The Shellshock Bug

Introduction

This vulnerability often occurs in the Unix bash shell, found on every Unix/Linux based web server, server and network device. This makes it highly versatile in its exploitability and its applications, thus contributing to its popularity.

How does it work?

Due to the absence of a sanitation mechanism for environment variables in the bash script, there exists no method of verifying the source of HTTP requests. Thus there exists a vulnerability dubbed the “shellshock” vulnerability first spotted by Stephane Chazelas in 2014.

The concern lies within the simplicity of its implementation. All an assailant needs are basic programming skills, a server and access to malware. In addition, the cost to carry out such an attack is practically a couple of hundred rupees a month. Thus this hacking strategy proves to be ideal with minimal knowledge, price and little effort.

Vulnerability

For example, routers and some IoT devices use Bash scripts in their routine functioning and are connected to your computers via LAN’s putting the entire network at risk.

The shellshock bug can also be used in DDoS(distributed denial-of-service) attack to either delay server response, clutter the network with junk commands to deny users regular functionality or handcuff the server to ensure it is unable to handle any requests.

Why is it still prominent, and how to tackle it?

Conclusion:

Liked our idea or what we do? Do you want to become a beta-tester for us? or are you interested in a live demo of our product?

Participate in our beta testing which is live!! @ https://beta.bugbase.in/

--

--

India’s first consolidated Bug Bounty Platform’s technical blog by Aditya Arun Iyer

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
BugBase - The BugGyaan Blog

India’s first consolidated Bug Bounty Platform’s technical blog by Aditya Arun Iyer