Hackers Exploit Bash 'Shellshock' Bug With Worms in Early Attacks

Advertisement
By Reuters | Updated: 26 September 2014 18:51 IST
Hackers have begun exploiting the newly identified "Shellshock" computer bug, using fast-moving worm viruses to scan for vulnerable systems and then infect them, researchers warned on Thursday.

"Shellshock" is the first major Internet threat to emerge since the discovery in April of "Heartbleed," which affected encryption software used in about two-thirds of all web servers, along with hundreds of technology products.

The latest bug has been compared to "Heartbleed" partly because the software at the heart of the "Shellshock" bug, known as Bash, is also widely used in web servers and other types of computer equipment.

According to security experts, "Shellshock" is unlikely to affect as many systems as "Heartbleed" because not all computers running Bash can be exploited. Still, they said the new bug has the potential to wreak more havoc because it enables hackers to gain complete control of an infected machine, which lets them destroy data, shut down networks or launch attacks on websites.

Advertisement

(Also see: Everything You Need to Know About the Bash Bug)

The "Heartbleed" bug only allowed hackers to steal data.

Advertisement

The industry is rushing to determine which systems can be remotely compromised by hackers, but there are currently no estimates on the number of vulnerable systems.

Amazon.com Inc and Google Inc have released bulletins to advise web services customers how to protect themselves from the new cyber threat. A Google spokesman said the company is releasing software patches to fix the bug.

Advertisement

(Also see: Google Project Zero to Tackle Security Threats 'Across the Internet')

"We don't actually know how widespread this is. This is probably one of the most difficult-to-measure bugs that has come along in years," said Dan Kaminsky, a well-known expert on Internet threats.

Advertisement

For an attack to be successful, a targeted system must be accessible via the Internet and also running a second vulnerable set of code besides Bash, experts said.

"There is a lot of speculation out there as to what is vulnerable, but we just don't have the answers," said Marc Maiffret, chief technology officer of cyber-security firm BeyondTrust. "This is going to unfold over the coming weeks and months."

Attacks on devices
Joe Hancock, a cyber-security expert with insurer AEGIS in London, said in a statement that he is concerned about the potential for attacks on home broadband routers and controllers used to manage critical infrastructure facilities.

"In some areas this will be a challenge to fix, as many embedded devices are not designed with regular updates in mind and will never be able to be patched," Hancock said.

HD Moore, chief research officer with security software maker Rapid7, said it could take weeks or even months to determine what impact the bug will have.

"At this point we don't know what we don't know, but we do expect to see additional exploit vectors surface as vendors and researchers start the assessment process for their products and services," Moore said in an email. "We are likely to see compromises as a result of this issue for years to come."

Linux makers released patches to protect against attacks on Wednesday, though security researchers uncovered flaws in those updates, prompting No. 1 Linux maker Red Hat Inc to advise customers that the patch was "incomplete."

"That's a problem. It's been a little over 24 hours and we're still in the same boat," said Mat Gangwer, lead security consultant at Rook Security. "People are kind of freaking out. Rightfully so."

Worms
Russian security software maker Kaspersky Lab reported that a computer worm has begun infecting computers by exploiting "Shellshock."

The malicious software can take control of an infected machine, launch denial-of-service attacks to disrupt websites, and also scan for other vulnerable devices, including routers, said Kaspersky researcher David Jacoby.

He said he did not know who was behind the attacks and could not name any victims.

Jaime Blasco, labs director at AlienVault, said he had uncovered the same piece of malware, as well as a second worm seeking to exploit "Shellshock," which was designed for launching denial of service attacks.

"Heartbleed" is a bug in an open-source encryption software called OpenSSL. The bug put the data of millions of people at risk, as OpenSSL is used in about two-thirds of all websites. It also forced dozens of technology companies to issue security patches for hundreds of products that use OpenSSL.

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  2. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, 50-Megapixel Cameras
  3. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  4. OnePlus 15 India Launch Teased; Key Features Revealed Ahead of Launch
  5. iQOO Pad 5e Launched Alongside iQOO Watch GT 2 and iQOO TWS 5
  6. Redmi K90 Pro Max Key Features Revealed Ahead of Launch on October 23
  7. BSNL Samman Plan For Senior Citizens Announced at This Price
  8. DeepSeek-OCR Could Change How AI Reads Text From Images
  1. Baai Tujhyapayi OTT Release Date Revealed: Know Everything About Streaming, Plot, Cast, and More
  2. OnePlus 15 Launch in India Teased via Microsite; Company Reveals Key Features Ahead of China Debut
  3. BSNL Samman Plan Announced For New Senior Citizen Users: Price, Benefits
  4. Daksha: The Deadly Conspiracy Is Streaming Now: Know All About This Mohan Babu, Lakshmi Manchu Starrer
  5. Vivo Led Market as Smartphone Shipments in India Rose 3 Percent YoY in Q3 2025: Omdia
  6. DeepSeek-OCR Open-Source AI Model Changes How AI Models Read and Process Plain Text
  7. Vivo X300 Pro, Realme GT 8 Pro and Poco Pad M1 Listed on TDRA Site, Could Launch Soon
  8. Poco F8 Ultra Listing on NBTC Certification Website Hints at Imminent Launch
  9. Diwali Blackout: How the AWS Outage Crippled Major Apps Across the World
  10. WhatsApp Blocks AI Firms From Offering Chatbot Access via WhatsApp Business API
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.