7 ms·
So, as a amateur sysadmin of a decently popular side project, what should I do? I've read over the post on the mailing list, and I think I understand the basic
by matchu 12y ago
So, as a amateur sysadmin of a decently popular side project, what should I do? I've read over the post on the mailing list, and I think I understand the basic attack, but I'm having trouble understanding exactly how an attacker could run bash on my server and what I therefore need to patch (though I suspect that's intentional). Is `sudo apt-get update && sudo apt-get upgrade` sufficient on an Ubuntu server?
- ilconsigliere 12y agoIt will be once they release a patch, yes https://security-tracker.debian.org/tracker/CVE-2014-6271 https://security-tracker.debian.org/tracker/CVE-2014-6271
- karlkatzke 12y agoAlready out on Ubuntu, I believe?
- clarry 12y agoI don't know if Ubuntu has pushed a patched version of bash, but bash is what you should update. Someone already posted a way to test whether your version is vulnerable. You might also look into changing the default shell (but beware, scripts with bashisms in them...).
- hamiltonkibbe 12y agoUbuntu pushed the update around noon 4.3-7ubuntu1.1
- pjungwir 12y agoReally? I haven't been able to find any notice of that, and on 14.04 LTS if I run `sudo apt-get install --only-upgrade bash` I'm still vulnerable.
- ForHackernews 12y agohttp://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-6271.html http://people.canonical.com/~ubuntu-security/cve/2014/CVE-20...
- pjungwir 12y agoAh, looks like I needed to run `sudo apt-get update` first.
- hamiltonkibbe 12y agosudo apt-get update && sudo apt-get upgrade
- gcb0 12y agoyeah, it was updated in debian in the morning...
- larrys 12y agoA good question that so far nobody has answered (as of right now).
- sauere 12y ago> Is `sudo apt-get update && sudo apt-get upgrade` sufficient on an Ubuntu server? Yes. Patch is out.
- pjungwir 12y agoIt appears that Linode changes /etc/apt/sources.list to point to their own mirror of Ubuntu repositories, and as far as I can tell those are not updated yet. So I guess the solution is to wait or edit sources.list. Just FYI if you're on their systems!
- teach 12y agoJust did an update on my Linode and one of the updates was replace bash 4.1-2ubuntu3 So seems like it's there now.
- traviscj 12y agoDepends on whether you have mirrors.linode.com or the ubuntu servers set up in sources.list. I had to swap mine out.
- teach 12y agoWell, I didn't even know about mirrors.linode.com. Mine were still the ubuntu default servers. I guess apt-get from one of Linode's mirrors saves bandwidth? Or is it just more polite?
- aaronem 12y agoIt probably ensures that you get the Linode-customized flavors of packages where such exist, so that, for example, you don't inadvertently upgrade your kernel to a build without the ability to mount Linode disks.
- iancarroll 12y ago
- cookiecaper 12y agoIf you're still waiting for mirrors and such to sync, you can install these packages manually on the LTS releases with the snippet here: http://hastebin.com/oraheyipug.hs http://hastebin.com/oraheyipug.hs
- ay 12y agoLooks like the patched version and the pre-patched version show the same version, or am I being stupid and missing something ? ayourtch@mcmini:~/bash-patch$ ls bash_4.2-2ubuntu2.2_amd64.deb bash-builtins_4.2-2ubuntu2.2_amd64.deb t ayourtch@mcmini:~/bash-patch$ dpkg -x bash_4.2-2ubuntu2.2_amd64.deb t ayourtch@mcmini:~/bash-patch$ diff -c t/bin/bash /bin/bash Binary files t/bin/bash and /bin/bash differ ayourtch@mcmini:~/bash-patch$ t/bin/bash --version GNU bash, version 4.2.25(1)-release (x86_64-pc-linux-gnu) Copyright (C) 2011 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software; you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. ayourtch@mcmini:~/bash-patch$ /bin/bash --version GNU bash, version 4.2.25(1)-release (x86_64-pc-linux-gnu) Copyright (C) 2011 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html> This is free software; you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. ayourtch@mcmini:~/bash-patch$ sha1sum t/bin/bash 9eeed02173db163b013933eff3b8c6aa3697f67f t/bin/bash ayourtch@mcmini:~/bash-patch$ sha1sum /bin/bash 3384fadf84146a4d4b6b7f529f615e9947b4ac99 /bin/bash ayourtch@mcmini:~/bash-patch$
- cookiecaper 12y agoOnly the build/patchset version is incremented in these packages (the -2ubuntu2.2). You can see the package version with dpkg -s bash | grep Version.
- keithhyfn 12y agoAnyone have code that might work on 13.04 please?
- zobzu 12y agoyou should update all security updates, reliably, periodically, regardless of HN posts. you're probably not directly vulnerable for this very vuln, but then again, maybe you are. with enough vulns it gets complex enough to check that its easier to just update with all the security updates..
- detectify 12y agoWe just updated our scanner and included this CVE. You can run Detectify to see if your setup is vulnerable. We offer a recurring service that runs continuously and alerts you if you are exposed to new emerging vulnerabilities. This removes some of the complexity of always being on top of security alerts.
- zobzu 12y agosup advertiser
- vhost- 12y agoIf you just want to upgrade bash, and prevent services like nginx, fpm, and apache from being restarted in production, you can run `sudo apt-get update && sudo apt-get install --only-upgrade bash` Related to that, does anyone else know if upgrading bash will require a restart of other services kind of like upgrading openssl requires restarting things?
- auxiliation 12y ago> Related to that, does anyone else know if upgrading bash will require a restart of other services kind of like upgrading openssl requires restarting things? I don't think it will, for a couple of reasons. OpenSSL is integrated into other services as a library, while bash would be called as an external application. I also noticed that once I upgraded bash, the proof of concept stopped working in a terminal I opened prior to the upgrade.
- euid 12y agoUpgrades should not require any restarts, and no restarts are required for you to stop being vulnerable - as this only affects newly created bash sessions, not already running ones.
- stefantalpalaru 12y ago