Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Bash bug disrupts Unix and Linux servers to hit internet

by The Gurus
September 25, 2014
in Editor's News
Share on FacebookShare on Twitter

The Bash software bug may be bigger than Heartbleed, as it allows hackers to control the command prompt on many Unix computers.
 
The flaw in the shell, or command prompt software, could allow hackers to exploit a bug in Bash to take complete control of a targeted system.
 
Details of the flaw, which credited discovery to “Unix/Linux and telecom specialist “ Stephane Chazelas, said that this related to how environment variables are processed. As this vulnerability is exploitable over the network in many common configurations, especially if Bash has been configured as the system shell.
 
Speaking to IT Security Guru, Jason Steer, director of technology strategy at FireEye, said that the problem is that Unix and Linux is the backbone of the internet and unless you understand Linux and Unix, this could be a problem.
 
He said: “It is like you have preferences and how you like things, but they can be bypassed by not really closing off the entry point, which is a fundmental point of application security. From an enterprise perspective, many don’t run Unix or Linux and there is so much speculation and given that so many enterprises rely on Windows due to skillsets, only academics and Government have it and care about it as it comes down to the cost of support.
 
“From an end user perspective, there will not be much impact. Apple will release a patch, but this is more about systems and servers that may be vulnerable. It is about shopping and banking providers and are they doing everything to patch their systems which can impact your data.”

Steer said that there is still not an understanding of Heartbleed six months on, and we are struggling with flaws on the OWASP top 10 and if we cannot do that properly and focus on it, then next week there will be another bug and more media hype.
 
Following the discovery of the bug yesterday, the Department of Homeland Security’s United States Computer Emergency Readiness Team (US-CERT) issued an alert saying the vulnerability affected Unix-based operating systems including Linux and Mac OS X.
 
Robert Graham, researcher at Errata Security, said in a blog said that this is bigger than Heartbleed as the bug interacts with other software in unexpected ways. “We know that interacting with the shell is dangerous, but we write code that does it anyway,” he said.
 
“An enormous percentage of softw
are interacts with the shell in some fashion. Thus, we’ll never be able to catalogue all the software out there that is vulnerable to the Bash bug.”

 
He also said that while known systems (like your web-server) are patched, unknown systems remain unpatched, and we are still seeing that with the Heartbleed bug,

Akamai chief security officer Andy Ellis said in his blog that the company had validated the existence of the vulnerability for “an extended period of time”.
 
He said: “We have also verified that this vulnerability is exposed in SSH – but only to authenticated sessions. Web applications like cgi-scripts may be vulnerable based on a number of factors; including calling other applications through a shell, or evaluating sections of code through a shell.”
 
To mitigate the problem, he recommended: upgrading to a new version of Bash; replacing Bash with an alternate shell; limiting access to vulnerable services; or filtering inputs to vulnerable services.
 
Steer said: “My question is what else is out there below the water? If you distill it to the essence of the story, it is that developers don’t do enough testing in quality assurance to secure the code before it goes out, and humans make bad decisions that we don’t sort out.”

Tags: BashBugFlawLinuxUnix
ShareTweet
Previous Post

Apple was made aware of iCloud access flaw 6 months ago

Next Post

44CON 2014

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol