Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Debian This forum is for the discussion of Debian Linux.


  Search this Thread
Old 09-26-2014, 03:14 AM   #16
Senior Member
Registered: Mar 2012
Posts: 1,783

Rep: Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592Reputation: 592

Originally Posted by charly78 View Post
If you run a webserver
I know this is just some guy making a point but he got my server (209.126.*.* notsureprivacy why I did that)
grep bash /var/log/apache2/access.log
209.126.*.* - - [24/Sep/2014:16:58:12 -0400] "GET / HTTP/1.0" 200 307 "() { :; }; ping -c 11 216.75.*.*" "shellshock-scan ("
209.126.*.* - - [24/Sep/2014:18:49:15 -0400] "GET / HTTP/1.0" 200 307 "() { :; }; ping -c 11 209.126.*.*" "shellshock-scan ("

grep "\(?\s*_*\s*\)?\s*{|cgi" /var/log/apache2/access.log

grep /bin /var/log/apache2/access.log - - [25/Sep/2014:04:14:19 -0400] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.0" 404 411 "-" "() { :;}; /bin/ping -c 1" - - [25/Sep/2014:17:42:32 -0400] "GET / HTTP/1.1" 200 288 "() { :; }; /bin/ping -c 1" "() { :; }; /bin/ping -c 1"
anyone good at filters for fail2ban maybe we can make a filter that helps keep folks at bay
You're giving 200 responses to those scans.
My (updated) servers are returning 403 to them.
Old 09-26-2014, 08:50 AM   #17
Senior Member
Registered: Sep 2003
Distribution: Debian Squeeze / Wheezy
Posts: 1,623

Rep: Reputation: 50
check & patch for "Shellshock"

We're using servers & self-made thin clients with Debian Squeeze.

Where can I download just a patch instead of apt-get upgrade?

Last edited by cccc; 09-26-2014 at 03:41 PM.
Old 09-26-2014, 11:09 AM   #18
Dutch Master
Senior Member
Registered: Dec 2005
Posts: 1,686

Rep: Reputation: 124Reputation: 124
You aren't really looking, aren't you?

OK, this once as it's important:
Old 09-26-2014, 01:41 PM   #19
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594Reputation: 3594
// Thread merged if necessary, renamed to include CVE numbers and popular name and stickied. Please keep the distribution-specific discussion here, else see Please let me know if you spot similar topic threads to merge.
Old 09-26-2014, 03:40 PM   #20
Senior Member
Registered: Sep 2003
Distribution: Debian Squeeze / Wheezy
Posts: 1,623

Rep: Reputation: 50
Originally Posted by akiuni View Post
Hello Charly78

I apologies for the link I gave you, it redirects to a french server and I'm not sure that you can access it from your location.
you should be able to download the patches from aptitude or apt-get but if it doesn't, you can download them directly from the debian repository :

using ftp client :
navigate to /debian/pool/main/b/bash/

localize and download the file you need : bash_4.1-3+deb6u2_amd64.deb should suite for you.

I've tried this patch on my Squeeze, but still vulnerable.
Old 09-26-2014, 11:12 PM   #21
Registered: Aug 2012
Location: Toronto,Canada
Posts: 73

Original Poster
Rep: Reputation: Disabled
I have patched all the versions and it is like this you have two ways the binary package pre made from your debian or type of debian distro or compile it from source.

I first test it in a console

env x='() { :;}; echo vulnerable' bash -c "echo testing this"
It should look like this if its patched

# env x='() { :;}; echo vulnerable' bash -c "echo testing this"
bash: warning: x: ignoring function definition attempt                                                                                                                                                   
bash: error importing function definition for `x'                                                                                                                                                        
testing this
Then I do the usual using super user account (root) or sudo depending on your version or type of Debian.
apt-get update ; apt-get install bash
if it updates you are covered for some of the major parts of the CVE-2014 numbers but will have to wait for the dust to settle before the latest patches like the 2 most recent patches that have been entered into today. You are done you can call it a day and you will pass and avoid most the kiddies on the net testing for openings for some fun.

if it tells you you are already uptodate then you need to find out what you are running

dpkg-query -l|grep bash
# dpkg-query -l|grep bash                                                                                                                                                                
ii  bash                                                      4.3-9.1                            amd64        GNU Bourne Again SHell
As you can see I have 4.3. Next you find a mirror that is not busy (main ones where impossible to get on today, busy)
and look for where they have the bash files

I used one from germany. You will find patches going as far back from today fixing the issues as far back as version 2

