Hi Alan, This has not been a low priority for Apple. You can and have been able to download the patch from Apple Support at:
<http://support.apple.com/kb/DL1769?viewlocale=en_US&locale=en_US> ------ Shellshock Vulnerability: What Mac OS X Users Need to Know What exposes your Mac to Shellshock There are two routes to exposing this vulnerability to a remote attack on a Mac: Route 1 Go into System Preferences > Sharing and turn on Remote Login In the same location, turn on All Users Go into System Preferences > Users & Groups and make sure Guest Access is enabled Your system is now vulnerable. If you don’t enable guest access your system is still vulnerable if the attacker knows or is able to guess your username and password. But as this connection is secured, they can’t get that from packet sniffing. And enabling a guest shell on a box is probably not the most secure thing to do anyway. Route 2 This route requires OS X Server, an old (Lion or earlier) version of OS X, or for the user to install Apache/PHP/some other scripting environment. Enable Apache and have it running Enable Apache to run scripts or execute extensions Have one of those scripts or extensions vulnerable to malicious attacking (being able to inject something into the script that gets executed) The attacker can then insert the variables into the script or extension that gets run under the Bash shell, then the injection gets into the Shellshock vulnerability, and voila—machine compromised. This one, however, requires exploiting two holes. First, in the script running on Apache, and then in turn using that compromised script to send something to the Bash shell. What this means As you can see, these are both edge cases. And both routes probably require a level of technical expertise that the person configuring their account as such can patch the exploit fairly simply. Also note that for route 1, enabling a Bash shell with Guest access for remote login most likely opens up your system to many other possible attacks. The difference Shellshock provides is access to root privileges, in other words full machine access to said Guest user. The bigger issue is all the devices with embedded Unix, where telnet (unsecured) access is enabled, and no login is required. These typically are “The Internet of Things” (IoT) devices. Even if they require an administrator password other then “Admin” to get change settings, Shellshock may now give the attacker root to do whatever they want on the device. Prior to Apple patching this hole this is what you could have done do to stay protected A few simple steps to make sure you’re not exposed: Don’t enable Guest Access AND at the same time enable All Users for Remote Login. Don’t run a Web server on your personal machine. Have a strong password on your Account. Keep Gatekeeper turned “On.” Only install or run signed Apps from trusted sources. Cheers, Ronni 17" MacBook Pro 2.3GHz Quad-Core i7 “Thunderbolt" 2.3GHz / 8GB / 750GB @ 7200rpm HD OS X 10.9.5 Mavericks Windows 7 Ultimate (under sufferance) On 2 Oct 2014, at 2:04 pm, Alan Smith <[email protected]> wrote: > Obviously a low priority with Apple (I hope they're working overtime on > fixing iOS 8). > > The UNIX bash update is NOT available from Software Updates. What is a > reasonable time to wait for this “recommended” update to filter down to > ordinary users? > > Cheers > Alan > (iMacs with Mavericks 10.9.5) > > > On 30 Sep 2014, at 10:57 pm, Daniel Kerr <[email protected]> wrote: > >> For those worried about the UNIX bash "issues", you can download updates for >> your OS now,… >> http://support.apple.com/downloads/ >> >> Just choose your OS and can download the update. (if it isn't showing in >> Software Update already) >> >> More info here - >> http://www.macrumors.com/2014/09/29/apple-os-x-mavericks-bash-update/ >> >> Kind regards >> Daniel >> >> Sent from my iPhone 6 >> >> --- >> Daniel Kerr >> MacWizardry >> >> Phone: 0414 795 960 >> Email: <daniel AT macwizardry.com.au> >> Web: <http://www.macwizardry.com.au> >> >> >> **For everything Apple** >> NOTE: Any information provided in this email may be my personal opinion and >> as such should be taken accordingly, and may not be the views of >> MacWizardry. Any information provided does not offer or warrant any form of >> warranty or accept liability. It would be appreciated that if any >> information in this email is to be disseminated, distributed or copied, that >> permission by the author be requested.
-- The WA Macintosh User Group Mailing List -- Archives - <http://www.wamug.org.au/mailinglist/archives.shtml> Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.shtml> Settings & Unsubscribe - <http://lists.wamug.org.au/listinfo/wamug.org.au-wamug>

