TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Internet

Remember the Heartbleed? the Shellshock bug is more serious

Paul Balo by Paul Balo
September 29, 2014
in Internet, Security
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email
In Brief
  • Somehow there always seems to be another Internet security disaster around the corner.
  • Now the bug, Shellshock (officially CVE-2014-6271), a far more serious vulnerability, is running uncontrolled over the Internet.
  • It’s never a good time to panic, but if you’re discouraged I don’t blame you; I know I am.

Somehow there always seems to be another Internet security disaster around the corner. A few months ago everyone was in a panic about Heartbleed.
Now the bug, Shellshock (officially CVE-2014-6271), a far more serious vulnerability, is running uncontrolled over the Internet. It’s never a good time to panic, but if you’re discouraged I don’t blame you; I know I am.

In retrospect, the grave concern over Heartbleed seems misplaced. As information disclosure bugs go it was a really bad one, but it was only an information disclosure bug and a difficult one to exploit. The sky’s the limit on attacks with Shellshock and it’s so easy to exploit that it’s already being widely-exploited according to research firm Fireeye, which says they have already observed several forms of attack:
• Malware droppers
• Reverse shells and backdoors
• Data exfiltration
• DDoS

Of course it’s not just Fireeye; everyone is reporting widespread sightings of exploits. SeeKaspersky, Trend Micro, HP Security Research and many others.
Speaking of HP, their TippingPoint unit states that their network IPS has been updated to recognize known attacks using Shellshock. A vigorously updated IPS, deployed not just at the perimeter but also at critical points within the network, may be the only effective systemic protection you have against Shellshock for now. HP is not the only IPS around of course. And remember that an IPS is more of a protection against known exploits than against the vulnerability generally.

shellshock

This particular bug has been in the Bash shell for over two decades. The implications of this are really bad. First, it means that an extremely important and popular program either went unscrutinized or poorly-scrutinized. Surely there are many other such problems out there. Don’t be surprised if several of them have been used carefully and surreptitiously for targeted attacks for years. In fact, don’t be surprised if Shellshock has been used in the past.
All sorts of horrible scenarios are possible with Shellshock. It’s not just limited to web server attacks. Fireeye shows how different Internet services, even DHCP and SSH, can be exploited to perform the attack, as long as Bash is the shell, and it usually is. They demonstrate automated click fraud, stealing the host password file, several DDOS attacks using the server and several ways to establish a shell on the server without any malware running on it.

Also worth reading
US Lawmakers Push AI Kill Switch Bill After OpenAI Rogue-Model Incident Proofpoint Says Paying Ransomware Gangs Can Invite A Second Demand OpenAI Says Its Test Models Breached Hugging Face During Cyber Evaluation Kenya Restores President Ruto Website After Bitcoin Ransom Hack Hugging Face Says An Agentic AI System Hacked Its Data Pipeline Suno Hack Exposes The Training-Data Fight Behind AI Music

shellshock-rob-graham-twitter

Another nasty aspect of this bug is that so many *NIX servers are out of sight/out of mind. There is (usually) no automatic update process that runs periodically. This was true of Heartbleed as well, but OpenSSL has nowhere near the ubiquity of Bash, and even where OpenSSL is present it doesn’t necessarily work with critical information..
The open source software community also inspires little confidence with the way the initial updates proved inadequate. The release of the initial Shellshock bug was withheld until a patch was available, but it wasn’t long before further research showed that additional related vulnerabilities exist and that they needed patches as well. (Current Bash versions address all known vulnerabilities — and, tautologically, none of the unknown ones).
Of course, reactive patching like this is a loser’s game. As Heartbleed and many earlier vulnerability crises have shown, a proactive auditing policy and procedure is required if you want to be prepared for cases like these. Proper implementation of such a policy would give you a current and precise inventory of software on your network. You really want to have this, because attackers who have penetrated your network probably have one too. You need to react at least as quickly as they do.

This is hard work and the sort of best practice with which everyone agrees, but for which few have time. And even it is largely just a better way to be reactive, although it does have the added advantage of helping to find unauthorized software on the network. The less you know about what software you are running and where, the longer it will take for you to deal with crises like Shellshock. And more will come. And if your slow reaction leads to damages to customers or third parties they can justifiably say that you didn’t do everything you could to protect your systems.

source: Larry Seltzer/zdnet

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • bluehammer-will-dormann
    BlueHammer Windows Exploit Exposes Microsoft Bug…
  • 020tYFWBL4Yz8jIIFUdKDR1-22
    A Fix to Microsoft Windows Defender And Security Flaws
  • 2026-05-08-Linux_LPE-Dirty_Frag-Aufmacher-3f0ce52bb528ed97
    New Linux Zero-Day Flaw 'Dirty Frag' With Root…
  • microsofts-surface-duo-dualscreen-androi-5f1f3d057e8c350ae07dd862-1-jul-28-2020-15-24-20-poster
    Microsoft Patch Tuesday Fixes 63 Bugs, 1 Zero-Day
  • Anthropic-Mythos-Project-Glasswing
    Anthropic Plans Public Release of Mythos‑Class…
  • samsung-browser-internet-lost-3
    Samsung Drops "Internet", Renames Browser To "Browser"
  • blog5f352fc3b2393_wp
    Hackers Exploit Popular WordPress Backup Tool Used…
  • android
    Google Patches 107 Flaws Including 2 Android Zero-Days
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Internet Security
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Paul Balo

Paul Balo

Paul Balo is the founder of TechBooky and a highly skilled wireless communications professional with a strong background in cloud computing, offering extensive experience in designing, implementing, and managing wireless communication systems.

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • SpaceX Deploys V3 Starlink Satellites But Loses Another Super Heavy Booster July 26, 2026
  • The Boring Company Reportedly Seeks $4B As Musk’s Tunnel Bet Gets A $20B Valuation July 26, 2026
  • Claude Opus 5 Gives Anthropic A Cheaper Answer To The Fable 5 Problem July 25, 2026
  • Meta Makes Facebook Verified Free As AI Scams Make Real People Harder To Spot July 24, 2026
  • SAP Cloud Growth Eases Fears That AI Will Weaken Enterprise Software July 24, 2026
  • US Lawmakers Push AI Kill Switch Bill After OpenAI Rogue-Model Incident July 24, 2026
  • Airtel Money’s $61B Quarter Makes Its London IPO A Bigger Africa Fintech Story July 24, 2026
  • Intel Q2 Revenue Jumps As AI Compute Demand Lifts Chip Business July 24, 2026
  • AMD And Anthropic Deal Puts Real Pressure On Nvidia’s AI Chip Lead July 24, 2026
  • New York’s Data Centre Pause Shows AI Infrastructure Is Hitting Politics July 23, 2026
  • OpenAI Researcher’s $2B Drug Discovery Plan Shows AI Biotech Hype Is Back July 23, 2026
  • Airtel Africa Q1 Shows Mobile Money And Data Are Doing The Heavy Lifting July 23, 2026

Browse Archives

July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Jun    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.