I guess there are already worms around, exploiting this bug. Thus, has somebody thought of exploiting and patching the attackers in response?
Common, but by no means ubiquitous.
31–34 of 34 posts
I guess there are already worms around, exploiting this bug. Thus, has somebody thought of exploiting and patching the attackers in response?
Common, but by no means ubiquitous.
shellshock_detector.lua seems to let this more obscure exploit slip by, undetected: http://seclists.org/oss-sec/2014/q3/696 http://seclists.org/oss-sec/2014/q3/734
well, installing a LKM, just that =p Now sysdig aint bad per se but id like to see it mainlined or using mainline code
Fair point, even though: - At this point sysdig is estimated to have tens of thousands of users, and we haven't gotten a kernel bug in a while, with people (us included) regularly using it a lot in production. Of course, I see the irony of mentioning this in a "shellshock" thread - the dkms packaging should completely hide all the complexities required in maintaining a kernel module - Part of the kernel code, if you…
its not like if grekh code was bug free - theres a lot of bugs being fixed daily in the kernel as well.
additionally, the kernel distribution path has better verifications than sysdig's and sorry, ill trust that more than a few guys. It doesnt make your work any less, its just the way it is.