6 ms·
For more info: http://www.csoonline.com/article/2687265/application-security/remote-exploit-in-bash-cve-2014-6271.html http://www.csoonline.com/article/2687265/
by Zweihander 12y ago
For more info:
http://www.csoonline.com/article/2687265/application-security/remote-exploit-in-bash-cve-2014-6271.html http://www.csoonline.com/article/2687265/application-securit...
This should be fun
- deleted 12y ago[deleted]
- nknighthb 12y agoCGI has always been an accident waiting to happen, but hardly anybody uses it anymore anyway, and even more rarely in a manner that invokes bash, of all things. I fail to see how "HTTP requests" generically are a vector, and its "Here is a sample" statement is not a link and is followed by... nothing. This article tells me nothing useful other than "don't allow untrusted data into your environment", which we've all known for 20 years.
- huhtenberg 12y ago> hardly anybody uses it anymore anyway Lots of PHP setups do.
- ars 12y agoLots? Really? PHP was one of the first to have a dedicated apache module. Perl is much more likely to be CGI.
- lmz 12y agoI seem to recall cPanel defaulting to suPHP (which uses CGI).
- jamroom 12y agoYeah this is true - a lot of hosting providers run PHP as a CGI as it allows them to run the PHP process under the user account (although it is very slow, and RUID2 is a better solution). If you're not running mod_cgi can this affect the system in any way? Thanks!
- prothid 12y agoYes, lots. nginx + php is very popular.
- pritambaral 12y agoIs fastCGI the same thing as CGI, for this case, though?
- nknighthb 12y agoThey would be too slow to be useful at any kind of real load. Are you sure you're not thinking of FastCGI? That doesn't pass data through the environment, it goes over a socket.
- jamroom 12y agoYeah - it is really slow, but a surprisingly large number of hosting providers run it that way under cPanel.
- justincormack 12y agoPeople still shell out to do stuff from scripts from all sorts of languages. Unless these sanitize the environment they would be vulnerable.
- nknighthb 12y agoUnless you're using CGI, your system environment will not be contaminated. CGI is vulnerable because it relies on passing untrusted data in environment variables. No other gateway interface I'm familiar with does.
- nitrogen 12y agoAre you certain that no method of invoking a dynamic script sets environment variables to values controlled by requests? If so, it sounds like even an innocent call to system("lame a.wav b.mp3") could lead to code execution. Edit: also, you may be surprised to find that some "libraries" are actually wrappers around external binaries (e.g. libgpgme). If any of them used a system() or exec() call that preserves environment, and the binary or the library ever invokes bash (e.g. via system()), then trouble will ensue.
- nknighthb 12y agoAre you certain God doesn't exist? This is far from the first environment variable attack to impact CGI scripts, and CGI's successors have avoided passing data in environment variables. It's possible some moron decided to create their own CGI replacement using environment variables, but it's not going to be in widespread use.
- nitrogen 12y agoHow does nginx pass data to passenger? Edit: also note that CUPS is vulnerable according to https://access.redhat.com/articles/1200223 https://access.redhat.com/articles/1200223 Also dhclient (!)
- 12y ago
- rmc 12y agoThis article tells me nothing useful other than "don't allow untrusted data into your environment", which we've all known for 20 years. Yes, we've all known that. But we're slowly discovering all different ways the untrusted data can get there.
- peterwwillis 12y agoAlmost all vendor-supplied web interfaces that don't come bundled with a web server are CGI so you can just run it from whatever web server you have. Even some very popular 'appliances' out there that have their own web server run CGI.
- fl0wenol 12y agoFastCGI accepts name/value pairs from the server and most default language bindings against it will turn them into environment variables for the benefit of code that expects to be able to reference them. This can get tricky if you do anything that spawns a process with your code later.