I'm running the latest ACID build, and ran the tests recommended by http://www.theregister.co.uk/2014/09/24/bash_shell_vuln/ to see if it is vulnerable. The ACID build passed both tests... the bug was not detected. See also, https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environmen t-variables-code-injection-attack/ This does not mean my routers are safe... still an open question for me. Bob kk6ecm _____ From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of mike@midnighteng.com Sent: Thursday, September 25, 2014 8:06 AM To: app_rpt-users@ohnosec.org Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /bin bash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this. google shellshock for more info. ...mike/kb8jnm
Information on Centos Bash update - http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm... 73 Doug WA3DSP http://www.crompton.com/hamradio From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash.It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /binbash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk.Current patches may not be entirely effective.Much more to be known about this. google shellshock for more info. ...mike/kb8jnm _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Thanks, Did the update as I am sure others will as well. Steve N4YZA From: Doug Crompton Sent: Thursday, September 25, 2014 12:27 PM To: mike@midnighteng.com Cc: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Information on Centos Bash update - http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm... 73 Doug WA3DSP http://www.crompton.com/hamradio -------------------------------------------------------------------------------- From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /bin bash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this. google shellshock for more info. ...mike/kb8jnm _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. -------------------------------------------------------------------------------- _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. -------------------------------------------------------------------------------- No virus found in this message. Checked by AVG - www.avg.com Version: 2014.0.4765 / Virus Database: 4025/8270 - Release Date: 09/25/14
Sorry I did not qualify that. The way to update centos is yum update bash The current update is: Updated: bash.i386 0:3.2-33.el5.1 This should not require any recompiles. If you have any current bash jobs running you would have to stop and restart them to use the new code or just reboot. 73 Doug WA3DSP http://www.crompton.com/hamradio From: doug@crompton.com To: mike@midnighteng.com Date: Thu, 25 Sep 2014 12:27:42 -0400 CC: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Information on Centos Bash update - http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm... 73 Doug WA3DSP http://www.crompton.com/hamradio From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash.It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /binbash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk.Current patches may not be entirely effective.Much more to be known about this. google shellshock for more info. ...mike/kb8jnm _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
I performed the yum update... killed asterisk... lots of errors, repeater down. looks like I should have just updated bash (sigh!) need to rebuild ACID unless there is a way to "undo" the yum update. (sigh!) _____ From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Doug Crompton Sent: Thursday, September 25, 2014 11:38 AM To: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Sorry I did not qualify that. The way to update centos is yum update bash The current update is: Updated: bash.i386 0:3.2-33.el5.1 This should not require any recompiles. If you have any current bash jobs running you would have to stop and restart them to use the new code or just reboot. 73 Doug WA3DSP http://www.crompton.com/hamradio _____ From: doug@crompton.com To: mike@midnighteng.com Date: Thu, 25 Sep 2014 12:27:42 -0400 CC: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Information on Centos Bash update - http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm l 73 Doug WA3DSP http://www.crompton.com/hamradio _____ From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /bin bash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this. google shellshock for more info. ...mike/kb8jnm _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
This should fix your update… http://docs.allstarlink.org/drupal/node/111 -- Tim :wq On Sep 25, 2014, at 1:02 PM, Bob <kk6ecm@gmail.com> wrote:
I performed the yum update... killed asterisk... lots of errors, repeater down. looks like I should have just updated bash (sigh!) need to rebuild ACID unless there is a way to “undo” the yum update. (sigh!)
From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Doug Crompton Sent: Thursday, September 25, 2014 11:38 AM To: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues
Sorry I did not qualify that. The way to update centos is
yum update bash
The current update is:
Updated: bash.i386 0:3.2-33.el5.1
This should not require any recompiles. If you have any current bash jobs running you would have to stop and restart them to use the new code or just reboot.
73 Doug WA3DSP http://www.crompton.com/hamradio
From: doug@crompton.com To: mike@midnighteng.com Date: Thu, 25 Sep 2014 12:27:42 -0400 CC: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues
Information on Centos Bash update -
http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm...
73 Doug WA3DSP http://www.crompton.com/hamradio
From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues
The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued.
Some folks set-ups are vulnerable. If you run HTTP, you certainly are.
Just a FYI...
SHELLSHOCK - this is bigger and older than heartbleed.
It is a very big deal for "all" linux systems running http.
http://seclists.org/oss-sec/2014/q3/650
to check your version of bash, type
cd /bin bash --version
our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this.
google shellshock for more info.
