


{"id":2761,"date":"2014-09-26T09:52:45","date_gmt":"2014-09-26T14:52:45","guid":{"rendered":"http:\/\/www.poweradmin.com\/blog\/?p=2761"},"modified":"2015-10-21T13:04:06","modified_gmt":"2015-10-21T18:04:06","slug":"shellshock-vulnerability-worse-than-heartbleed","status":"publish","type":"post","link":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/","title":{"rendered":"Shellshock vulnerability &#8211; worse than HeartBleed :("},"content":{"rendered":"<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">Do you remember <a title=\"HeartBleed\" href=\"\/blog\/heartbleed-bug-are-you-affected\/\" target=\"_blank\">HeartBleed<\/a> from a few months back? There\u2019s another huge vulnerability that just came to light: <a title=\"PA Server Monitor Product Security\" href=\"\/servermonitor\/product-security.aspx\">Shellshock<\/a>. And this one is much worse than <a title=\"PA Server Monitor and HeartBleed\" href=\"\/servermonitor\/product-security.aspx\">HeartBleed<\/a> \ud83d\ude41<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as \u2018environment variables\u2019 and unfortunately, many <\/span><span style=\"font-family: verdana,geneva; font-size: 12pt;\">programs pass data through these variables. So an attacker could conceivably take over a server by simply:<\/span><\/p>\n<ul>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">using a script as a username or password<\/span><\/li>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">sending an email body or email subject that contains a bad script<\/span><\/li>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">setting a web page title to a script value so that web page scrapers would request the page and then get infected<\/span><\/li>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">post a script value to a web form<\/span><\/li>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">save a document that contains a bad script<\/span><\/li>\n<li><span style=\"font-family: verdana,geneva; font-size: 12pt;\">etc\u2026<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">What makes it so scary is bash is used all over in a large portion of Unix\\Linux software. That means servers, routers, refrigerators, phones, etc. can potentially be vulnerable.<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">It\u2019s like a lock company that made millions of locks over 20 years for homes, cars, buildings, cabinets, vaults, etc. It has just come to light that one particular factory worker\u2019s locks <\/span><span style=\"font-family: verdana,geneva; font-size: 12pt;\">are vulnerable to being opened without the key. The problem is, nobody knows exactly which locks that particular worker built over the 20 years. Everyone needs to be concerned.<\/span><\/p>\n<h2><span style=\"font-family: verdana,geneva; font-size: 12pt; color: #3366ff;\"><strong>What can you do to protect yourself from Shellshock?<\/strong><\/span><\/h2>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">If you have servers, update bash on any server\/device that you can. Check if your router, NAS, firewall, etc. have any updates posted.<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">If you are a consumer of services on the web (who isn\u2019t?), you\u2019re at the mercy of all of your service providers patching the software and services they use. \ud83d\ude41<\/span><\/p>\n<h2><span style=\"font-family: verdana,geneva; font-size: 12pt; color: #3366ff;\"><strong>Silver lining?<\/strong><\/span><\/h2>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">Windows servers almost never use bash, so they are most likely unaffected.<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">All Power Admin products are NOT vulnerable \u2014 we don\u2019t use bash, and don\u2019t use any library or third party code that uses Bash.<\/span><\/p>\n<h2><span style=\"font-family: verdana,geneva; font-size: 12pt; color: #3366ff;\"><strong>Storm Clouds<\/strong><\/span><\/h2>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">This, along with HeartBleed and Edward Snowden revelations, <span style=\"text-decoration: underline;\">might<\/span> have a chilling effect on cloud service adoption. And we like cloud services like everyone else!<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">With one exception\u2026. It\u2019s never made sense to us to have networks and servers monitored by the cloud. The monitoring software needs to be the most trusted because it has deep insight into the network, lists of server names, credentials to those servers, configuration information and so on.<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">Jen Andre has already discussed <a title=\"Nagios' vulnerability\" href=\"http:\/\/blog.threatstack.com\/cve-2014-6271-and-you-a-tale-of-nagios-and-the-bash-vulnerability\" target=\"_blank\" rel=\"nofollow\">Nagios\u2019 vulerability<img class=\"extlink-icon\" src=\"https:\/\/www.poweradmin.com\/blog\/wp-content\/plugins\/external-links-nofollow-open-in-new-tab-favicon\/images\/extlink.png\"><\/a> (many Nagios plugins use bash), which means monitoring products and online services based on Nagios are also vulnerable. Other online \u2018cloud monitoring\u2019 services are quite likely vulnerable too because most of them are Linux based.