Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

Hack5190

macrumors 6502a
Original poster
Oct 21, 2015
531
311
(UTC-05:00) Cuba
Tonight I tested sh and bash on my Leopard install using the script from here (https://github.com/wreiske/shellshocker/blob/master/shellshock_test.sh).

Both were vulnerable, after some searching I was able to use the information from this posting (http://www.macissues.com/2014/09/25...x-the-shell-shock-bash-vulnerability-in-os-x/) to patch and compile updated versions of sh and bash.

If you wish to use the updated versions I compiled, they are available to download from here https://www.dropbox.com/s/h8ugiy5t53uwth1/shellshock.zip?dl=0

For connivence the script to test for shell shock vulnerability is included in my download.
 
  • Like
Reactions: G4fanboy

Hack5190

macrumors 6502a
Original poster
Oct 21, 2015
531
311
(UTC-05:00) Cuba
I created an Installer package that fixes this shortly after it first was discovered. I'll see if I can locate the original thread.

Here is the original thread: https://forums.macrumors.com/threads/the-bash-bug-and-ppc.1789601/

Thanks for the info and link, having only joined the PowerPC owners club (and this forum) in Nov of 2015 I missed your thread.

Truth is the primary reason I did this was to test my compiler install and for something to do last night while others in the house watched the Republican comedy show (aka debate).
 
Last edited:

Gamer9430

macrumors 68020
Apr 22, 2014
2,247
1,402
USA
Sorry if I'm a bit late to the party on this, but what exactly does is the vulnerability?
 

throAU

macrumors G3
Feb 13, 2012
8,822
6,987
Perth, Western Australia
If you're running 10.5 shellshock is the least of your concerns.

For example, there is a vulnerability in NSString (pretty sure un-patched in 10.5) which will basically potentially allow any application on your machine to be exploited.
 

Cox Orange

macrumors 68000
Jan 1, 2010
1,814
241
Here they say it will work under 10.4, too
http://resale.headgap.com/bobsmactips.html (hit cmd+f and type "bash problems" to find the part I am referring to)
Mind there they are linking to the version that ends with .27 while tenfourfox-blogspot has updated it to .30

Is Intel's installer using vs. .30 ?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.