Active Topics

 


Reply
Thread Tools
Posts: 92 | Thanked: 144 times | Joined on Apr 2014
#11
What would be the best way to patch?

wait for an update from community -
get a fix from another linux distribution -
apt-get remove bash?

I have no idea

Thanks
 
Estel's Avatar
Posts: 5,028 | Thanked: 8,613 times | Joined on Mar 2011
#12
It's quite funny, considering how some guy (our own, private version of poettering, if anyone would be in doubt who I'm referring to) tried to push bash into everyone's throat in Maemo Community, calling ash "messybox" and (sucessfuly) pretending busybox-power integration into CSSU.

Yes - if anyone haven't noticed, we still doesn't have busybox-power in CSSU - where it belongs - and need to install it via package that does binary file replacement... Mind this day and big middle finger to you, busybox haters.

/Estel
__________________
N900's aluminum backcover / body replacement
-
N900's HDMI-Out
-
Camera cover MOD
-
Measure battery's real capacity on-device
-
TrueCrypt 7.1 | ereswap | bnf
-
Hardware's mods research is costly. To support my work, please consider donating. Thank You!
 
jellyroll's Avatar
Posts: 435 | Thanked: 684 times | Joined on Apr 2012 @ Netherlands 020
#13
This is the output I had.
Attached Images
 
 

The Following 3 Users Say Thank You to jellyroll For This Useful Post:
Posts: 1,808 | Thanked: 4,272 times | Joined on Feb 2011 @ Germany
#14
Originally Posted by Estel View Post
It's quite funny, considering how some guy (our own, private version of poettering, if anyone would be in doubt who I'm referring to) tried to push bash into everyone's throat in Maemo Community, calling ash "messybox" and (sucessfuly) pretending busybox-power integration into CSSU.

Yes - if anyone haven't noticed, we still doesn't have busybox-power in CSSU - where it belongs - and need to install it via package that does binary file replacement... Mind this day and big middle finger to you, busybox haters.

/Estel
Don't know what your point is. Really. busybox is a MESSYBOX whose only advantage is only visible on severly limited systems -- not the N900.

IMHO bash or dash would be a much saner default. Plus the standard Linux coreutils instead of busybox clones.

And as for security: wait until someone starts looking at busybox. Then all those people having non-updatable appliances running web servers with crappy CGI's running as root (i.e. most routers or NASes) will regret it.

I can't wait to have a working debian on my N900. F*ck Maemo.
(I'm usually more polite, blame it on the Oktoberfest).
 

The Following 12 Users Say Thank You to reinob For This Useful Post:
Posts: 3,074 | Thanked: 12,960 times | Joined on Mar 2010 @ Sofia,Bulgaria
#15
reinob: don't feed the troll, please
__________________
Never fear. I is here.

720p video support on N900,SmartReflex on N900,Keyboard and mouse support on N900
Nothing is impossible - Stable thumb2 on n900

Community SSU developer
kernel-power developer and maintainer

 

The Following 7 Users Say Thank You to freemangordon For This Useful Post:
Posts: 254 | Thanked: 509 times | Joined on Nov 2011 @ Canada
#16
Probably the only exploit vector you would worry about would be DHCP. The other vectors are unlikely to affect your n900, such as cgi scripts, restricted ssh shells, etc...

Most of you are probably running the vulnerable version of openssl still which is probably a bigger risk than this.
 

The Following User Says Thank You to shawnjefferson For This Useful Post:
Posts: 81 | Thanked: 342 times | Joined on Jul 2012 @ Finland
#17
Originally Posted by Estel View Post
It's quite funny, considering how some guy (our own, private version of poettering,

/Estel
That's a weird comparison. People that are bashing (sic) Poettering for not following the so called Unix philosophy, now finally got their own pure Unix philosophy vulnerability in bash ah, well sorry for off-topic...
 

The Following User Says Thank You to jukk For This Useful Post:
Posts: 1,808 | Thanked: 4,272 times | Joined on Feb 2011 @ Germany
#18
Originally Posted by freemangordon View Post
reinob: don't feed the troll, please
Sorry. Didn't/don't consider either the message or the messenger as a troll.

The question of busybox vs busybox-power vs GNU is still IMHO a very valid point of discussion. Some day Maemo might actually boot/work with bash as /bin/sh. I think I should work on that. But then again, give me debian or slackware and I'll dump Maemo on the spot
 

The Following 4 Users Say Thank You to reinob For This Useful Post:
Estel's Avatar
Posts: 5,028 | Thanked: 8,613 times | Joined on Mar 2011
#19
Originally Posted by reinob View Post
Don't know what your point is.
My point is that in Maemo, we're still stuck with busybox as /bin/sh, so suggesting (or considering as only one viable possibility) to half-bake a replace by installing bash, instead of putting updated (including security updates) busybox to CSSU, is a big bulls**t.

Especially, that busybox is prime example of core system package that can't be distributed in extras in sane way (the only possibility is via binary file replacement, and you could distribute whole CSSU this way... Except, that it's just plain wrong), yet it's not included in CSSU for bulls**t reasons.

Suggestions to use BASH instead were all too common during busybox-power in CSSU discussion, effectively creating TWO possible attack surfaces, instead of one. Of course bash fanatics were absolutely sure that we won't create 2nd attack surface, as bash is awesome, magic, and 100% secure - which was proven wrong, and such assumption was wrong by design (no matter how secure your software is, it's still 2nd surface for attack). Not to mention being quite unrelated and demagogic (as it's hardly argument against updating our default /bin/sh).
---

Anyway, there is a side effect to this thread, too - suddenly, I lost big portion of respect for some people, that suddenly are able to only use derivatives of "troll" in place of discussion with arguments (and even gain "thanks" for it) - and I bet that it have more to do with pan-maemo's politic, than topic at hand. Well, there is old saying about spending too much time with someone and gaining his traits - I guess some people sticked to joerg on IRC for too long. Pity, perhaps, but well, not the end of the world and s**t happens... Enough OT.

/Estel
__________________
N900's aluminum backcover / body replacement
-
N900's HDMI-Out
-
Camera cover MOD
-
Measure battery's real capacity on-device
-
TrueCrypt 7.1 | ereswap | bnf
-
Hardware's mods research is costly. To support my work, please consider donating. Thank You!
 

The Following 3 Users Say Thank You to Estel For This Useful Post:
Posts: 2,076 | Thanked: 3,268 times | Joined on Feb 2011
#20
Sorry, but have to disagree. Seems like you're fighting your personal war thanks to shellshock. Imagine the opposite, vuln in busybox, practically all routers in the world exposed (and N900/non-CMdroids). Someone from bash proponents in CSSU comes in and states: "You see Estel, you're a dum...."
Bash was chosen for its features because this is full linux distro, not embedded system. We can afford running full blown (pun unintended) and featured linux distro with the latest and greatest (gplv3 even), try compiling/packaging some stuff on device and poor-featuredness of busybox tar will jump right at you. Yeah, go ahead and relink gtar and then...
 

The Following 11 Users Say Thank You to szopin For This Useful Post:
Reply

Tags
maemo 5, shellshock


 
Forum Jump


All times are GMT. The time now is 01:51.