Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

What can site admins learn from Bashbug vulnerability?

by The Gurus
January 9, 2015
in Opinions & Analysis
Share on FacebookShare on Twitter

Once upon a time, life as a Linux or UNIX admin was pretty sweet, without nearly as many extended shifts or panicked phone calls in the middle of the night as poor Windows admins had to deal with.
 
Sadly, nothing lasts forever. With these systems coming to play such a widespread role in server management, it was inevitable that eventually somebody would find a vulnerability and exploit it. Nevertheless, the scale of the Bashbug crisis shocked everybody. What are the lessons we can learn to reduce the risk of something like this happening again?
 
What is the Bashbug?
If you’re one of the lucky ones and haven’t had to deal with this yet, the first thing you should be aware of is that it’s a problem affecting the UNIX Bash shell which issues and interprets commands given to servers by their admins.
 
In September last year it emerged that a vulnerability – dubbed Shellshock – meant that hackers had a backdoor into servers running Bash, so that they could run commands and effectively take over the servers. It seems likely that several systems were quietly hijacked like this before the story broke, enabling hackers to use them as zombies for doing things like cracking passwords, distributing spam or carrying out DDoS attacks, without the server owners knowing, though some of them may have wondered why everything was running so slowly.
 
Although patches for fixing Shellshock quickly became available, it’s thought that there as many as 500 million systems out there that remain vulnerable because nobody has yet realised that they need to be patched or found the right way to go about it.
 
Network vulnerabilities and the Internet of Everything
One of the reasons why the Bashbug has been hard to detect is that it’s buried at a very low level in old systems (going back 25 years), which generally don’t get checked in that much detail because they’ve been stable for such a long time.
 
The development on the “Internet of Everything” (aka IoE, one step beyond the Internet of Things and focused on the connection of infrastructure across multiple sites) has been the creation of many new vulnerabilities, both by enabling hackers to operate on a larger scale any by enabling them to reach beyond computers and access all kinds of things that we use in our everyday lives.
 
This means that the security of everything from burglar alarms to the food in our fridges can be compromised, not to mention entire public transport systems, city lighting grids and so on. In this situation, it’s vital to ensure that vulnerabilities like Shellshock are spotted as soon as possible and fixed immediately afterwards.
 
The shift in internet use from single business or domestic sites which connect with single ISPs to multiple devices connecting to multiple ISPs and each other means that access to a single server can potentially give a hacker access to many more, as harvesting passwords provides routes into other systems and areas as sensitive as people’s hospital records and finances. Therefore, it’s important not only to deal with the Bashbug locally, but also to promote widespread solutions because the security of individuals depends largely on the security of many.
 
Tackling the Bashbug
Even if you’ve already patched for the Bashbug, it’s not something you should forg
et about, as there have been reports of some patches not fully resolving the problem. The early ones were made and distributed as fast as possible, with no time for them to be checked as thoroughly as most such products.
 
Because of this and because hackers have been trying to develop workarounds, it’s important to treat Shellshock as an on-going problem. It’s also important to be wary if you have a Windows or Mac based system, as you may still have Bash running at a lower level (and Bash is part of many Mac systems anyway).
 
To make sure that this problem is eliminated and stays that way, you should make regular system checks at a deep level. Trend Micro provides some useful free tools for this, though its Deep Security software is the recommended choice if you want to do a really thorough search that also takes into account other potential system flaws. If you find that your system is vulnerable, it also provides a virtual patch that can give you the security you need.
 
Shellshock is unlikely to be the last problem of this type that we encounter, so managing this one effectively is important not only in the immediate term but because it can prepare us to act swiftly and effectively next time around.
 
 
Luke Salmond is a freelance writer specialising in the Tech and Web Development sector

Tags: BugFlawShellshockVulnerability
ShareTweet
Previous Post

Predicting 2015 – Flaws get bigger and badder

Next Post

Microsoft to abandon patch advance notifications

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol