shellshock virus
BBC news has posted a story about a new virus called shellshock. This virus apparently affects Mac computers. Anyone else come across this?
iMac (27-inch Late 2009), OS X Mavericks (10.9), new download
Apple Event: May 7th at 7 am PT
BBC news has posted a story about a new virus called shellshock. This virus apparently affects Mac computers. Anyone else come across this?
iMac (27-inch Late 2009), OS X Mavericks (10.9), new download
It's not a virus. It's just the latest scare tactic promulgated by popular media outlets to ensure the uninformed among us remain uninformed. The fact you characterize it as a "virus" is proof of that, on its face.
If you are running a web server download and install the recent patch from the GNU project archive. If and when Apple will release an update to the Bash version included with OS X is up to them.
There are plenty of bad things that could happen to a system due to existing vulnerabilities, known or unknown. There is no reason for any more concern today than there has ever been. Bash has been included with OS X for years, perhaps since its inception.
Similar vulnerabilities may also be discovered and exploited, now or in the future. The resulting effects, if there are any, cannot be accurately predicted.
Until then:
Detailed info from user fmiranda, who lists him/herself as a Red Hat Solution Architect. In short, someone who likely knows a ton about Unix/Linux.
The truth is: yes you are technically vulnerable. But the reality is unless you allow SSH access from remote connections or a web server that runs server side scripting, you are not at risk. You are only truly vulnerable if someone you do not know can remotely access your machine & do so in a way where a Bash command can be executed.
So this issue is mainly of concern to system administrators on Mac OS X & Unix/Linux servers exposed to the world, not desktop users who do not enable SSH sharing.
Some reading regarding these issues I came across if anyone is interested😉
http://www.theregister.co.uk/2014/09/24/bash_shell_vuln/
http://nkush.blogspot.com/2014/09/patching-bash-shellshock-on-apple-max.html
https://access.redhat.com/articles/1200223
http://alblue.bandlem.com/2014/09/bash-remote-vulnerability.html
There is a patch out now - OS X bash Update 1.0 – OS X Mavericks.
shellshock virus