shellshock - detect in Apache?

Gary Stainburn gary.stainburn at ringways.co.uk
Fri Sep 26 14:37:35 UTC 2014


On Friday 26 September 2014 15:21:27 Michael D. Setzer II wrote:
> Problem is you are still running the old bash bash -c should be ./bash -c
>
> The only issue that I see is that the make install isn't replacing the
> /bin/bash, but is putting the new bash in
> /usr/local/bin/bash
>
> Tried to copy bash to the /bin, but it seems to be in use?
> But after the make install, it did work.
> On one system, I needed to restart to get it to take affect, but have only
> check a two systems with older versions of Fedora.
>

Doh :-)

It now works as expected.  I have copied the file to /usr/bin/bash - the 
existing / old version of bash is /bin/bash

I have updated the shell field in /etc/passed for a test user and then logged 
in as that user. All looks okay. Next step is to replace the old bash and 
cross my fingers.

If this works, I'll roll it out to the live servers too.

Thanks again


More information about the users mailing list