---
title: SHELLSHOCK - [CVE-2014-6271]
description: SHELLSHOCK - [CVE-2014-6271]
image: https://blog.aujas.com/hs-fs/file-4112377908-gif/blog-files/clip_image002.gif
---

[![Aujas Logo-1](https://blog.aujas.com/hs-fs/hubfs/Aujas%20Logo-1.webp?width=951&name=Aujas%20Logo-1.webp "Aujas Logo-1")](https://www.aujas.com/)

- Services 
    - [Identity and Access Management](https://www.aujas.com/robotics-iam-identity-access-management-services) 
          - [Identity Governance Fast Track](https://www.aujas.com/iam-identity-governance-fast-track)
          - [Privileged Identity Management Fast Track](https://www.aujas.com/privileged-identity-management)
          - [Cloud Single Sign-on Fast Track](https://www.aujas.com/cloud-sso)
          - [Robotics Driven IAM](https://www.aujas.com/robotics-iam-services)
          - [Risk Aware IAM](https://www.aujas.com/risk-aware-iam)
          - [Consumer IAM](https://www.aujas.com/consumer-identity-and-access-management)
    - [Cybersecurity Advisory Services](https://www.aujas.com/cybersecurity-advisory-services) 
          - [Cyber Risk Management](https://www.aujas.com/cyber-risk-management-services)
          - [Integrated Compliance Management](https://www.aujas.com/cybersecurity-compliance-services)
          - [GRC Technology Automation](https://www.aujas.com/grc-technology-automation-services)
          - [Third Party Risk Management](https://www.aujas.com/third-party-risk-management)
          - [Privacy and Data Protection](https://www.aujas.com/data-privacy-data-protection-services)
    - [Security Verification](https://www.aujas.com/security-verification-services) 
          - [On-Demand Security Assessment](https://www.aujas.com/on-demand-security-testing-and-services)
          - [Breach & Attack Simulation](https://www.aujas.com/automated-continuous-attack-simulation)
          - [IoT Security Assessment](https://www.aujas.com/internet-of-things-security-assessment)
          - [Red Teaming](https://www.aujas.com/red-teaming-services)
          - [Integrated Security Assurance Program](https://www.aujas.com/isap)
          - [DDoS Simulation](https://www.aujas.com/ddos-attack-simulation-services)
          - [DevSecOps](https://www.aujas.com/devsecops)
          - [API Security](https://www.aujas.com/api-security)
    - [Security Engineering](https://www.aujas.com/security-engineering-services) 
          - [Secure Software Development](https://www.aujas.com/secure-software-development)
          - [Ecosystem Engineering](https://www.aujas.com/ecosystem-engineering)
          - [Custom Security Development](https://www.aujas.com/custom-security-solution-development)
          - [Registered Device Management Platform](https://www.aujas.com/registered-device-management-platform)
    - [Managed Detection and Response](https://www.aujas.com/managed-detection-and-response-services) 
          - [Offensive Security Services](https://www.aujas.com/offensive-security-services)
          - [OT Security Services](https://www.aujas.com/ot-security-services)
          - [Microsoft Sentinel](https://www.aujas.com/sentinel)
          - [Threat Management](https://www.aujas.com/threat-management-service)
          - [SIEM & Security Monitoring](https://www.aujas.com/siem-security-monitoring)
          - [SecOps Orchestration](https://www.aujas.com/security-orchestration-automation-and-response)
          - [Google SecOps](https://www.aujas.com/googlesecops)
    - [Cloud Security](https://www.aujas.com/cloud-computing-security-services) 
          - [AWS Cloud Security Services](https://www.aujas.com/aws-cloud-security-services)
          - [Cloud Security Foundation](https://www.aujas.com/cloud-security-foundation)
          - [Cloud Risk Management](https://www.aujas.com/cloud-risk-management)
          - [Cloud Security Engineering](https://www.aujas.com/cloud-security-engineering)
- Products 
    - [PALM](https://www.aujas.com/platform-for-access-lifecycle-management)
    - [Saksham](https://saksham.aujas.com)
    - [CodeSign](https://codesign.aujas.com)
    - [Aadhaar Registered Device Manager](https://www.aujas.com/registered-device-management-platform)
- Company 
    - [About us](https://www.aujas.com/about-us) 
          - [Investor Relations](https://www.aujas.com/investor-relations)
    - [Team](https://www.aujas.com/team)
    - [Partnership](https://www.aujas.com/partnership)
    - [Contact us](https://www.aujas.com/contact-us)
- [Careers](https://www.aujas.com/cybersecurity-careers)
- Resources 
    - [Blog](https://blog.aujas.com)
    - [Collaterals](https://www.aujas.com/collaterals)
    - [Case Studies](https://www.aujas.com/case-study)
- [Contact Sales](https://www.aujas.com/contact-us)
- ![](https://blog.aujas.com/hubfs/Aujas%202020/blue-search.png)

