4 ms·
I'm taking all of your comments into consideration. I've made two updates already: Removed "This could mean that the server is not at all vulnerable" from the
by shellshocker 12y ago
I'm taking all of your comments into consideration. I've made two updates already:
Removed "This could mean that the server is not at all vulnerable" from the warning messages.
Fixed the second exploit to be bash, not sh.
- PabloFanque 12y agoYour site currently (2pm EST) lists two exploits, but omits a third variant which "Mitchell" posted in your site's comments 8 hours ago. I've tested two fully updated Ubuntu servers. Both are not vulnerable to the two exploits you posted, but both are vulnerable to the exploit listed in Mitchell's comment. I suggest you post Mitchell's variant prominently as well. The two exploits you've posted: 1. env x='() { :;}; echo vulnerable' bash -c "echo this is a test" 2. env X='() { (a)=>\' bash -c "echo date"; cat echo The third variant Mitchell posted in his comment: 3. env -i X=' () { }; echo hello' bash -c 'date' The systems I've tried these on both have been updated with "sudo apt-get update"; "sudo apt-get dist-upgrade". The systems are: A. Ubuntu 12.04.5 LTS, running Bash version 4.2.25(1)-release (x86_64-pc-linux-gnu) B. Ubuntu 10.04.4 LTS, running version 4.1.5(1)-release (x86_64-pc-linux-gnu)
- plorg 12y agoMy updated 14.04 (bash version 4.3.11(1)-release) doesn't appear to be vulnerable to this third exploit.