{"id":73541,"date":"2014-09-25T21:30:52","date_gmt":"2014-09-25T19:30:52","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=73541"},"modified":"2025-07-02T00:27:09","modified_gmt":"2025-07-02T07:27:09","slug":"what-is-the-shellshock-bash-bug","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/what-is-the-shellshock-bash-bug\/","title":{"rendered":"Why the Shellshock Bash bug is even scarier than Heartbleed"},"content":{"rendered":"<p>A newly discovered vulnerability within the command line which runs in the background of Mac OS X, Linux and many Unix based system lets hackers remotely execute commands to computers and websites. Bash has been around for <strong>twenty-five years<\/strong> but this vulnerability was just <a title=\"Red Hat\" href=\"https:\/\/securityblog.redhat.com\/2014\/09\/24\/bash-specially-crafted-environment-variables-code-injection-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">recently discovered<\/a> and has the potential to exploit computers, devices, websites and more. We will likely continue seeing damage from the Shellshock Bash bug for years to come.<\/p>\n<h3>What is Bash and why are so many things using it?<\/h3>\n<p>Without getting too technical, Bash is basically an <strong>interpreter for computers<\/strong>, allowing users to execute commands on Unix and Linux systems. It is used on a variety of devices because the software is open source and is the industry standard for web servers.<\/p>\n<p style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-73549\" title=\"web server graph\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/09\/web-server-graph-568x290.png\" alt=\"Netcraft web server OS breakdown\" width=\"568\" height=\"290\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/web-server-graph-568x290.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/web-server-graph-256x130.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/web-server-graph.png 697w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><em>Image credit: <a title=\"Netcraft\" href=\"http:\/\/news.netcraft.com\/archives\/2014\/09\/24\/september-2014-web-server-survey.html\" target=\"_blank\" rel=\"noopener noreferrer\">Netcraft<\/a><\/em><\/p>\n<p>Over half of all web servers in the world are running <strong>Apache<\/strong>, which is a web server application responsible for HTTP, or hypertext transfer protocol. Apache is credited for the huge growth of the internet.<\/p>\n<h3>How is Bash being exploited?<\/h3>\n<p>Bash is allowing attackers to <strong>execute arbitrary code<\/strong> on affected systems without any form of authentication. This type of attack is called &#8220;code injection,&#8221; and there are many environmental variables for hackers to exploit.<\/p>\n<p>As mentioned previously, many websites run on web servers that are vulnerable to the Shellshock Bash bug. <strong>This means entire websites could theoretically be taken down by it<\/strong>. Worse, there are tons of devices that support Bash like <strong>web cameras<\/strong> and <strong>routers<\/strong>. Home automation tools like networked lightbulbs and thermostats could be affected as well.<\/p>\n<h3>Good thing I&#8217;m using Windows.<\/h3>\n<p>While the <strong>Windows operating system isn&#8217;t directly affected<\/strong>, the devices you connect to your computer may still use Bash. The router you use to connect your Windows computer to the internet is most likely running an operating system that&#8217;s vulnerable.<\/p>\n<h3>Is this as bad as Heartbleed?<\/h3>\n<p>The Shellshock Bash bug is drawing many comparisons to the <a title=\"&quot;Heartbleed&quot; security bug leaves majority of the web vulnerable\" href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed vulnerability<\/a> discovered a couple months ago. While the vulnerabilities are completely different, the <strong>widespread effects of both attacks are comparable<\/strong>. We&#8217;ll be seeing the effects of both vulnerabilities for many years to come.<\/p>\n<p>The difference is, Heartbleed only affected websites and services. The Shellshock Bash bug can affect sites, computers and many other devices.<\/p>\n<p>Attackers know about the exploit and are already using it. Someone created an internet scanning tool to probe websites that are vulnerable to the Shellshock Bash bug. <em>Ars Technica<\/em> found <a title=\"Ars Technica\" href=\"http:\/\/arstechnica.com\/security\/2014\/09\/concern-over-bash-vulnerability-grows-as-exploit-reported-in-the-wild\/\" target=\"_blank\" rel=\"noopener noreferrer\">over 2 billion sites<\/a> that &#8220;fit the profile for the Shellshock exploit.&#8221;<\/p>\n<p>We don&#8217;t know how far hackers will go. These hackers could possibly creating worms that can pass through firewalls and self-replicate, infecting a wide array of machines on a network without users noticing. Hackers could even <strong>snoop on your personal data<\/strong> once your machine is compromised using the bug.<\/p>\n<p>For now, we&#8217;re waiting to see what attackers are going to do with the exploit.<\/p>\n<h3>What can I do to protect myself?<\/h3>\n<p>If you&#8217;re a Mac user and want to find out if you&#8217;re vulnerable, you can run the following script in the <strong>Terminal<\/strong> application (located in your Utilities folder).