New "Shellshock" Bug Identified

A new flaw found in the Unix Bash shell has recently been identified by Akamai. This vulnerability has been around for over 2 decades now, but is just now being uncovered. That's a crazy thought, it took 22 years for someone to find a small flaw in such a widely used platform. This bug can effect Linux, OS X machines, routers, and older IoT devices. This exploit is said to be easily used by hackers, however most devices now use busybox, which has not been made vulnerable. My first reaction was, how did this go undetected for so long. I then did some research to find that Bash is entirely maintained by one person, Chet Ramey.

I think it's important to note that this bug was not being used maliciously prior to being discovered. I also feel that most people don't use Linux, OS X or routers running Bash anymore, unless they own a business. So as far as the public should be concerned, I don't think there should be much of a scare to this bug for personal use, unless something gets vastly exploited or more vulnerabilities become detected. However, businesses and the government agencies with older systems, do have to worry a lot.

Souces:
PC World
Wired

No comments:

Post a Comment