Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Shellshock: What do you actually need to do to stay secure?
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • Biztech
  • Shellshock: What do you actually need to do to stay secure?

Shellshock: What do you actually need to do to stay secure?

fptechno • October 11, 2014, 11:35:58 IST
Whatsapp Facebook Twitter

Since Shellshock targets UNIX-based machines, organisations should harden their servers. This can be done by implementing a ’least privilege’ strategy and preventing unlimited root shell accesses.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Shellshock: What do you actually need to do to stay secure?

The Shellshock bug is the newest cyber threat to hit the internet and said to be a more serious vulnerability than Heartbleed. Shellshock has been lurking in the massively popular software package Bash, a command line interpreter, or shell, that provides a powerful, flexible way to run commands on a computer. A highly stealthy vulnerability, Shellshock has gone undetected in Bash for more than two decades.

Bash is a standard, free, tool for all UNIX-based operating systems and Apple’s OS X. One of the largest industries to rely on UNIX-based systems is the energy sector, who’s SCADA and industrial control systems are largely built on this technology. Additionally, it is widely used on simple Internet connected devices, meaning that not only can servers be compromised but also home routers, IP cameras, basically concerning, the Internet of Things.
[caption id=“attachment_93525” align=“alignleft” width=“300”] ![Representational image. Reuters](https://images.firstpost.com/wp-content/uploads/2014/08/CYBER-REUTERS-300x200.jpg) Representational image. Reuters[/caption]

STORY CONTINUES BELOW THIS AD

“Shellshock allows attackers to execute code remotely, leaving organisations susceptible to unauthorised processes or commands on target machines. Zero-day vulnerabilities like this are ideal entry points for a classic advanced persistent threat,” said Dan Dinnar, Vice President for Asia Pacific at CyberArk. “Once an attacker exploits a zero-day to bypass security defences, they look for ways to jump beyond the reach of the zero-day and that is almost always by exploiting privileged accounts. Organisations need to focus on securing and monitoring activity for these accounts to limit the scope and damage of a breach by cutting off an attacker’s ability to move laterally from an affected machine to others in the network. "

More from Biztech
Future Group - Reliance Retail Deal approved by CCI Future Group - Reliance Retail Deal approved by CCI RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market RBI ban on cryptocurrencies takes effect; prohibition could force investors to tap the black market

From a privileged account security perspective, CyberArk recommends:

1. Harden UNIX servers: Since Shellshock targets UNIX-based machines, organisations should harden their servers. This can be done by implementing a ’least privilege’ strategy and preventing unlimited root shell accesses. Organisations need to remove unnecessary root privileges, while tightly controlling or restricting shell capabilities when needed. This means that only authorised commands can be run, rather than those injected by an attack, such as through Shellshock.

2. Monitor privileged account behaviour: Exploited zero-day vulnerabilities most often lead to privileged credential theft as a way to move beyond the vulnerable machine. To identify this lateral movement, organisations should monitor account activity for irregular behaviour of privileged accounts.

Tags
Linux Unix bug Botnet vulnerability CyberArk Bash Shellshock
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV