View Single Post
  #10  
Old 10-02-2014, 09:45 AM
audetd's Avatar
audetd audetd is offline
Member
 
Join Date: Jun 2010
Location: Montreal,QC. Canada
Posts: 7
audetd has 10 reputation points
Default

Quote:
Originally Posted by richa164 View Post
Run this test from linux shell.







env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

If you get

Vulnerable
This is a test

Well guess what !!


and now just checking my LAB's

Here is the result for the Communication Manager
dadmin@CM-LAB> env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test

Result for my DOM0
[admin@CM2-SPDom0 ~]$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test
[admin@CM2-SPDom0 ~]$

Result for my CDOM0
[admin@CM2-SPCdom ~]$ env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
vulnerable
this is a test
[admin@CM2-SPCdom ~]$


So that mean i am Vulnerable.

is there an offcial procedure from Avaya to find out.

Daniel
__________________
_____________________________
Daniel
Allstream Application Specialist

Last edited by audetd; 10-02-2014 at 12:27 PM.
Reply With Quote