Re: Re: Bash exploit in the wild
By: Deuce to Psi-Jack on Fri Sep 26 2014 16:59:20
De> The initial patch doesn't completely close the hole... just a heads-up.
What I've been wondering, and I'm addressing this to anybody, I guess, though
I pointed it as a reply to you because I'm thinking you may well know better
than a lot of others, is what the ':' in the script does? I mean, I know that
it's integral to the vulnerability, but I can't place how the ':' is
interpreted. Every other character I understand. My suspicion is that the ':'
is interpreted as its usage as a tertiary operator, but that doesn't seem to
totally add up, either. I'm trying to understand what the logic in the
punctuation is so that I can understand where the security hole lies in bash,
just to increase my general understanding, but I haven't found it laid out well
anywhere, yet.
---
■ Synchronet ■ Tinfoil Tetrahedron BBS telnet or ssh -p 2222 to tinfoil.synchro
.net
|