CVE-2014-6271ãçºç«¯ã¨ãã bash ã®èå¼±æ§ããããã ShellShock ã£ã¦å¼ã°ãã¦ãã奴ãç°å¢å¤æ°ã«ä»è¾¼ãã ä»»æã®ã³ãã³ããå®è¡ã§ãã¦ãã¾ãã£ã¦ãã¨ãããCGI ã¨ã®çµã¿åãããåãæ²æ±°ããã¦ããã ãã®é sudo ã®è¨å®ã®åå¼·ããã¦ããã®ã§ããµã¨æ°ã«ãªã£ãã®ããsudoã®è¨å®ã§ç°å¢å¤æ°ãæã¡è¶ãã¦ä½¿ç¨ãããã¨ãã§ãã env_keep ã®è¨å®ãsudo 㧠root ã¨ãã¦bashãå®è¡ãããã°ãä»»æã®ã³ãã³ããç¹æ¨©ææ ¼ãã¦å®è¡ã§ãã¡ãããããï¼ ã¨ãããã®ã æ©é試ãã¦ã¿ãã æ®éã«å®è¡ãããã® $ export ORACLE_SID='() { :;}; echo Vulnerability !!!' $ cat /usr/local/bin/testcmd #!/bin/bash -x id printenv ORACLE_SID $ /usr/local/
{{#tags}}- {{label}}
{{/tags}}