Skip to main content

FM
Former Member

Shellshock: 'Deadly serious' new vulnerability found

Open padlock More than 500 million computers could be affected, early estimates suggest

Related Stories

A "deadly serious" bug potentially affecting hundreds of millions of computers, servers and devices has been discovered.

The flaw has been found in a software component known as Bash, which is a part of many Linux systems as well as Apple's Mac operating system.

The bug, dubbed Shellshock, can be used to remotely take control of almost any system using Bash, researchers said.

Some experts said it was more serious than Heartbleed, discovered in April.

"Whereas something like Heartbleed was all about sniffing what was going on, this was about giving you direct access to the system," Prof Alan Woodward, a security researcher from the University of Surrey, told the BBC.

"The door's wide open."

Some 500,000 machines worldwide were thought to have been vulnerable to Heartbleed. But early estimates, which experts said were conservative, suggest that Shellshock could hit at least 500 million machines.

The problem is particularly serious given that many web servers are run using the Apache system, software which includes the Bash component.

Patch immediately

Bash - which stands for Bourne-Again SHell - is a command prompt on many Unix computers. Unix is an operating system on which many others are built, such as Linux and Mac OS.

The US Computer Emergency Readiness Team (US-Cert) issued a warning about the bug, urging system administrators to apply patches.

However, other security researchers warned that the patches were "incomplete" and would not fully secure systems.

Of particular concern to security experts is the simplicity of carrying out attacks that make use of the bug.

Replies sorted oldest to newest

On an unrelated matter...everyone with a windows machine should have these two pieces of software and run them at lease once a week.

 

http://thisisudax.org/downloads/JRT.exe
https://toolslib.net/downloads...wnload/1-adwcleaner/

 

they help with these annoyances. Do not download from anywhere but these links. These are the official sites.


Ask Toolbar
    Babylon
    Blekko
    Claro / iSearch
    Conduit
    Crossrider
    DealPly
    Delta
    Facemoods / Funmoods
    Findgala
    Globasearch
    Hao123
    iLivid
    Iminent
    IncrediBar
    MocaFlix
    MyPC Backup
    MyWebSearch
    PerformerSoft
    Privitize
    Qvo6
    Searchqu
    Snap Do
    Swag Bucks
    Wajam
    Web Assistant
    WhiteSmoke
    Zugo



FM
Originally Posted by cain:

Thanks Stormy

For those of you so crippled that you cannot even get a browser address you need to reset the browsers.

 

In Mozilla firefox; type about: support in the URL (address) bar and press enter. On the right of the new screen that comes up you will see the option to reset the browser.

 

It clears the browser of those hijackers and toolbars etc but it is only temporary. Use that opportunity to get well armed with the two programs above to start getting rid of the annoyances.

 

You need to note the programs that say the find something on your computer that only they can clean if you pay them. Uninstall these in safe mode and restart.

FM
Last edited by Former Member

Add Reply

×
×
×
×
×
Link copied to your clipboard.
×
×