ddos.org
域名年龄: 20年4个月23天HTTP/1.1 302 Found 语言环境:PHP/5.5.1 目标网址:http://www.blyon.com/tag/ddos/ 类型:text/html 文件大小:0 访问时间:2016年01月29日 05:02:32 服务器:web/1.1 HTTP/1.1 200 OK 语言环境:PHP/5.3.27 X-Pingback: http://www.blyon.com/xmlrpc.php 类型:text/html; charset=UTF-8 Transfer-Encoding: chunked 访问时间:2016年01月29日 05:02:32 服务器:web/1.1 代理服务器:1.1 sjc1-10 网站编码:UTF-8
Recent PostsThis Bash bug will be a mess!What happens when National Geographic steals your art?Why Defense.Net and F5: The Hybrid CloudBlue Apron: I’m not having fun.I finally updated opte.orgArchivesSeptember 2014May 2014April 2014February 2014January 2014September 2013April 2013August 2012March 2011December 2010November 2010October 2010August 2010July 2010May 2010April 2010January 2010December 2009August 2009July 2009June 2009TagsAkamaiAmazonAnonymousAppleAsteriskAT&TCable TVComcastCybersecurityCyber SecurityCyberwarDDoSDefense.NetDigital NativeEuropean Cyber ArmyEV InnovationsFacebookFireWireHybrid TechnologiesInternetLi-Ion MotorsNewsNewspapersNew York TimesPHPProlexicRBNRetweetSecuritySIPSoftwareSoftware BugsSRVStreamingtechnologyTerroristsTweetsTwitterURI DialingUser HabitsUS GovernmentVideoLanVLCWeb ResearchWikiLeaksSearch for:Posts Tagged ‘DDoS’« Older EntriesThis Bash bug will be a mess!Thursday, September 25th, 2014Bash (GNU Bourne-Again SHell) is a common command line interface (shell) for newer styles of UNIX-like operating systems. It’s favored by Linux distributions and OS X because it is a little more user friendly than other shells. It has also had a 22 year old bug that allows an attacker possibly remotely execute arbitrary commands on the victim’s machine, typically as root.Read the full CVE-2014-6271 CERT report.What does this mean for us OS X users? Well, not much, unless you run DHCP or Internet Connection Sharing (which uses DHCP) which could allow remote command execution.What does this mean for your Linux box? If you have any idiotic applications that allow remote input, such as a form or setup script that passes unchecked variables to Bash, you’re in big trouble.Implications are all over the place: Huge DDoS botnets powered by massively connected machines. People’s data being compromised everywhere. Scanners executing a simple command such as rm -rf / which will simply nuke the entire server’s disk… It’s going to be messy for people that have followed poor development and security practices with their web applications, stats, log analysis software, or any application that passes external input to bash.This doesn’t impact BSD (by default), which for the most part has shunned Bash since it’s beginning favoring a different shell called cshell (csh). It also probably not heavily impact services like Facebook and Google, because they shouldn’t be allowing shell calls from web applications and their user access should be limited to trusted applications and users anyway.WAFs (Web Application Firewalls) are a huge help in this situation. Rather than wait for all of your services to be patched you can deploy a rule or have your WAF service deploy a rule that can block this attack vector. I consider this a huge advantage when combatting new exploits.Anyway, it’s time to get patching and expect the Internet to be a little messy for the next f
© 2010 - 2020 网站综合信息查询 同IP网站查询 相关类似网站查询 网站备案查询网站地图 最新查询 最近更新 优秀网站 热门网站 全部网站 同IP查询 备案查询
2025-08-30 00:45, Process in 0.0035 second.