211006

bluefirecorp
Legendary
*
Offline Offline

Activity: 882
Merit: 1000


View Profile
September 25, 2014, 01:42:29 PM
 #2

Still waiting on my patch. They had one patch, but only fixed a small bit of it Sad

Decksperiment
Sr. Member
****
Offline Offline

Activity: 630
Merit: 250


View Profile
September 25, 2014, 02:34:46 PM
 #3

"A newly discovered security bug in a widely used piece of Linux software, known as "Bash," could pose a bigger threat to computer users than the "Heartbleed" bug that surfaced in April, cyber experts warned on Wednesday. Bash is the software used to control the command prompt on many Linux computers. Hackers can exploit a bug in Bash to take complete control of a targeted system, security experts said. The Department of Homeland Security's United States Computer Emergency Readiness Team, or US-CERT, issued an alert saying the vulnerability affected Unix-based operating systems including Linux and Apple Inc's Mac OS X"

http://www.nbcnews.com/tech/security/new-bash-bug-could-pose-bigger-threat-heartbleed-n211006



Bug? This has actually been known by myself since 98-99, and I found it online!! Along with how to create a root account on a unix system, using 98se. I should run an ftp server for those wishing to contribute to server costs lol, just to give access to a pentesters exploits..
RedDiamond (OP)
Sr. Member
****
Offline Offline

Activity: 294
Merit: 250


View Profile
September 25, 2014, 03:02:15 PM
 #4

"A newly discovered security bug in a widely used piece of Linux software, known as "Bash," could pose a bigger threat to computer users than the "Heartbleed" bug that surfaced in April, cyber experts warned on Wednesday. Bash is the software used to control the command prompt on many Linux computers. Hackers can exploit a bug in Bash to take complete control of a targeted system, security experts said. The Department of Homeland Security's United States Computer Emergency Readiness Team, or US-CERT, issued an alert saying the vulnerability affected Unix-based operating systems including Linux and Apple Inc's Mac OS X"

http://www.nbcnews.com/tech/security/new-bash-bug-could-pose-bigger-threat-heartbleed-n211006



Bug? This has actually been known by myself since 98-99, and I found it online!! Along with how to create a root account on a unix system, using 98se. I should run an ftp server for those wishing to contribute to server costs lol, just to give access to a pentesters exploits..

Maybe you mean this one from 1999: http://www.cvedetails.com/cve/CVE-1999-0491/

The currently found bug is much worse: http://www.cvedetails.com/cve/CVE-2014-6271/

"GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. "
Bitcoin Magazine
Sr. Member
****
Offline Offline

Activity: 252
Merit: 250


View Profile
September 25, 2014, 06:48:33 PM
 #5

oh shit it's just like winnuke (circa 1997-1998)

i am here.
catena5260
Sr. Member
****
Offline Offline

Activity: 476
Merit: 501


View Profile
September 25, 2014, 07:33:09 PM
 #6

Is it in any way related to the recent problems with Huobi, related to coins credit by mistake?
anonymous.lawman
Full Member
***
Offline Offline

Activity: 140
Merit: 100

金句收集研究!


View Profile
September 26, 2014, 12:56:08 AM
 #7

Uninstall it.

Coming soon!
b!z
Legendary
*
Offline Offline

Activity: 1582
Merit: 1010



View Profile
September 26, 2014, 03:11:10 AM
 #8

#windowsvistamasterrace
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!