ShellShock vulnerability: how to stay safe | myhrtoolkit

Published on September 30, 2014 by Kit Barker
    Data security
ShellShock vulnerability

A new software bug known as the “Bash Bug” or “Shellshock” has been identified, which allows attackers to gain control over targeted computers. The bug is present in a piece of computer software called Bash  that is typically found on computers running an operating system called Linux or Unix, of which there are many variations.

Generally, this operating system is used to power server computers, such as the ones that many of the world’s websites run on. Also impacted are all Apple Mac computers that run Apple’s operating system, OS X. Computers running Microsoft Windows are not impacted by this vulnerability directly, but could be at risk if web servers are compromised.

The ShellShock vulnerability and myhrtoolkit

Prior to the exposure of this vulnerability, myhrtoolkit already had a high level of security as access to our server, via FTP and SSH protocols, was locked down and limited by IP address. There is a theoretical risk that servers could be exploited simply by sending malformed requests to the server. However upon testing our servers were shown to be not vulnerable to this due to our previous hardening.

In response to ShellShock, our Linux provider, Red Hat have released a fully patched version of bash (the software that had the issue). This has been installed on all of our servers and tested as per Red Hat's instructions. As such, the servers running myhrtoolkit remain secure.

Related articles

Myhrtoolkit moving infrastructure to Google Cloud Platform

Information security and HR: creating a security-conscious culture

Picture of Kit Barker

Written by Kit Barker

Kit is myhrtoolkit's Chief Technology Officer and a company director for myhrtoolkit who leads the technical team in developing the system. On our blog he shares specialist knowledge and tips around data security and company culture.

Free Data Migration
free data migration
Unlimited Free Support
unlimited free support
3 month MOT
3 month MOT