3 ms·
As I understand this, any CGI script could be affected. Even if written in a different language if it turn does an os.system (or equivalent). More info here: h
by adamt 12y ago
As I understand this, any CGI script could be affected. Even if written in a different language if it turn does an os.system (or equivalent). More info here:
https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/ https://securityblog.redhat.com/2014/09/24/bash-specially-cr...
The permissions would only be as the web server user, but that allows all sorts of things to be run that are quite dangerous (resource exhaustion, attacking remote machines, downloading code and running it)
- cpncrunch 12y agoYou would still need to be able to pass arbitrary data to the bash command, and if your php (or whatever) script does that, you have a lot of other potential problems to worry about.
- adamt 12y agoBecause of the way cgi works you could just set a user agent or other http header to contain an 'rm' or'nc' command or something in to download and run an attack tool. E.g. You could run netcat to listen on a port or connect out to an attacker's system to provide a connection into an otherwise firewalled database server
- cpncrunch 12y agoYes, you're right. We have perl running on our server, and I just verified that it is vulnerable if any shell scripts are run from perl. However I just quickly switched on modperl, and I verified that it is now not affected. (According to Redhat, mod_perl and php are not affected, but it's good to verify).
- jrochkind1 12y agoRedHat security says: > PHP scripts executed with mod_php are not affected even if they spawn subshells. https://securityblog.redhat.com/2014/09/24/bash-specially-crafted-environment-variables-code-injection-attack/ https://securityblog.redhat.com/2014/09/24/bash-specially-cr...