BR100 Increased By (0.99%)
BR30 Increased By (0.38%)
KSE100 Increased By (1.06%)
KSE30 Increased By (1.14%)
BECO 5.41 Increased By ▲ 0.09 (1.69%)
BML 56.50 Increased By ▲ 1.41 (2.56%)
BOP 35.08 Increased By ▲ 0.04 (0.11%)
CNERGY 8.17 Increased By ▲ 0.08 (0.99%)
DCL 11.41 Increased By ▲ 0.05 (0.44%)
FCCL 57.30 Increased By ▲ 1.11 (1.98%)
FCSC 5.00 Decreased By ▼ -0.01 (-0.2%)
FFL 17.84 Increased By ▲ 0.16 (0.9%)
FNEL 1.25 Increased By ▲ 0.01 (0.81%)
HUMNL 11.15 Increased By ▲ 0.22 (2.01%)
KEL 8.51 Decreased By ▼ -0.06 (-0.7%)
KOSM 6.78 Increased By ▲ 0.29 (4.47%)
MLCF 106.98 Increased By ▲ 0.47 (0.44%)
NBP 198.96 Decreased By ▼ -0.80 (-0.4%)
PACE 11.12 Increased By ▲ 0.10 (0.91%)
PAEL 45.49 Increased By ▲ 0.49 (1.09%)
PIAHCLA 31.43 Increased By ▲ 2.86 (10.01%)
PIBTL 19.07 Increased By ▲ 0.80 (4.38%)
PPL 243.40 Decreased By ▼ -1.09 (-0.45%)
PRL 35.74 Increased By ▲ 0.80 (2.29%)
PTC 65.75 Decreased By ▼ -0.07 (-0.11%)
SEARL 94.51 Increased By ▲ 0.46 (0.49%)
SSGC 32.09 Increased By ▲ 1.26 (4.09%)
TELE 8.86 Increased By ▲ 0.16 (1.84%)
THCCL 65.94 Increased By ▲ 0.95 (1.46%)
TPLP 10.70 Increased By ▲ 0.44 (4.29%)
TREET 25.14 Increased By ▲ 0.27 (1.09%)
TRG 63.57 Increased By ▲ 0.21 (0.33%)
WAVES 10.71 Increased By ▲ 0.06 (0.56%)
WTL 1.25 Increased By ▲ 0.01 (0.81%)
Print Print edition: 2014-09-29

'Bash' computer bug could hit millions

Published September 29, 2014 Updated September 29, 2014 12:00am

The US government and technology experts warned Thursday of a vulnerability in some computer-operating systems, including Apple's Mac OS, which could allow widespread and serious attacks by hackers. The flaw affects "Unix-based operating systems" powered by Linux and Apple's Mac OS, said the warning from the US Computer Emergency Readiness Team (CERT), part of the Department of Homeland Security.
CERT said that if hackers exploit this they could take control of a PC: "Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on an affected system."
The agency said a patch was available for the flaw, which is described by security researchers as "Bash" or "Shellshock." Some said the security hole would be more damaging than the "Heartbleed" bug which affected millions of computers world-wide earlier this year.
Bigger than Heartbleed
"This is going to be much bigger than Heartbleed," said Rahul Kashyap, chief security architect at Bromium Labs, a California-based security firm.
Kashyap said the Bash bug could affect millions of devices, from Web servers to Macintosh computers to webcams and other devices which connect to the Internet using open-source operating systems based on Linux.
Because the software is so prevalent, "it means attackers can get into your house, your home routers," Kashyap told AFP.
"They could deface a lot of websites on the fly. A lot of damage can be done, and it's a very simple code."
Even though no exploit of the flaw was seen in the first hours since the vulnerability was made public, Kashyap said he expected "a huge impact in the next few days."
Independent security consultant Graham Cluley agreed that if hackers create a worm that exploits the flaw, "it would, without question, make the Bash bug a more serious threat than the Heartbleed OpenSSL bug that impacted many systems earlier this year." While Heartbleed allowed unauthorised parties to spy on computers, "the Shellshock Bash bug allows attackers to hijack computers, and use them for their own purposes," Cluley said in a blog post.
'Staggering' potential
Gavin Millard at the security firm Tenable also expressed concern on the extent of the flaw.
"The potential for attackers utilising Shellshock is huge," he said.
"With millions of Unix and Linux servers being vulnerable and running web services that hackers can connect to, the attack surface is staggering," he wrote in a blog post.
Johannes Ullrich at the SANS Internet Storm Center said the patch for the flaw "is incomplete" and that people using affected systems "should try to implement additional measures" which could include beefed-up firewalls or other software changes.
Eugene Kaspersky, who heads the Kaspersky Lab security group, said in a tweet that the flaw is serious.
The Bash bug "is BAD, expect a lot of exploits and hacked websites to be disclosed in the coming weeks," he wrote.
Researcher Robert Graham of Errata Security said that unlike Heartbleed, this bug "has been around for a long, long time. That means there are lots of old devices on the network vulnerable to this bug."
The computer security firm Symantec said it "regards this vulnerability as critical, since Bash is widely used in Linux and Unix operating systems running on Internet-connected computers, such as Web servers."

Copyright Agence France-Presse, 2014

Comments

Comments are closed for this article.