{"id":669,"date":"2014-09-27T06:38:33","date_gmt":"2014-09-27T11:38:33","guid":{"rendered":"http:\/\/www.latindevelopers.com\/ivancp\/?p=669"},"modified":"2014-10-03T08:25:22","modified_gmt":"2014-10-03T13:25:22","slug":"actualizar-bash-para-evitar-ataques-shellshock","status":"publish","type":"post","link":"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/","title":{"rendered":"Actualizar bash para evitar ataques Shellshock"},"content":{"rendered":"<p>Cuando vi el titular dije: \u00abDebe tratarse de IE o algo con Windows&#8230;\u00bb pero cuando le\u00ed el contenido: WTF!! bash metido en esto? no puede ser!!<\/p>\n<p>A\u00fan no hay una soluci\u00f3n precisa que resuelva el problema pero por lo pronto debemos actualizar bash \u00abrait nau\u00bb. Para saber si tu sistema es vulnerable puedes ejecutar los siguientes comandos en consola:<\/p>\n<p><em>Comando 1:<\/em><\/p>\n<pre lang=\"bash\">env x='() { :;}; echo vulnerable' bash -c \"echo this is a test\"<\/pre>\n<p>Si el comando muestra `vulnerable` entonces tu sistema lo es.<\/p>\n<p><em>Comando 2:<\/em><\/p>\n<pre lang=\"bash\">env x='() { :;}; echo vulnerable' bash -c \"echo this is a test\"<\/pre>\n<p>Si el comando muestra una fecha, sigues siendo vulnerable.<\/p>\n<p><em>Comando 3:<\/em><\/p>\n<pre lang=\"bash\">env -i X=' () { }; echo hello' bash -c 'date'<\/pre>\n<p>Si el comando anterior muestra `hello` sigues siendo vulnerable.<\/p>\n<h2>Como actualizar bash?<\/h2>\n<p><strong>En Ubuntu\/Debian<\/strong>: (solo para versiones LTS)<\/p>\n<pre lang=\"bash\">sudo apt-get update && sudo apt-get install --only-upgrade bash<\/pre>\n<p><strong>En Centos\/Redhat\/Fedora<\/strong>:<\/p>\n<pre>sudo yum update bash<\/pre>\n<p>&nbsp;<\/p>\n<p>Esto hasta que publiquen una soluci\u00f3n definitiva, ser\u00eda buena idea realizar esas actualizaciones a diario hasta que la alerta roja desaparezca.<\/p>\n<p>&nbsp;<\/p>\n<p>Tomado de: <a href=\"https:\/\/shellshocker.net\/\" target=\"_new\">shellshocker<\/a><\/p>\n<div class=\"sharedaddy sd-sharing-enabled\"><div class=\"robots-nocontent sd-block sd-social sd-social-icon-text sd-sharing\"><h3 class=\"sd-title\">Compartelo:<\/h3><div class=\"sd-content\"><ul><li class=\"share-facebook\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-facebook-669\" class=\"share-facebook sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=facebook\" target=\"_blank\" title=\"Haz clic para compartir en Facebook\"><span>Facebook<\/span><\/a><\/li><li class=\"share-twitter\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-twitter-669\" class=\"share-twitter sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=twitter\" target=\"_blank\" title=\"Haz clic para compartir en Twitter\"><span>Twitter<\/span><\/a><\/li><li><a href=\"#\" class=\"sharing-anchor sd-button share-more\"><span>M\u00e1s<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><div class=\"sharing-hidden\"><div class=\"inner\" style=\"display: none;\"><ul><li class=\"share-email\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-email sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=email\" target=\"_blank\" title=\"Haz clic para enviar por correo electr\u00f3nico a un amigo\"><span>Correo electr\u00f3nico<\/span><\/a><\/li><li class=\"share-print\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-print sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/\" target=\"_blank\" title=\"Haz clic para imprimir\"><span>Imprimir<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-linkedin\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-linkedin-669\" class=\"share-linkedin sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=linkedin\" target=\"_blank\" title=\"Haz clic para compartir en LinkedIn\"><span>LinkedIn<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Cuando vi el titular dije: \u00abDebe tratarse de IE o algo con Windows&#8230;\u00bb pero cuando le\u00ed el contenido: WTF!! bash metido en esto? no puede ser!! A\u00fan no hay una soluci\u00f3n precisa que resuelva el problema pero por lo pronto &hellip; <a href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/\">Sigue leyendo <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n<div class=\"sharedaddy sd-sharing-enabled\"><div class=\"robots-nocontent sd-block sd-social sd-social-icon-text sd-sharing\"><h3 class=\"sd-title\">Compartelo:<\/h3><div class=\"sd-content\"><ul><li class=\"share-facebook\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-facebook-669\" class=\"share-facebook sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=facebook\" target=\"_blank\" title=\"Haz clic para compartir en Facebook\"><span>Facebook<\/span><\/a><\/li><li class=\"share-twitter\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-twitter-669\" class=\"share-twitter sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=twitter\" target=\"_blank\" title=\"Haz clic para compartir en Twitter\"><span>Twitter<\/span><\/a><\/li><li><a href=\"#\" class=\"sharing-anchor sd-button share-more\"><span>M\u00e1s<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><div class=\"sharing-hidden\"><div class=\"inner\" style=\"display: none;\"><ul><li class=\"share-email\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-email sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=email\" target=\"_blank\" title=\"Haz clic para enviar por correo electr\u00f3nico a un amigo\"><span>Correo electr\u00f3nico<\/span><\/a><\/li><li class=\"share-print\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-print sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/\" target=\"_blank\" title=\"Haz clic para imprimir\"><span>Imprimir<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-linkedin\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-linkedin-669\" class=\"share-linkedin sd-button share-icon\" href=\"https:\/\/www.latindevelopers.com\/ivancp\/2014\/09\/actualizar-bash-para-evitar-ataques-shellshock\/?share=linkedin\" target=\"_blank\" title=\"Haz clic para compartir en LinkedIn\"><span>LinkedIn<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><\/div><\/div><\/div><\/div><\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":""},"categories":[22],"tags":[52,43,17],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1tEO5-aN","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/posts\/669"}],"collection":[{"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/comments?post=669"}],"version-history":[{"count":3,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/posts\/669\/revisions"}],"predecessor-version":[{"id":674,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/posts\/669\/revisions\/674"}],"wp:attachment":[{"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/media?parent=669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/categories?post=669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.latindevelopers.com\/ivancp\/wp-json\/wp\/v2\/tags?post=669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}