Archive for Shellshock

echo vulnerable

Posted in Linux with tags , , , on October 3, 2014 by xi'an

screen shot with ubuntu 10.10Even though most people are now aware of the Shellshock security problem on the bash shell, here is a test to check whether your Unix system is at risk:

env x='() { :;}; echo vulnerable' bash -c 'echo hello'

if the prompt returns vulnerable, it means the system is vulnerable and needs to be upgraded with the proper security patch… For instance running

sudo apt-get update && sudo apt-get install --only-upgrade bash

for Debian/Ubuntu versions. Check Apple support page for Apple OS.