...mike/kb8jnm
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Cool. I'll give it a go before a reload. Whenever I do a server build, I take copious notes so I can duplicate all the steps,.. just time. Thanks much! Bob kk6ecm Sent from iPad
On Sep 25, 2014, at 1:41 PM, Tim Sawyer <tim.sawyer@mac.com> wrote:
This should fix your update… http://docs.allstarlink.org/drupal/node/111 -- Tim :wq
On Sep 25, 2014, at 1:02 PM, Bob <kk6ecm@gmail.com> wrote:
I performed the yum update... killed asterisk... lots of errors, repeater down. looks like I should have just updated bash (sigh!) need to rebuild ACID unless there is a way to “undo” the yum update. (sigh!)
From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Doug Crompton Sent: Thursday, September 25, 2014 11:38 AM To: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues
Sorry I did not qualify that. The way to update centos is
yum update bash
The current update is:
Updated: bash.i386 0:3.2-33.el5.1
This should not require any recompiles. If you have any current bash jobs running you would have to stop and restart them to use the new code or just reboot.
73 Doug WA3DSP http://www.crompton.com/hamradio
From: doug@crompton.com To: mike@midnighteng.com Date: Thu, 25 Sep 2014 12:27:42 -0400 CC: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues
Information on Centos Bash update -
http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm...
73 Doug WA3DSP http://www.crompton.com/hamradio
From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues
The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued.
Some folks set-ups are vulnerable. If you run HTTP, you certainly are.
Just a FYI...
SHELLSHOCK - this is bigger and older than heartbleed.
It is a very big deal for "all" linux systems running http.
http://seclists.org/oss-sec/2014/q3/650
to check your version of bash, type
cd /bin bash --version
our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this.
google shellshock for more info.
...mike/kb8jnm
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
Here is how you should check to see if you are vulnerable and odds are you ARE. ~# env x='() { :;}; echo vulnerable' bash -c "echo this is a test" If the system is vulnerable, the output is: vulnerable this is a test It is far easier to upgrade bash and all OS distros now have a patch. Wayne http://hamradiohost.net _____ From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of kk6ecm Sent: Thursday, September 25, 2014 3:11 PM To: Tim Sawyer Cc: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Cool. I'll give it a go before a reload. Whenever I do a server build, I take copious notes so I can duplicate all the steps,.. just time. Thanks much! Bob kk6ecm Sent from iPad On Sep 25, 2014, at 1:41 PM, Tim Sawyer <tim.sawyer@mac.com> wrote: This should fix your update. http://docs.allstarlink.org/drupal/node/111 -- Tim :wq On Sep 25, 2014, at 1:02 PM, Bob <kk6ecm@gmail.com> wrote: I performed the yum update... killed asterisk... lots of errors, repeater down. looks like I should have just updated bash (sigh!) need to rebuild ACID unless there is a way to "undo" the yum update. (sigh!) _____ From: app_rpt-users-bounces@ohnosec.org [mailto:app_rpt-users-bounces@ohnosec.org] On Behalf Of Doug Crompton Sent: Thursday, September 25, 2014 11:38 AM To: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Sorry I did not qualify that. The way to update centos is yum update bash The current update is: Updated: bash.i386 0:3.2-33.el5.1 This should not require any recompiles. If you have any current bash jobs running you would have to stop and restart them to use the new code or just reboot. 73 Doug WA3DSP http://www.crompton.com/hamradio _____ From: doug@crompton.com To: mike@midnighteng.com Date: Thu, 25 Sep 2014 12:27:42 -0400 CC: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues Information on Centos Bash update - http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm l 73 Doug WA3DSP http://www.crompton.com/hamradio _____ From: mike@midnighteng.com To: app_rpt-users@ohnosec.org Date: Thu, 25 Sep 2014 08:06:13 -0700 Subject: [App_rpt-users] NEW Security Issues The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued. Some folks set-ups are vulnerable. If you run HTTP, you certainly are. Just a FYI... SHELLSHOCK - this is bigger and older than heartbleed. It is a very big deal for "all" linux systems running http. http://seclists.org/oss-sec/2014/q3/650 to check your version of bash, type cd /bin bash --version our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this. google shellshock for more info. ...mike/kb8jnm _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem. _______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
That's strange I followed the instructions here. http://centosnow.blogspot.com/2014/09/critical-bash-updates-for-centos-5.htm... Updated no problem. Then Doug pointed out yum update bash. Just to be double sure I did that and it saw something like no update necessary. I just just got done taking on my repeater we had Zello, zoiper, and RF going it was a beautiful thing.
