BASH prompt security bug

General Discussion

BASH prompt security bug

Postby randap » Thu Sep 25, 2014 12:07 pm

Just seen this: http://www.bbc.co.uk/news/technology-29361794

It's a security bug found in BASH... I can't pretend I know or understand anything about this, but since my TiVo is "connected" I'm left wondering if we need to do something???
randap
Powering up...
Powering up...
 
Posts: 6
Joined: Mon Apr 18, 2011 7:37 pm

Re: BASH prompt security bug

Postby DX30 » Thu Sep 25, 2014 1:07 pm

I wouldn't panic about your TiVo. Unless you have taken steps to configure your router to allow you to access your TiVo from outside your home network (e.g. so you can remotely set recordings) it is unlikely to be vulnerable. And anyway at the end of the day what is on your TiVo that is a security risk? While personally I would be annoyed to lose some TV recordings I'd soon get over it.

I'd be more worried about the impact of Shellshock on commercial websites. These are a much juicier target for hackers with the potential for thousands of customers credit card details etc being at risk.
DX30
Valued Contributor
Valued Contributor
 
Posts: 645
Joined: Thu May 19, 2011 2:36 pm

Re: BASH prompt security bug

Postby gcobb » Sun Sep 28, 2014 12:05 am

I can confirm that the Tivo software does include a version of bash which is susceptible to this bug.

However, like DX30, I do not think it is anything to worry about. The bash problem requires some route to exploit it. The most common route is via a web server running what are known as "CGI scripts". I am not aware that anyone has ever made a CGI-capable web server available for Tivo, In fact, the only web server I am aware of for Tivo is Tivoweb -- but that uses TCL scripts instad of bash scripts, so it is not vulnerable to this bug.

Of course, I would always recommend being careful in allowing remote access to your Tivo from outside your home network. Not because of Shellshock but because none of the Tivo remote services have been designed (or seriously tested) for security.

And, just in case you are worried, the way data is downloaded from AltEPG does not provide a route to infect your Tivo either.
gcobb
AltEPG Team
AltEPG Team
 
Posts: 255
Joined: Sun Feb 20, 2011 8:36 pm


Return to General

Who is online

Users browsing this forum: No registered users and 10 guests

cron