[Cialug] Shellshock Bash Remote Code Execution Vulnerability

Scott Yates Scott at yatesframe.com
Thu Sep 25 12:23:12 CDT 2014


Help me understand a couple thingss:

How is this operating remotely?  I understand this being a problem if
people have shell access to a box, but how is it that anything "remote" is
allowed to set an environment variable in the first place?
​
​Am I missing something here, or is this only a problem if someone already
has shell access?​


More information about the Cialug mailing list