<\/p>\n<p style=\"text-align: center\"><strong>$ env x='() { :;}; echo vulnerable&#8217; bash -c &#8216;echo hello&#8217;<\/strong><\/p>\n<p>If the command reads &#8220;vulnerable&#8221; and &#8220;hello&#8221; then your machine is susceptible to the Shellshock bug. There&#8217;s a way to patch the vulnerability yourself by <strong>recompiling Bash<\/strong> but that&#8217;s extremely technical and <strong>not for the faint of heart<\/strong>. If you feel comfortable with the command line, head over to <a title=\"Stack Exchange\" href=\"http:\/\/apple.stackexchange.com\/questions\/146849\/how-do-i-recompile-bash-to-avoid-the-remote-exploit-cve-2014-6271-and-cve-2014-7\/146851#146851\" target=\"_blank\" rel=\"noopener noreferrer\">Stack Exchange<\/a> for details about how to patch the bug. Mere mortals will want to <strong>watch closely for an update from Apple<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-73574\" title=\"Mac terminal\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/3\/2014\/09\/Screen-Shot-2014-09-25-at-10.32.44-AM-568x398.png\" alt=\"Mac terminal shellshock bash bug\" width=\"568\" height=\"398\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/Screen-Shot-2014-09-25-at-10.32.44-AM-568x398.png 568w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/Screen-Shot-2014-09-25-at-10.32.44-AM-256x179.png 256w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/3\/2014\/09\/Screen-Shot-2014-09-25-at-10.32.44-AM.png 682w\" sizes=\"auto, (max-width: 568px) 100vw, 568px\" \/><\/p>\n<p>For most users, the best thing you can do now is to <strong>make sure you are running the latest software on all your devices<\/strong>. And I mean <em>all<\/em> of them. Check for <strong>firmware updates on your router<\/strong>, which most users tend to forget about. Consult the manual for your particular router to see how to update the firmware as each model has different steps.<\/p>\n<p>Users will also want to <strong>watch out for any suspicious sites or emails<\/strong> that want you to install software. With this bug causing a huge stir, you can be sure hackers will be looking to capitalize on people&#8217;s fears by offering <strong>fake software<\/strong> solutions to &#8220;patch&#8221; your computer.<\/p>\n<p>Beyond keeping your devices up to date and being careful online, control over this bug is largely out of your hands. You&#8217;ll have to wait for sites to patch the vulnerability on their web servers.<\/p>\n<p><em>Sources: <a title=\"Red Hat security blog\" href=\"https:\/\/securityblog.redhat.com\/2014\/09\/24\/bash-specially-crafted-environment-variables-code-injection-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">Red Hat<\/a> | <a title=\"Troy Hunt\" href=\"http:\/\/www.troyhunt.com\/2014\/09\/everything-you-need-to-know-about.html\" target=\"_blank\" rel=\"noopener noreferrer\">Troy Hunt<\/a><\/em><\/p>\n<h3>Related Stories<\/h3>\n<p><a title=\"Why does a keyboard app need 'Full Access' to my iPhone?\" href=\"http:\/\/features.en.softonic.com\/why-does-a-keyboard-app-need-full-access-to-my-iphone\" target=\"_self\" rel=\"noopener noreferrer\">Why does a keyboard app need &#8216;Full Access&#8217; to my iPhone?<\/a><\/p>\n<p><a title=\"Firefox and Thunderbird get 'critical' security updates\" href=\"http:\/\/news.en.softonic.com\/firefox-and-thunderbird-get-critical-security-updates\" target=\"_self\" rel=\"noopener noreferrer\">Firefox and Thunderbird get &#8216;critical&#8217; security updates<\/a><\/p>\n<p><a title=\"The next version of Android will encrypt your data by default\" href=\"http:\/\/news.en.softonic.com\/next-android-version-will-encrypt-your-data-by-default\" target=\"_self\" rel=\"noopener noreferrer\">The next version of Android will encrypt your data by default<\/a><\/p>\n<p><a title=\"Updates for Adobe Reader and Acrobat fix security vulnerability\" href=\"http:\/\/news.en.softonic.com\/updates-for-adobe-reader-and-acrobat-fix-security-vulnerability\" target=\"_self\" rel=\"noopener noreferrer\">Updates for Adobe Reader and Acrobat fix security vulnerability<\/a><\/p>\n<p style=\"text-align: right\"><em>Follow me on Twitter: <a href=\"https:\/\/twitter.com\/lewisleong\" target=\"_self\" rel=\"noopener noreferrer\">@lewisleong<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly discovered vulnerability within the command line which runs in the background of Mac OS X, Linux and many Unix based system lets hackers remotely execute commands to computers and websites. Bash has been around for twenty-five years but this vulnerability was just recently discovered and has the potential to exploit computers, devices, websites &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/what-is-the-shellshock-bash-bug\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Why the Shellshock Bash bug is even scarier than Heartbleed&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":73559,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[2441],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-73541","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/73541","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=73541"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/73541\/revisions"}],"predecessor-version":[{"id":330095,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/73541\/revisions\/330095"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/73559"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=73541"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=73541"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=73541"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=73541"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=73541"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=73541"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}