Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Shellshock



On Wed, Oct 01, 2014 at 05:33:58PM -0400, Bill Ricker wrote:
> On Wed, Oct 1, 2014 at 4:59 PM, Tom Metro <tmetro+blu at gmail.com> wrote:
> > But in the case of CGI you are just moving the network/local
> > barrier a bit further down the stack.
> 
> and moved it right through system() => /bin/sh => /bin/bash by alias
> which last wasn't designed to be network secure.

Of course, anyone who's writing CGI scripts and using system() should be
fired.  This has been well-known as a very serious security hole for
oh, just about as long as the CGI interface has existed, so anyone
still doing this now is either lazy to the point of malice or just not
qualified to do the job. 

-- 
Derek D. Martin    http://www.pizzashack.org/   GPG Key ID: 0xDFBEAD02
-=-=-=-=-
This message is posted from an invalid address.  Replying to it will result in
undeliverable mail due to spam prevention.  Sorry for the inconvenience.




BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org