So just cd to your source directory (You can use a different dir if you want) then wget the version or the latest if you want (check for dependencies. Easiest is to get the code you already have running example if you have 3.2 go get version 3.2.
then you untar gzip it and change to that directory and go get the patches right into the directory and patch it!

cd /usr/src
tar zxvf bash-4.3.tar.gz
cd bash-4.3
for the above example if you have a different version get that version

here is example of me changing to the directory and patching it.

cd /usr/src/bash-4.3
for i in $(seq -f "%03g" 1 26); do
wget -nv$i
patch -p0 < bash43-$i
You will note I have 4.3 and you might change to a different directory with your version.
seq -f "%03g" 1 26
above you need to see how many patches are in there. at the time of writing this there are 26 patches and it starts at 1. if your using 3.2 there is 53 patches so you would change these number in the example above to
seq -f "%03g" 1 53
and of course the two parts where it is

and press enter

when you are done you should have a mess of patching , maybe even warnings like illegal names.

finally you need to compile and install this with this command.

./configure && make && make install
then you are left with a whole bunch of stuff for a bit on your screen. You may need to install some files if it seems to fail. when its done you can test this again first move the old to a old file and the new link

mv /bin/bash /bin/bash.old
ln -s /usr/local/bin/bash /bin/bash
then test the old and the new
env x='() { :;}; echo vulnerable' /bin/bash.old -c echo
env x='() { :;}; echo vulnerable' bash -c echo
i would rm (remove the old

rm /bin/bash.old
Then you good til the next patch comes out although you would need in my case to increase the 26 to a 27 or what ever if they added more patches. as of writing this you are uptodate of all the known issues ( well , if they find more then ...)

I hope that helps i did this in this order so many times yesterday!

Also its not perfect but theres a fail2ban filter now out that might help a little more if your watching your apache2 logs like some of us. just look through some of my posts or go to the fail2ban site I put it up in there

Last edited by charly78; 09-26-2014 at 11:17 PM. Reason: typos
Old 10-02-2014, 08:31 AM   #22
LQ Newbie
Registered: Oct 2014
Location: Italy
Distribution: debian
Posts: 3

Rep: Reputation: Disabled
Originally Posted by charly78 View Post
ok for debian 5 Lenny I had to compile I have done 3 servers that I did in 2008 and it seems to work here is what I did you may need to sub in the version of bash you are using or check the server for the right directory or files.

#first find out the version you have so you know what to get for the patches and source files
dpkg-query -l|grep bash
ii bash 4.1-3 The GNU Bourne Again SHell

#i am doing everything in the /usr/src dir
cd /usr/src
tar zxvf bash-4.1.tar.gz
cd bash-4.1

# download and apply all patches, including the latest one that patches CVE-2014-6271
#note if you are on say older version like 3.2 of bash I would use
#for i in $(seq -f "%03g" 1 52); do since 3.2 has patches up to 52
for i in $(seq -f "%03g" 0 12); do
wget -nv$i
patch -p0 < bash41-$i

# compile and install to /usr/local/bin/bash
./configure && make
make install

# point /bin/bash to the new binary
mv /bin/bash /bin/bash.old
ln -s /usr/local/bin/bash /bin/bash

# test by comparing the output of the following
env x='() { :;}; echo vulnerable' /bin/bash.old -c echo
env x='() { :;}; echo vulnerable' bash -c echo

#then get rid Delete the old one thats a problem
rm /bin/bash.old

I hope this helps othere folks
Based on my experience
ln -s /usr/local/bin/bash /bin/bash doesn't work. After a reboot I got "bash no such file" and was impossible logon to the server in single-user too.
Perhaphs better cp /usr/local/bin/bash /bin/bash


patch, security, shell shock, shellshock

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Bash "shellshock" CVE-2014-6271 CVE-2014-7169 - Apache2 Fail2ban Filter charly78 Linux - Security 12 10-25-2014 11:36 AM
Bash "shellshock" CVE-2014-6271 CVE-2014-7169 - rated 10 ! syg00 Linux - Security 81 10-15-2014 02:11 PM
LXer: Shellshock update: bash packages that resolve CVE-2014-6271 and CVE-2014-7169 available LXer Syndicated Linux News 1 09-26-2014 01:43 PM
Bash "shellshock" CVE-2014-6271 CVE-2014-7169 - legacy system patch help Diggy Linux - Security 3 09-26-2014 01:06 PM > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 06:39 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration