Hi Ronni

Accepted, but my grizzle is that you "have to be in the know" to go to the 
Apple Support website.  (Daniel gave the links.) "Ordinary" Mac users probably 
rely on software update notifications delivered to their computer.  WAMUG 
members are in a privileged position! And more so when you glean the extra 
informative articles.

The Unix update was an aside as I grappled with iTunes and iOS 8 on my iPad. 
Definitely leaving the iPhone update until things become more settled!

Cheers
Alan

Sent from my iPad

> On 2 Oct 2014, at 3:41 pm, Ronni Brown <[email protected]> wrote:
> 
> Hi Alan,
> 
> This has not been a low priority for Apple. You can and have been able to 
> download the patch from Apple Support at:
> 
> <http://support.apple.com/kb/DL1769?viewlocale=en_US&locale=en_US>
> ------
> Shellshock Vulnerability: What Mac OS X Users Need to Know
> What exposes your Mac to Shellshock
> 
> There are two routes to exposing this vulnerability to a remote attack on a 
> Mac:
> 
> Route 1
> 
> Go into System Preferences > Sharing and turn on Remote Login
> In the same location, turn on All Users
> Go into System Preferences > Users & Groups and make sure Guest Access is 
> enabled                                                                       
>                                                                               
>                               Your system is now vulnerable. If you don’t 
> enable guest access your system is still vulnerable if the attacker knows or 
> is able to guess your username and password.                                  
>        But as this connection is secured, they can’t get that from packet 
> sniffing. And enabling a guest shell on a box is probably not the most secure 
> thing to do anyway.
> Route 2
> 
> This route requires OS X Server, an old (Lion or earlier) version of OS X, or 
> for the user to install Apache/PHP/some other scripting environment.
> 
> Enable Apache and have it running
> Enable Apache to run scripts or execute extensions
> Have one of those scripts or extensions vulnerable to malicious attacking 
> (being able to inject something into the script that gets executed)
> The attacker can then insert the variables into the script or extension that 
> gets run under the Bash shell, then the injection gets into the Shellshock 
> vulnerability, and voila—machine compromised. This one, however, requires 
> exploiting two holes. First, in the script running on Apache, and then in 
> turn using that compromised script to send something to the Bash shell.
> 
> What this means 
> 
> As you can see, these are both edge cases. And both routes probably require a 
> level of technical expertise that the person configuring their account as 
> such can patch the exploit fairly simply.
> 
> Also note that for route 1, enabling a Bash shell with Guest access for 
> remote login most likely opens up your system to many other possible attacks. 
> The difference Shellshock provides is access to root privileges, in other 
> words full machine access to said Guest user.
> 
> The bigger issue is all the devices with embedded Unix, where telnet 
> (unsecured) access is enabled, and no login is required. These typically are 
> “The Internet of Things” (IoT) devices. Even if they require an administrator 
> password other then “Admin” to get change settings, Shellshock may now give 
> the attacker root to do whatever they want on the device.
> 
> Prior to Apple patching this hole this is what you could have done do to stay 
> protected
> 
> A few simple steps to make sure you’re not exposed:
> 
> Don’t enable Guest Access AND at the same time enable All Users for Remote 
> Login.
> Don’t run a Web server on your personal machine.
> Have a strong password on your Account.
> Keep Gatekeeper turned “On.”
> Only install or run signed Apps from trusted sources.
> 
> Cheers,
> Ronni
> 
> 17" MacBook Pro 2.3GHz Quad-Core i7 “Thunderbolt"
> 2.3GHz / 8GB / 750GB @ 7200rpm HD
> 
> OS X 10.9.5 Mavericks
> Windows 7 Ultimate (under sufferance)
> 
>> On 2 Oct 2014, at 2:04 pm, Alan Smith <[email protected]> wrote:
>> 
>> Obviously a low priority with Apple (I hope they're working overtime on 
>> fixing iOS 8).
>> 
>> The UNIX bash update is NOT available from Software Updates.  What is a 
>> reasonable time to wait for this “recommended” update to filter down to 
>> ordinary users?
>> 
>> Cheers
>> Alan
>> (iMacs with Mavericks 10.9.5)
>> 
>> 
>>> On 30 Sep 2014, at 10:57 pm, Daniel Kerr <[email protected]> wrote:
>>> 
>>> For those worried about the UNIX bash "issues", you can download updates 
>>> for your OS now,…
>>> http://support.apple.com/downloads/
>>> 
>>> Just choose your OS and can download the update. (if it isn't showing in 
>>> Software Update already)
>>> 
>>> More info here - 
>>> http://www.macrumors.com/2014/09/29/apple-os-x-mavericks-bash-update/
>>> 
>>> Kind regards
>>> Daniel
>>> 
>>> Sent from my iPhone 6
>>> 
>>> ---
>>> Daniel Kerr
>>> MacWizardry
>>> 
>>> Phone: 0414 795 960
>>> Email: <daniel AT macwizardry.com.au>
>>> Web:   <http://www.macwizardry.com.au>
>>> 
>>> 
>>> **For everything Apple**
>>> NOTE: Any information provided in this email may be my personal opinion and 
>>> as such should be taken accordingly, and may not be the views of 
>>> MacWizardry. Any information provided does not offer or warrant any form of 
>>> warranty or accept liability. It would be appreciated that if any 
>>> information in this email is to be disseminated, distributed or copied, 
>>> that permission by the author be requested. 
> 
> -- The WA Macintosh User Group Mailing List --
> Archives - <http://www.wamug.org.au/mailinglist/archives.shtml>
> Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.shtml>
> Settings & Unsubscribe - 
> <http://lists.wamug.org.au/listinfo/wamug.org.au-wamug>
-- The WA Macintosh User Group Mailing List --
Archives - <http://www.wamug.org.au/mailinglist/archives.shtml>
Guidelines - <http://www.wamug.org.au/mailinglist/guidelines.shtml>
Settings & Unsubscribe - <http://lists.wamug.org.au/listinfo/wamug.org.au-wamug>