Shellshock


Recommended Posts

Unraid is not meant to be directly exposed to the internet anyway. It should have a private ip, and there should be no ports forwarded to unraids address in your router, unless you know exactly what you are doing, in which case you can patch bash yourself.

 

This makes the assumption that all the people that will ever connect to the network that unRAID is on will have good intentions, which is not a good thing to assume.

Link to comment

Unraid is not meant to be directly exposed to the internet anyway. It should have a private ip, and there should be no ports forwarded to unraids address in your router, unless you know exactly what you are doing, in which case you can patch bash yourself.

 

This makes the assumption that all the people that will ever connect to the network that unRAID is on will have good intentions, which is not a good thing to assume.

Unraid is not hardened, at all. It shouldn't be on a publicly accessible network segment, period. If you can't trust the people in your household not to hack your server, you have other issues besides technology.

 

Now, if you are a networking professional, and have experience with evaluating network security and such, it's a different matter, and as I said, you can do all the necessary and prudent things to allow public access to specific parts of an unraid box.

 

If you are asking how to patch bash, you shouldn't be putting your unraid box in an environment where it could be hacked because you don't have the knowledge to evaluate the other risks. I'm not trying to be a jerk, and I'm sorry if you take it that way, I'm just trying to keep people's data safe.

Link to comment

This bug has been around for a very long time. As far as I've read.

The vulnerability affects versions 1.14 through 4.3 of GNU Bash.

 

The issue is that script kiddies will attempt to use it as a method to gain entry.

All devices that have used linux, bash and accept user input are candidates.

 

While later versions of slackware have pre-compiled patched bash packages, It seems the unRAID slackware version does not.

Maybe someone knows of a location for a patched & compiled slackware bash package.

Link to comment

Unraid is not meant to be directly exposed to the internet anyway. It should have a private ip, and there should be no ports forwarded to unraids address in your router, unless you know exactly what you are doing, in which case you can patch bash yourself.

 

This makes the assumption that all the people that will ever connect to the network that unRAID is on will have good intentions, which is not a good thing to assume.

 

I'm less worried about people trying to connect at all. If you have a device that is exposed to the Internet (i.e. router) that gets infected, it could automatically propagate with a worm. This is why it is important to patch.

Link to comment

Unraid is not meant to be directly exposed to the internet anyway. It should have a private ip, and there should be no ports forwarded to unraids address in your router, unless you know exactly what you are doing, in which case you can patch bash yourself.

 

This makes the assumption that all the people that will ever connect to the network that unRAID is on will have good intentions, which is not a good thing to assume.

 

I'm less worried about people trying to connect at all. If you have a device that is exposed to the Internet (i.e. router) that gets infected, it could automatically propagate with a worm. This is why it is important to patch.

 

 

That's my concern also.

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.