• Bashpocalipsis

    From Yeray A.Dorta@2:341/203 to All on Wed Sep 24 21:09:00 2014
    Buenas !

    Creo que es momento de empezar a correr en circulos con los brazos en alto xD

    http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271

    ----
    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution.

    Impact
    CVSS Severity (version 2.0):
    CVSS v2 Base Score: 10.0 (HIGH) (AV:N/AC:L/Au:N/C:C/I:C/A:C) (legend)
    Impact Subscore: 10.0
    Exploitability Subscore: 10.0
    CVSS Version 2 Metrics:
    Access Vector: Network exploitable
    Access Complexity: Low
    Authentication: Not required to exploit
    Impact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
    ----



    -=- Netmail devnull@( 2:341/203 | 46:2/103 | 57:245/13 | 316:341/1 )
    =-= Email ^^^^^^^@bitslair[dot]voidlabs[dot]com
    -=- PGP KeyID 0x1352338D

    ... Computer Hacker wanted. Must have own axe.
    --- MultiMail/Linux v0.49
    --- SBBSecho 2.20-Linux
    * Origin: Bits Lair BBS (2:341/203)
  • From Antonio Hernandez Lopez@2:341/202.1 to Yeray A.Dorta on Wed Sep 24 23:14:00 2014
    Hello, Yeray!

    Wednesday September 24 2014 21:09, from Yeray A.Dorta -> All, in URL @OFGHIUrl:

    Creo que es momento de empezar a correr en circulos con los brazos en
    alto xD

    http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271

    Amos no jodas.... esta no la había visto...

    Saludos
    Belky

    Fidonet: 2:341/202.1
    e-mail : belky@vampirebbs.org
    twitter: @belky318
    GPG Key: 0x12D5D6E1

    --- VampireBBS
    * Origin: Punto Vampiro (2:341/202.1)
  • From Enric Lleal Serra@2:343/107.1 to Yeray A.Dorta on Wed Oct 15 13:29:05 2014
    ­Hola Yeray!

    El Miércoles 24 Septiembre 2014 a las 21:09, Yeray A.Dorta escribió a All:

    Creo que es momento de empezar a correr en circulos con los brazos en
    alto xD

    Depende de si el vector de ataque te aplica a lo que tengas expuesto, no?

    -
    A reveure!!
    Enric
    __________________________________________________________________
    FidoNet: 2:343/107.1 | beholderbbs.org | fidonet.cat | .es | .ws
    InterNet: kishpa(at)kishpa(dot)com | kishpa.com | GPG#0xDCCB8CFC

    ... Si temes a la muerte, temes a la vida.
    --- crashmail + golded + binkd
    * Origin: Black flag & crossed bones : Eye Of The Beholder BBS! (2:343/107.1)