<\/span><\/p>\n<p><span style=\"font-family: verdana,geneva; font-size: 12pt;\">With Power Admin products, all of the private and sensitive information about your network and servers stays completely under your control on hardware you control. At least that is one part of this predicament that our customers don\u2019t need to worry about at all \ud83d\ude42<\/span><\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Do you remember HeartBleed from a few months back? There\u2019s another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed \ud83d\ude41 Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as \u2018environment variables\u2019 and unfortunately, many programs [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2765,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,13,10,6],"tags":[],"class_list":["post-2761","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general-it","category-pc-security","category-power-admin","category-tech"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Do you remember HeartBleed from a few months back? There&#039;s another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as &#039;environment variables&#039; and unfortunately, many programs\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Doug N\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Network Wrangler - Tech Blog | IT Tips, tricks, tutorials and just interesting stuff for IT folks.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"Do you remember HeartBleed from a few months back? There&#039;s another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as &#039;environment variables&#039; and unfortunately, many programs\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-09-26T14:52:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2015-10-21T18:04:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Do you remember HeartBleed from a few months back? There&#039;s another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as &#039;environment variables&#039; and unfortunately, many programs\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#article\",\"name\":\"Shellshock vulnerability \\u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog\",\"headline\":\"Shellshock vulnerability &#8211; worse than HeartBleed :(\",\"author\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/author\\\/doug\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/wp-content\\\/uploads\\\/2014\\\/09\\\/shellshock-bash.jpg\",\"width\":300,\"height\":300,\"caption\":\"Shellshock - Bash Bug\"},\"datePublished\":\"2014-09-26T09:52:45-05:00\",\"dateModified\":\"2015-10-21T13:04:06-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#webpage\"},\"articleSection\":\"General IT, PC Security, Power Admin, Tech\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/category\\\/general-it\\\/#listItem\",\"name\":\"General IT\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/category\\\/general-it\\\/#listItem\",\"position\":2,\"name\":\"General IT\",\"item\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/category\\\/general-it\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#listItem\",\"name\":\"Shellshock vulnerability &#8211; worse than HeartBleed :(\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#listItem\",\"position\":3,\"name\":\"Shellshock vulnerability &#8211; worse than HeartBleed :(\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/category\\\/general-it\\\/#listItem\",\"name\":\"General IT\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/#organization\",\"name\":\"Network Wrangler - Tech Blog\",\"description\":\"IT Tips, tricks, tutorials and just interesting stuff for IT folks.\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/author\\\/doug\\\/#author\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/author\\\/doug\\\/\",\"name\":\"Doug N\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/90e32c982e6837acc816890c16572bb55b183e1d633149b06a835fa076f040e9?s=96&d=mm&r=pg\",\"width\":96,\"height\":96,\"caption\":\"Doug N\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#webpage\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/\",\"name\":\"Shellshock vulnerability \\u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog\",\"description\":\"Do you remember HeartBleed from a few months back? There's another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\\\/Linux bash command processor. Bash can be forced to execute commands stored as 'environment variables' and unfortunately, many programs\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/author\\\/doug\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/author\\\/doug\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/wp-content\\\/uploads\\\/2014\\\/09\\\/shellshock-bash.jpg\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#mainImage\",\"width\":300,\"height\":300,\"caption\":\"Shellshock - Bash Bug\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/shellshock-vulnerability-worse-than-heartbleed\\\/#mainImage\"},\"datePublished\":\"2014-09-26T09:52:45-05:00\",\"dateModified\":\"2015-10-21T13:04:06-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/\",\"name\":\"Network Wrangler - Tech Blog\",\"description\":\"IT Tips, tricks, tutorials and just interesting stuff for IT folks.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.poweradmin.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog","description":"Do you remember HeartBleed from a few months back? There's another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as 'environment variables' and unfortunately, many programs","canonical_url":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#article","name":"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog","headline":"Shellshock vulnerability &#8211; worse than HeartBleed :(","author":{"@id":"https:\/\/www.poweradmin.com\/blog\/author\/doug\/#author"},"publisher":{"@id":"https:\/\/www.poweradmin.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2014\/09\/shellshock-bash.jpg","width":300,"height":300,"caption":"Shellshock - Bash Bug"},"datePublished":"2014-09-26T09:52:45-05:00","dateModified":"2015-10-21T13:04:06-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#webpage"},"isPartOf":{"@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#webpage"},"articleSection":"General IT, PC Security, Power Admin, Tech"},{"@type":"BreadcrumbList","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.poweradmin.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/#listItem","name":"General IT"}},{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/#listItem","position":2,"name":"General IT","item":"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#listItem","name":"Shellshock vulnerability &#8211; worse than HeartBleed :("},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#listItem","position":3,"name":"Shellshock vulnerability &#8211; worse than HeartBleed :(","previousItem":{"@type":"ListItem","@id":"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/#listItem","name":"General IT"}}]},{"@type":"Organization","@id":"https:\/\/www.poweradmin.com\/blog\/#organization","name":"Network Wrangler - Tech Blog","description":"IT Tips, tricks, tutorials and just interesting stuff for IT folks.","url":"https:\/\/www.poweradmin.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.poweradmin.com\/blog\/author\/doug\/#author","url":"https:\/\/www.poweradmin.com\/blog\/author\/doug\/","name":"Doug N","image":{"@type":"ImageObject","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/90e32c982e6837acc816890c16572bb55b183e1d633149b06a835fa076f040e9?s=96&d=mm&r=pg","width":96,"height":96,"caption":"Doug N"}},{"@type":"WebPage","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#webpage","url":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/","name":"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog","description":"Do you remember HeartBleed from a few months back? There's another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as 'environment variables' and unfortunately, many programs","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.poweradmin.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#breadcrumblist"},"author":{"@id":"https:\/\/www.poweradmin.com\/blog\/author\/doug\/#author"},"creator":{"@id":"https:\/\/www.poweradmin.com\/blog\/author\/doug\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.poweradmin.com\/blog\/wp-content\/uploads\/2014\/09\/shellshock-bash.jpg","@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#mainImage","width":300,"height":300,"caption":"Shellshock - Bash Bug"},"primaryImageOfPage":{"@id":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/#mainImage"},"datePublished":"2014-09-26T09:52:45-05:00","dateModified":"2015-10-21T13:04:06-05:00"},{"@type":"WebSite","@id":"https:\/\/www.poweradmin.com\/blog\/#website","url":"https:\/\/www.poweradmin.com\/blog\/","name":"Network Wrangler - Tech Blog","description":"IT Tips, tricks, tutorials and just interesting stuff for IT folks.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.poweradmin.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Network Wrangler - Tech Blog | IT Tips, tricks, tutorials and just interesting stuff for IT folks.","og:type":"article","og:title":"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog","og:description":"Do you remember HeartBleed from a few months back? There's another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as 'environment variables' and unfortunately, many programs","og:url":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/","article:published_time":"2014-09-26T14:52:45+00:00","article:modified_time":"2015-10-21T18:04:06+00:00","twitter:card":"summary","twitter:title":"Shellshock vulnerability \u2013 worse than HeartBleed :( | Network Wrangler - Tech Blog","twitter:description":"Do you remember HeartBleed from a few months back? There's another huge vulnerability that just came to light: Shellshock. And this one is much worse than HeartBleed :( Shellshock is based on a vulnerability in the Unix\/Linux bash command processor. Bash can be forced to execute commands stored as 'environment variables' and unfortunately, many programs"},"aioseo_meta_data":{"post_id":"2761","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2021-10-06 21:38:07","updated":"2025-10-01 23:05:26","focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.poweradmin.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/\" title=\"General IT\">General IT<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tShellshock vulnerability \u2013 worse than HeartBleed :(\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.poweradmin.com\/blog"},{"label":"General IT","link":"https:\/\/www.poweradmin.com\/blog\/category\/general-it\/"},{"label":"Shellshock vulnerability &#8211; worse than HeartBleed :(","link":"https:\/\/www.poweradmin.com\/blog\/shellshock-vulnerability-worse-than-heartbleed\/"}],"_links":{"self":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/2761","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/comments?post=2761"}],"version-history":[{"count":5,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/2761\/revisions"}],"predecessor-version":[{"id":4109,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/posts\/2761\/revisions\/4109"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media\/2765"}],"wp:attachment":[{"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/media?parent=2761"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/categories?post=2761"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.poweradmin.com\/blog\/wp-json\/wp\/v2\/tags?post=2761"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}