My Jailbroken iPad is vulnerable to the shellshock exploit.

Discussion in 'iPad Hacking' started by dragon499, Sep 25, 2014.

  1. dragon499

    dragon499
    Expand Collapse
    iPad Fan

    Joined:
    Aug 12, 2010
    Messages:
    284
    Thanks Received:
    11
    Not sure if this belongs in the hacking section - Mods, feel free to move this somewhere else more appropriate:

    On my iPad 4 Jailbroken on IOS 7.0.4, It appears that the system is vulnerable to the shellshock exploit. When SSHing into a terminal session, this command:

    env x='() { :;}; echo vulnerable' bash -c 'echo this is a test'

    Returns:

    vulnerable
    this is a test

    This command:

    env X="() { :;} ; echo vulnerable" /bin/sh -c "echo stuff"

    Returns:

    vulnerable
    stuff

    I've changed the root and mobile passwords for general security.

    My question is: Is this a vulnerability in theory only, or can some malicious program or process actually take advantage of this?

    Does being jailbroken make an iPad more vulnerable than stock iPads?

    Thanks

     
  2. willerz2

    willerz2
    Expand Collapse
    iPad Addict

    Joined:
    Feb 22, 2012
    Messages:
    1,341
    Thanks Received:
    255
    The only time you'll need to worry about ShellShock vuln is if you're using cracked/unsigned apps or packages, or using anything from developers that aren't vetted that may embed shell protocols. When you jailbreak your device and use Cydia packages and such, the packages already have root access as jailbreaking allows for root access so you're already "exposed". Assuming you're not using cracked/unsigned items, the only real threat would be if you're using a package that's actively using shell with bash, which in this age of jailbreaking, is next to none.

    EDIT:
    Here's what Saurik has to say. You may understand him better than the way I'm explaining it since I'm working off of other sources and am currently wired as hell from coffee brewed with Red Bull instead of water.
     
  3. twerppoet

    twerppoet
    Expand Collapse
    iPad Legend II

    Joined:
    Jan 8, 2011
    Messages:
    20,286
    Thanks Received:
    5,822
    Be careful. I'm pretty sure that was the formula for Splode! cola.
     

Share This Page



Search tags for this page

ios shellshock

,

is ipad 1 vulnerable

,

shellshock exploit

,

shellshock jailbreak ios

,

shellshock jailbroken