[clug] Security talk and the bash 'shellshock' vulnerability

Carlo Hamalainen carlo at carlo-hamalainen.net
Sun Sep 28 01:22:58 MDT 2014


On 28/09/14 09:16, Brett Worth wrote:
> This one seems to have been fixed with today's update on Ubuntu to
> bash-4.3-7ubuntu1.4:

That's good to know.

Some more proof of concepts:

https://github.com/mubix/shellshocker-pocs/blob/master/README.md

e.g. qmail: http://twitpic.com/ec3615

Fun times ahead.

--
Carlo Hamalainen
http://carlo-hamalainen.net


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.samba.org/pipermail/linux/attachments/20140928/946be58d/attachment.pgp>


More information about the linux mailing list