oss-sec mailing list archives

Re: Thoughts on Shellshock and beyond


From: "David A. Wheeler" <dwheeler () dwheeler com>
Date: Tue, 07 Oct 2014 22:47:35 -0400 (EDT)

All:

Given the feedback here and elsewhere, I've tried to distill how to detect or prevent shellshock-like things 
ahead-of-time.  My current try is here:

   http://www.dwheeler.com/essays/shellshock.html#detect-or-prevent

More ideas and refinements would be welcome.  I've also made a number of refinements (e.g., the timeline has more info, 
where the name came from has been identified, etc.).

Thanks again!

--- David A.Wheeler


Current thread: