A new vulnerability, known as “Shellshock”, was recently discovered within Bash. This security hole needs to be patched immediately to avoid potential exploits of your Linux server. Our Fully Managed cPanel customers have already had this patch applied since yesterday. An additional patch will likely be required to completely resolve “Shellshock” but that additional patch is not yet available. Once it is, we will apply it for our fully managed customers immediately and provide an update to our self-managed customers on the steps they need to take.

In the interest of getting to the point quickly of how to best fix the issue, we will dive right into how you can test your server for the vulnerability and patch it as best as can be done for the time being. If you want more information on the vulnerability itself here are a few articles with more information.

https://www.cnet.com/news/bigger-than-heartbleed-bash-bug-could-leave-it-systems-shellshocked/
https://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html?m=1
https://money.cnn.com/2014/09/24/technology/security/bash-bug/index.html

Test:

Test for the vulnerability by running the following command at shell:

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

If the output of the above command looks similar to the following:

vulnerable
this is a test
 
then your system is vulnerable.
 

Update Bash:

If you’re using CentOS 5/6/7, run the following command:

yum clean all
yum update bash

If bash doesn’t get updated, check /etc/yum.repos.d/CentOS-Base.repo and ensure it is default and not Hivelocity Mirrors (not updated, working on resolution).

Manual Build of Bash

For Cent4 or Debian Squeeze or older versions of software you may need to compile bash from source. Use the following command script:

The script below does the following:

  • Downloads bash
  • Downloads latest patches for bash
  • Extracts bash
  • Applies the patches to the source code
  • Builds and installs bash into /bin/bash
mkdir /src
cd /src
wget https://ftp.gnu.org/gnu/bash/bash-4.3.tar.gz
for i in $(seq -f "%03g" 0 25); do wget https://ftp.gnu.org/gnu/bash/bash-4.3-patches/bash43-$i; done
tar zxvf bash-4.3.tar.gz
cd bash-4.3
for i in $(seq -f "%03g" 0 25);do patch -p0 < ../bash43-$i; done;
./configure --prefix=/ && make && make install
 

Additional information and updates:

National Vulnerability Database 

Please note: The original patch (shown above) was thought to have fixed the issue CVE-2014-6271 but is now known to be incomplete. An attacker can provide specially-crafted environment variables containing arbitrary commands that will be executed on vulnerable systems under certain conditions. However, according to Red Hat, customers should upgrade to the version of Bash which contains the fix for CVE-2014-6271 (which was done yesterday for managed clients), and not wait for the new, yet to be released, patch which fixes CVE-2014-7169. CVE-2014-7169 is a less severe issue and patches for it are being worked on at the moment.

To summarize, CVE-2014-6271 does fix the initial low access complexity exploit. But it was incomplete and thus, a new exploit, assigned CVE-2014-7169 is out and that is currently being patched and will be available through repos shortly. This is a high access complexity exploit so it’s not as serious or widespread as the initial exploit.

 

Need More Personalized Help?

If you have any further issues, questions, or would like some assistance checking on this or anything else, please reach out to us from your my.hivelocity.net account -> Support and provide your server credentials within the encrypted field for the best possible security and support.

If you are unable to reach your my.hivelocity.net account or if you are on the go, please reach out from your valid my.hivelocity.net account email to us here at: [email protected]. We are also available to you through our phone and live chat system 24/7/365.

 

Additional Links:

Looking for more information on CentOS, Red Hat, or CloudLinux? Search our Knowledge Base!  

In need of more great content? Interested in cPanel, Private Cloud, or Edge Computing? Check out our recent posts for more news, guides, and industry insights!

Leave a Comment

Your email address will not be published. Required fields are marked *

Related Articles

Hivelocity News

Is Hivelocity’s TPA2 Your Next Data Center?

Over the last six months, one of the country’s biggest power companies as well as one of its largest cable providers have both reached out asking to utilize footage of our Hivelocity TPA2 data center for upcoming commercials. While we’re not at liberty yet to reveal which companies we’ve been …

Continue read
Hivelocity News

Proxmox VE Now Available with All Instant Deploy Servers

With a blend of KVM hypervisor technology and Linux Containers (LXC), Proxmox is the virtualization tool which can revolutionize your development environment. Now available as a default option with all Hivelocity Instant Deployment Dedicated Server purchases, scaling and maintaining your virtual infrastructure has never been easier. “In the past,” says …

Continue read
Hivelocity News

The Importance of World-Class Support

When it comes to providing the ideal hosting experience there are many approaches. Whether it’s affordability, customization options, bleeding-edge tech, a powerhouse network, or in-house systems that set you apart from the competition, every provider has a different roadmap to creating the “perfect” hosting solution. One crucial feature which is …

Continue read

Rapid Restore

Backup your entire server’s data every night and have access to 5 days of rolling restore points.  Restore your server’s data, OS and configuration any time you need it.

Our Rapid Restore service saves the day during accidental data loss, hardware failures and virus contraction. Simply pick your recovery point and restore the data from that day. 

DDoS Protection

While our competitors may advertise DDoS protection, most often, they are merely implementing easily evaded router rules or simply black-holing targeted servers. They consider this “DDoS protecting their network.” However, neither of these solutions should give comfort to any online business. Should your site be attacked, chances are likely both of these options will end with your server being taken offline. At Hivelocity, we take the responsibility of keeping your servers online very seriously. For this reason, we offer two very serious forms of DDoS protection.

FREE

Every solution we provide includes our Filtering Edge of Network System (FENS). FENS is a series of proprietary systems that proactively monitors and protects the entire Hivelocity Network from most common Denial of Service (DOS) and Distributed Denial of Service (DDoS) attacks.

$15/MONTH PER SERVER

For an extra fee, you can enhance your server’s protection further with the addition of our Server Defense System. Our Server Defense System sits in front of your server, inspecting inbound data and looking for malicious traffic. The moment an attack is detected, it instantly begins scrubbing each data packet. Hivelocity’s Server Defense System delivers business continuity even in the face of massive and complex attacks.

Our Server Defense System is like adding an alarm and armed guard to your business, alerting you to and destroying anything attempting to jump that fence. Our Server Defense System utilizes internally developed proprietary systems in addition to Corero’s Threat Defense Smartwalls for data packet scrubbing. Each of our data centers is a scrubbing center with Corero Smartwalls on-premise, allowing us to provide on-prem zero-lag data scrubbing.

SSL Certificates

The security of your online commerce and protecting your customers’ data is as important to us as it is to you. When your customers see the green bar, they will know their connection to you is protected. We offer single domain, multi-domain, and wild-card certificates.

We offer industry leading 128-bit encryption certificates, allowing you to conduct e-commerce with complete security. Inspire confidence in your customers by displaying any number of seals and indicators certifying that your site is secure.

Load Balancing

Adding this service to two servers with identical content will allow you to distribute your load evenly across your hardware. Don’t lose business because you couldn’t handle the demand. Load balance and handle your biggest resource spikes with ease.

Firewalls

Stop attacks, prevent unauthorized access, and achieve regulatory compliance. Our Juniper hardware firewalls offload the work so your server never has to consume resources protecting itself from malicious traffic. A single firewall can be used to protect multiple servers.

Cloud Storage

Cloud storage offers users redundancy and easy accessibility, ensuring your data remains secure and readily available. Scale to as much as you need for only a 20¢/GB.

Cloud Storage is distributed and replicated across many servers, protecting your data from hardware failure. Highly scalable, it can handle thousands of client connections via TCP/IP. Connect to your virtual drive with SFTP, FTP, and SSHMount and in the future NFS and AFP. Cloud Storage is based on a stackable design which is upgradeable up to 2TB per instance.