Just in:
ESG Achievement Awards 2023/2024 is Open for Application, Celebrating Innovative Sustainable Practices and Responsible Risk Management // Sharjah Census Gears Up for Final Enumeration Phase // Abu Dhabi Secures US$5 Billion in Fresh Funding // Leading with Compliance, ZUHYX Earns the Canadian MSB License // UAE Scrutinizes Report on Racial Discrimination Treaty // Prince Holding Group’s Chen Zhi Scholarship Clinches Silver Stevie for CSR Excellence at Asia-Pacific Stevie Awards // Andertoons by Mark Anderson for Thu, 25 Apr 2024 // Ministry of Agriculture Supports Taiwanese Tea’s Entry into Singapore Market to Boost Global Presence // NetApp’s 2024 Cloud Complexity Report Reveals AI Disrupt or Die Era Unfolding Globally // Astana International Exchange Connects with Regional Markets Through Tabadul Hub // Booming Region Fuels Innovation Surge // UAE President, Spanish Prime Minister Hold Phone Talks // Lee Chong Wei Shows Up On Chinese Hot cultural Talk Show “SHEDE Wisdom Talents”, Talking About “Crossing The Hill” // Election Commission Has A Dismal Record On Acting Against Modi’s Breaches Of Poll Code // AVPN Charts Path Forward at 2024 Global Conference // Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // Quality HealthCare Partners with eHealth to Enhance Patient Treatment Efficiency // Dubai Gears Up for Second FinTech Summit as Funding Surges // Etihad Airways Announces Paris Service with A380 // Lai & Turner Law Firm PLLC Welcomes Eric Strocen as Director of Family Law Division //

Hackers Exploit Shellshock, Much More Trouble Awaits

Security experts are keeping an eye on the Shellshock vulnerability, also known as the Bash (Bourne-Again Shell) bug, as a focus for malicious scanning and at least one botnet. They warn, though, that hackers haven’t even begun to test the limits of the vulnerability.

The Shellshock vulnerability, also called the Bash (Bourne-Again Shell) bug, could be even an even greater threat than the Heartbleed bug. Disclosed in April, Heartbleed threw a scare into Internet users by exploiting OpenSSL cryptography vulnerabilities to allow theft of servers private keys and users’ session cookies and passwords via fake Web sites.

The Internet security firm FireEye reported that it has seen plenty of malicious traffic using the Bash bug, some of it possibly from Russia. The activity has included DDoS attacks, malware droppers, reverse shell hacks, backdoors and data exfiltration.

ADVERTISEMENT

Elsewhere, security researchers at Incapsula logged more than 17,400 attacks at an average rate of 725 an hour. The company said that more than 1,800 domains in its network were attacked from about 400 unique IP addresses, more than half originating in China and the United States.

Attackers are using scanners that bombard networks and seek out vulnerable machines. To this point, most of the attention from hackers has gone to the Common Gateway Interface vector, an interface between a Web server and executables that produce dynamic content.

A Threat to UNIX Machines

The extent of Shellshock could go far behind Web servers, however. The bug could become a serious threat to computers using Unix-based operating systems, including Linux and Apple’s Mac OS X. From there it has the potential to spread to all Internet-connected devices. Bash is the software used to control the command prompt on many Unix computers, and Shellshock can exploit it to take complete control of a system.

Shellshock could also allow hackers to gain access to every Internet-enabled device in a person’s home by way of products as benign as smart light bulbs.

Hard to Count Vulnerable Devices

Experts say one reason is that the bug interacts with other software in unexpected ways because so much software uses the Bourne-Again Shell in some way. That means it’s almost impossible to fully catalog all the devices and products that could be vulnerable to the Bash bug.

Where Shellshock differs from Heartbleed is that the previous bug only affected a specific version of OpenSSL. Bash has been around long enough that lots of older devices on networks are vulnerable, which means the number of systems that need to be patched is much greater — especially considering that many others won’t be patched.

An early patch for the vulnerability turned out to be inadequate. Further patches against related vulnerabilities were released over the weekend. Given the ease with which attackers have exploited Bash and what little trouble they’ve had with the large Bash user base, the problems created by Shellshock might be just beginning.

This entry passed through the Full-Text RSS service – if this is your content and you’re reading it on someone else’s site, please read the FAQ at fivefilters.org/content-only/faq.php#publishers.

ADVERTISEMENT

ADVERTISEMENT
Just in:
NetApp’s 2024 Cloud Complexity Report Reveals AI Disrupt or Die Era Unfolding Globally // Lee Chong Wei Shows Up On Chinese Hot cultural Talk Show “SHEDE Wisdom Talents”, Talking About “Crossing The Hill” // Cobb’s Game-Changer: Introducing One-Stop Event Transport Management Solution // ZUHYX Exchange: Embracing Social Responsibility for a Sustainable Future // Ministry of Agriculture Supports Taiwanese Tea’s Entry into Singapore Market to Boost Global Presence // UAE Scrutinizes Report on Racial Discrimination Treaty // Prince Holding Group’s Chen Zhi Scholarship Clinches Silver Stevie for CSR Excellence at Asia-Pacific Stevie Awards // Oman Seeks Growth Through Strategic Economic Alliances // Abu Dhabi Secures US$5 Billion in Fresh Funding // AVPN Charts Path Forward at 2024 Global Conference // Dubai Gears Up for Second FinTech Summit as Funding Surges // New Dynamics in Cryptocurrency Security: ZUHYX Builds the Strongest Fund Protection System // Etihad Airways Announces Paris Service with A380 // Leading with Compliance, ZUHYX Earns the Canadian MSB License // PolyU forms global partnership with ZEISS Vision Care to expand impact and accelerate market penetration of patented myopia control technology // Hong Kong Unveils April 30 Launch for Landmark Crypto ETFs // ESG Achievement Awards 2023/2024 is Open for Application, Celebrating Innovative Sustainable Practices and Responsible Risk Management // Central Bank of Nigeria Debunks Rumors of Crypto Account Freeze // Galaxy Macau’s Sakura Cultural Festival Kicked off in Splendor // Booming Region Fuels Innovation Surge //