Live data from Hacker News

Easy, realtime, system-wide Shellshock monitoring

draios.com

31–34 of 34 posts

Re: Easy, realtime, system-wide Shellshock monitoring

#31
post #26

I guess there are already worms around, exploiting this bug. Thus, has somebody thought of exploiting and patching the attackers in response?

I haven't studied a worm in years, but historically it's been common practice to close the door you came in through upon entry, for exactly this reason.

Common, but by no means ubiquitous.

Re: Easy, realtime, system-wide Shellshock monitoring

#33
I'll give props to hackers clever enough to poke holes in a massive beast of a system that enjoys boasting itself as "impenetrable", but these, I'm not too happy about - http://www.pressreader.com/profile/Media_Mentions/shellshock. The potential effects are much too close for comfort.

Re: Easy, realtime, system-wide Shellshock monitoring

#34
post #6
post #2

well, installing a LKM, just that =p Now sysdig aint bad per se but id like to see it mainlined or using mainline code

Fair point, even though: - At this point sysdig is estimated to have tens of thousands of users, and we haven't gotten a kernel bug in a while, with people (us included) regularly using it a lot in production. Of course, I see the irony of mentioning this in a "shellshock" thread - the dkms packaging should completely hide all the complexities required in maintaining a kernel module - Part of the kernel code, if you…

its respectable but in the end it doesnt matter. when you have to run this on thousand of systems that have not been tested with that LKM, the LKM can potentially destroy everything.

its not like if grekh code was bug free - theres a lot of bugs being fixed daily in the kernel as well.

additionally, the kernel distribution path has better verifications than sysdig's and sorry, ill trust that more than a few guys. It doesnt make your work any less, its just the way it is.

Post reply on HN