Hi Everyone, I'm going to try to slow the panic here! WHY is this such a huge security concern for AllStar users???? The only remote attack vector that might be of concern is via the apache webserver. And, this is only a concern if you've got bash shell scripts in a publicly accessible cgi-bin directory. So, if you do have a vulnerable cgi-bin, just temporarily do a "chmod 700" on this directory and the problem is mitigated....Or, just stop the apache service entirely. This vulnerability isn't like HeartBleed from several months ago. Nor does it provide a means for privilege escalation. Am I missing something??? (I hope not! I've got over 100 servers with this vulnerability currently). So, slow down and -plan- this fix. Don't break your system due to an unneeded panic! 73, David KB4FXC On Thu, 25 Sep 2014 mike@midnighteng.com wrote:
The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued.
Some folks set-ups are vulnerable. If you run HTTP, you certainly are.
Just a FYI...
SHELLSHOCK - this is bigger and older than heartbleed.
It is a very big deal for "all" linux systems running http.
http://seclists.org/oss-sec/2014/q3/650
to check your version of bash, type
cd /bin bash --version
our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this.
google shellshock for more info.
...mike/kb8jnm
I totally agree. All this security talk you might think we were running national security servers. Human nature is sometimes so bizarre. People can be scared so easily and the media loves scaring people. But then sometimes it takes scare tactics to get someone to take action. Has anyone ever had an Allstar system compromised that was properly setup? The fix is easy. If you are running centos just do yum update bash The upcoming Beaglebone Black 1.2 release will have the fix. Ubuntu auto updated today. Other releases should have similar update paths. Run this script at the Linux prompt to test - env X="() { :;} ; echo busted" `which bash` -c "echo completed" If it returns busted then you have the problem. One caveat - the current fixes are preliminary and have not gone through extensive testing to you might want to check for updates again in a fews day or weeks. 73 Doug WA3DSP http://www.crompton.com/hamradio
Date: Thu, 25 Sep 2014 16:29:30 -0400 From: kb4fxc@inttek.net To: app_rpt-users@ohnosec.org Subject: Re: [App_rpt-users] NEW Security Issues
Hi Everyone,
I'm going to try to slow the panic here! WHY is this such a huge security concern for AllStar users????
The only remote attack vector that might be of concern is via the apache webserver. And, this is only a concern if you've got bash shell scripts in a publicly accessible cgi-bin directory. So, if you do have a vulnerable cgi-bin, just temporarily do a "chmod 700" on this directory and the problem is mitigated....Or, just stop the apache service entirely.
This vulnerability isn't like HeartBleed from several months ago. Nor does it provide a means for privilege escalation.
Am I missing something??? (I hope not! I've got over 100 servers with this vulnerability currently).
So, slow down and -plan- this fix. Don't break your system due to an unneeded panic!
73, David KB4FXC
On Thu, 25 Sep 2014 mike@midnighteng.com wrote:
The increase in recent hack attempts are the result of the resent knowlage of a fundamental bug in bash. It was not a big deal till someone published the flaw before some patches could be issued.
Some folks set-ups are vulnerable. If you run HTTP, you certainly are.
Just a FYI...
SHELLSHOCK - this is bigger and older than heartbleed.
It is a very big deal for "all" linux systems running http.
http://seclists.org/oss-sec/2014/q3/650
to check your version of bash, type
cd /bin bash --version
our acid installs should be at 3.2 Remote ssh devices are possibly at risk. Current patches may not be entirely effective. Much more to be known about this.
google shellshock for more info.
...mike/kb8jnm
_______________________________________________ App_rpt-users mailing list App_rpt-users@ohnosec.org http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users
To unsubscribe from this list please visit http://ohnosec.org/cgi-bin/mailman/listinfo/app_rpt-users and scroll down to the bottom of the page. Enter your email address and press the "Unsubscribe or edit options button" You do not need a password to unsubscribe, you can do it via email confirmation. If you have trouble unsubscribing, please send a message to the list detailing the problem.
When I had SIP enabled and standard ports forwarded, many days I saw almost continuous attempts to register several thousand extensions at a time. As I said in my previous post,.... I cleaned my house and slapped myself on the wrists, after having completely lost access to the repeater. Login for root was enabled, and after a couple years, they brute forced their way in guessing the password. While the password wasn't "1234", it was in the dictionary. In many cases it doesn't mean going crazy, just examining your set up and correcting dumb stuff.
participants (10)
-
Bob -
David McGough -
Doug Crompton -
kk6ecm -
mike@midnighteng.com -
Robert A. Poff WB3AWJ -
Robert Newberry -
The Rices -
Tim Sawyer -
Wayne