DaPlumber
Patron
- Joined
- May 21, 2014
- Messages
- 246
ShellShock, more deadly than Heartbleed?
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169
Just in case that you want to verify whether Bash is vulnerable
run this simple command:
env x='() { :;}; echo vulnerable' bash -c "echo test" | grep -v "test"
It looks like FreeNAS-9.2.1.7-RELEASE-x64 IS vulnerable.
Not that my FreeNAS is exposed to the world-wild web, but...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6271
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7169
Just in case that you want to verify whether Bash is vulnerable
run this simple command:
env x='() { :;}; echo vulnerable' bash -c "echo test" | grep -v "test"
It looks like FreeNAS-9.2.1.7-RELEASE-x64 IS vulnerable.
Not that my FreeNAS is exposed to the world-wild web, but...