Daily Archives: 25.09.2014

Securing Mac-OS from CVE-2014-6271 (Shellshock / Bash bug)

For this to work you need to have Xcode installed. If you don't have it, try: sudo xcode-select –install In a terminal execute these commands: mkdir bash-fix cd bash-fix curl https://opensource.apple.com/tarballs/bash/bash-92.tar.gz | tar zxf – cd bash-92/bash-3.2 curl https://ftp.gnu.org/pub/gnu/bash/bash-3.2-patches/bash32-052 | patch -p0 cd .. xcodebuild Wait until you see "BUILD SUCCEEDED". Backup your old executables: […]

Test for Bash Bug Vulnerability CVE-2014-6271 (Shellshock)

Try this line in a Mac or Linux terminal to know if you're vulnerable nor not: env x='() { :;}; echo vulnerable' bash -c 'echo test' If you're not vulnerable, this line will just output "test", else it will output "vulnerable test". For Debian Wheezy users there's an official update available already. For those that […]