Lightning Base

Get Started Now

  • Home
  • Tour
  • Pricing
  • Contact
  • About

Bash Exploit / Shellshocker and Lightning Base

Friday, September 26th, 2014 / Posted In :Security /  By :Chris Piepho / Leave a comment

We don’t generally discuss server/software vulnerabilities on this blog unless we’re making a change/update that will affect client sites. But when issues hit the general media and we start to get support tickets asking if we’re aware about the problem, I like to post a general update for everyone so clients know we’re taking care of things.

If you don’t want to read all this, yes, we have updated bash and our systems should be secure. If you’re interested in some details:

Recently there have been a number of articles, both in the WordPress community and on more general tech sites about a bash (bourne-again shell) exploit, often referred to as ‘Shellshocker’. This is a serious vulnerability, largely because it affects an extremely wide variety of machines, everything from servers on various operating systems to embedded systems. It is not something that is easy to exploit on many machines, but as researchers look into it further an expanding number of ways to take advantage of the problem seem to be popping up. I don’t believe it would be good for anyone to assume un-patched systems are safe.

The vulnerability first came to our attention yesterday morning. That afternoon a patch was released from Redhat and to CentOS and Cloudlinux. We upgraded bash on all systems shortly after the updated versions reached the respective repositories. From what I’m seeing in our logs, there were a few scans that appear to be security researchers testing for vulnerabilities at that point, who have been followed by actual malicious exploit attempts today.

We also put in place webapp firewall rules to block the attack before patches were released. Rules like that are rarely 100%, the rule has to be perfect to block all attacks. But it makes it more difficult for exploit attempts to get through, and at this point I don’t believe they were even necessary, the patches appear to have rolled out before malicious attempts to exploit the vulnerability hit our systems.

Redhat/Linux developers are still looking at a second issue with Bash. My understanding is that this is a harder-to-exploit vulnerability, but also harder to patch. Once they have settled on a fix and rolled that out to the repositories, we will be updating again to make sure the systems are secure.

UPDATE: The fix for the second portion of the vulnerability (CVE-2014-7169) has been released and applied to all of our systems.

This isn’t something that our clients should have to worry about, but if you have any questions, don’t hesitate to open a ticket in our client area.



Author : Chris Piepho

Chris is the founder of Lightning Base. You'll find him all over around here - writing on this blog, providing customer service, and handling whatever else needs to be done. You can reach him easily by filling out our contact form and addressing your message to Chris.

WordPress 4.0 Released
SSL v3 Disabled – POODLE Vulnerability
Click here to cancel reply.

Leave a Reply

Post Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

Menu

  • Home
  • Tour
  • Pricing
  • Contact
  • About

Archives

  • November 2024
  • December 2018
  • June 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • September 2015
  • August 2015
  • July 2015
  • May 2015
  • April 2015
  • February 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • May 2014
  • April 2014
  • September 2013
  • June 2013
  • April 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • May 2012
  • March 2012
  • February 2012
  • January 2012

WP Host

Lightning Base: Making WordPress faster, easier, better. Take the tour or get started today.

From the Blog

  • Mitigating the Really Simple SSL Security Vulnerability

    Note: This blog has been pretty quiet for a long time. We're looking to change that and more frequently discuss things h...

  • WordPress 5.0

    WordPress 5.0 will be released tomorrow, December 6th. This is one of the largest updates WordPress has seen in a long t...

  • WordPress 4.5.3 Security Update Released

    WordPress 4.5.3 was released today, as announced on WordPress.org. The Update This is a security update, it is important...

  • Public Beta Invite: HTTP/2, HTTPS Caching

    We've been working on changes that enable HTTP/2 and built-in caching for HTTPS sites/pages for several months now. At t...

Menu

  • Home
  • Tour
  • Pricing
  • Contact
  • About
  • Affiliates
  • Client Login

© 2020 Lightning Base LLC. All rights reserved. | Privacy Policy | Terms of Use