Add new comment

wnylibrarian's picture

Shellshock Resources

Unfortunately I feel this will be happening more and more. It was late this past Spring many Internet sites were rocked with the Heartbleed vulnerability. Heartbleed was a serious vulnerability that effected sites using OpenSSL, how Internet information is transferred and encrypted, and how by reading the system memory that encrypted information could be hacked and read.

The newest incarnation now involves how using what is known as a Bash Shell, confidential information can be exposed through a terminal window. This effects both PCs, Macs, and Linux devices.

I've placed links to relevant articles below. You may also wish to test your system. You can test if your system is vulnerable using the following:

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
if the output reads vulnerable    this is a test ---your system needs to be patched.