[GLLUG] Bash Bug

James Roberts j.roberts at stabilys.com
Thu Sep 25 17:41:11 UTC 2014


On 25/09/14 18:25, chris procter wrote:
...

> I'd still say heartbleed is worse though, who runs bash cgi scripts?

Yes I'd agree - but, I'd also say quite a lot of low-end modem-routers, 
access points, webcams, IoT and other very low resource systems will do 
just this, especially older ones: when I learned web programming a 
really long time ago it started out with calling shell functions from 
cgi! I still have the code for a bash web server, somewhere... and we 
know where many manufacturers get their scripts (from any website on the 
net).

Most more current stuff will probably use busybox instead (which has 
ash, effectively).

MeJ

-- 
Stabilys Ltd		www.stabilys.com
244 Kilburn Lane
LONDON
W10 4BA

0845 838 5370




More information about the GLLUG mailing list