miércoles, 24 de septiembre de 2014

'Bash' command flaw leaves Linux, OS X and more open to attack




Apparently, the internet has more deep-seated security bugs to worry about than Heartbleed. Researchers have discovered a longstanding flaw in a common Unix command shell (bash) for Linux and Macs that lets attackers run any code they want as soon as the shell starts running. They can effectively get control of any networked device that runs bash, even if there are limits on the commands remote users can try. That's a big problem when a large chunk of the internet relies on the shell for everyday tasks -- many web servers will call on it when they're running scripts, for example.


There are already patches for multiple Linux variants (CentOS, Debian, Redhat), and big internet services like Akamai have already taken action. However, the age and sheer ubiquity of the exploit means that there are some older servers and other internet-connected devices that won't (and in some cases, can't) be fixed. In other words, there's a chance that everything from poorly maintained websites to your home security camera will remain vulnerable. Some devices will be protected, however, as security researcher Paul McMillan notes that many embedded devices "use BusyBox, which is not vulnerable." It's unlikely that hackers will breach many of the major sites you visit thanks to their quick responses to the flaw, and many of your existing gadgets are probably safe. Having said this, it's hard to know exactly how far reaching the damage may be -- it could take years before there's no longer a significant threat.


[Image credit: Robert Graham, Twitter]



Apple OS X Yosemite










  • Type Computer OS

  • Source model Closed, w/ open source

  • Architecture 64-bit

  • Announced 2014-06-02


see all specs


There are not any reviews for this product yet.

Why not be the first to write one?



Get better reviews from people who actually have this product!


write a reviewsee all reviews →










via Engadget RSS Feed http://ift.tt/1mW4830

No hay comentarios:

Publicar un comentario