Skip to the main content.

1 min read

Caution: Watch Out for Shellshock, the Latest Vulnerability That’s Spreading Rapidly & Could Potentially Be More Dangerous Than the Infamous Heartbleed!

Bash SecurityA major vulnerability, CVE-2014-6271, has been spreading rapidly and impacting a wide range of businesses. CVE-2014-6271, also known as “shellshock,” impacts “bash” software, which is used in most business computers. According to some researchers, shellshock could potentially be more dangerous than heartbleed, the open/SSL bug that had most business owners in a state of panic about their security a few months ago!

So how does the shellshock vulnerability work? Well, the vulnerability allows attackers to inject their own malicious code into bash, a command line interface that connects users to Unix-based systems. Once the attacker injects malicious code into bash, they’re able to:

  • Access sensitive information.
  • Steal business data.
  • Execute code to slow performance.

While bash was written over 30 years ago, it’s transformed into one of the most widely used utilities in the business environment. In fact, OS X, Linux, Windows, and Android often run bash. In addition, web servers commonly run bash as well; which means the vulnerability puts a lot of businesses at risk.

Chances Are, Most of Your Systems Are Running Bash – Don’t Forget to Apply the Latest Security Patches & Bug Fixes on All of Your Workstations!

When it comes to vulnerabilities like shellshock, it’s fundamental to ensure you’re applying the latest security patches and bug fixes on all of your workstations; otherwise, you’re open to malware and viruses infecting your network. Aside from applying the latest security patches and bug fixes, what can be done to stay protected? Here’s a few ideas:

  • Download legitimate anti-virus software and keep the software up-to-date, then make sure you’re scanning for viruses on a regular basis.
  • Install a reliable firewall and make sure it’s configured properly to block unauthorized or dangerous traffic.
  • Adjust your browser’s security settings to increase its ability to combat intrusions effectively.

According to Robert Graham, a Security Researcher, “While the known systems, like your web server, are patched, unknown systems remain unpatched. We saw that with the heartbleed bug, six months later, hundreds of thousands of systems remain vulnerable.”

He continued, “These systems are rarely things like web servers, but are more often things like Internet-enabled cameras. Internet-of-things devices, like video cameras, are especially vulnerable because a lot of their software is built from web-enabled bash scripts.”

Feeling concerned about shellshock? To learn more, or to schedule a no-obligation security assessment, give us a call at {phone} or send us an email at {email}. {company} is here to help you minimize the risk of an attack or infection.

Cloud Migration Will Affect More Than $1 Trillion in IT Spending by 2020

Cloud Migration Will Affect More Than $1 Trillion in IT Spending by 2020

It’s nearly all you hear about these days in the world of IT – along with ransomware and other malware cyberattacks which are all the rage with...

Read More
The Long-Awaited iPhone 6 Will Be Here Sooner Than You Think – Here’s What You Can Expect!

The Long-Awaited iPhone 6 Will Be Here Sooner Than You Think – Here’s What You Can Expect!

While the iPhone 5S is less than six months old, there’s been a lot of rumors about its replacement. And if previous versions are any indication, the...

Read More
Capital One Data Breach Affects More Than 100 Million Customers

Capital One Data Breach Affects More Than 100 Million Customers

Capital One Data Breach Affects More Than 100 Million Customers and Small Businesses in The U.S. & 6 Million in Canada On July 29, 2019, Capital One...

Read More