![blue-search](https://blog.aujas.com/hubfs/Aujas%202020/blue-search.png "blue-search")

![Aujas Cybersecurity Logo 2024](https://blog.aujas.com/hubfs/Aujas%20Cybersecurity%20Logo%202024.webp "Aujas Cybersecurity Logo 2024")

- Services 
    - [Identity and Access Management](https://www.aujas.com/robotics-iam-identity-access-management-services) 
          - [Identity Governance Fast Track](https://www.aujas.com/iam-identity-governance-fast-track)
          - [Privileged Identity Management Fast Track](https://www.aujas.com/privileged-identity-management)
          - [Cloud Single Sign-on Fast Track](https://www.aujas.com/cloud-sso)
          - [Robotics Driven IAM](https://www.aujas.com/robotics-iam-services)
          - [Risk Aware IAM](https://www.aujas.com/risk-aware-iam)
          - [Consumer IAM](https://www.aujas.com/consumer-identity-and-access-management)
    - [Cybersecurity Advisory Services](https://www.aujas.com/cybersecurity-advisory-services) 
          - [Cyber Risk Management](https://www.aujas.com/cyber-risk-management-services)
          - [Integrated Compliance Management](https://www.aujas.com/cybersecurity-compliance-services)
          - [GRC Technology Automation](https://www.aujas.com/grc-technology-automation-services)
          - [Third Party Risk Management](https://www.aujas.com/third-party-risk-management)
          - [Privacy and Data Protection](https://www.aujas.com/data-privacy-data-protection-services)
    - [Security Verification](https://www.aujas.com/security-verification-services) 
          - [On-Demand Security Assessment](https://www.aujas.com/on-demand-security-testing-and-services)
          - [Breach & Attack Simulation](https://www.aujas.com/automated-continuous-attack-simulation)
          - [IoT Security Assessment](https://www.aujas.com/internet-of-things-security-assessment)
          - [Red Teaming](https://www.aujas.com/red-teaming-services)
          - [Integrated Security Assurance Program](https://www.aujas.com/isap)
          - [DDoS Simulation](https://www.aujas.com/ddos-attack-simulation-services)
          - [DevSecOps](https://www.aujas.com/devsecops)
          - [API Security](https://www.aujas.com/api-security)
    - [Security Engineering](https://www.aujas.com/security-engineering-services) 
          - [Secure Software Development](https://www.aujas.com/secure-software-development)
          - [Ecosystem Engineering](https://www.aujas.com/ecosystem-engineering)
          - [Custom Security Development](https://www.aujas.com/custom-security-solution-development)
          - [Registered Device Management Platform](https://www.aujas.com/registered-device-management-platform)
    - [Managed Detection and Response](https://www.aujas.com/managed-detection-and-response-services) 
          - [Offensive Security Services](https://www.aujas.com/offensive-security-services)
          - [OT Security Services](https://www.aujas.com/ot-security-services)
          - [Microsoft Sentinel](https://www.aujas.com/sentinel)
          - [Threat Management](https://www.aujas.com/threat-management-service)
          - [SIEM & Security Monitoring](https://www.aujas.com/siem-security-monitoring)
          - [SecOps Orchestration](https://www.aujas.com/security-orchestration-automation-and-response)
          - [Google SecOps](https://www.aujas.com/googlesecops)
    - [Cloud Security](https://www.aujas.com/cloud-computing-security-services) 
          - [AWS Cloud Security Services](https://www.aujas.com/aws-cloud-security-services)
          - [Cloud Security Foundation](https://www.aujas.com/cloud-security-foundation)
          - [Cloud Risk Management](https://www.aujas.com/cloud-risk-management)
          - [Cloud Security Engineering](https://www.aujas.com/cloud-security-engineering)
- Products 
    - [PALM](https://www.aujas.com/platform-for-access-lifecycle-management)
    - [Saksham](https://saksham.aujas.com)
    - [CodeSign](https://codesign.aujas.com)
    - [Aadhaar Registered Device Manager](https://www.aujas.com/registered-device-management-platform)
- Company 
    - [About us](https://www.aujas.com/about-us) 
          - [Investor Relations](https://www.aujas.com/investor-relations)
    - [Team](https://www.aujas.com/team)
    - [Partnership](https://www.aujas.com/partnership)
    - [Contact us](https://www.aujas.com/contact-us)
- [Careers](https://www.aujas.com/cybersecurity-careers)
- Resources 
    - [Blog](https://blog.aujas.com)
    - [Collaterals](https://www.aujas.com/collaterals)
    - [Case Studies](https://www.aujas.com/case-study)
- [Contact Sales](https://www.aujas.com/contact-us)
- ![](https://blog.aujas.com/hubfs/Aujas%202020/blue-search.png)

![](https://blog.aujas.com/hubfs/Aujas%202020/close.png)

 

 

# SHELLSHOCK - \[CVE-2014-6271\]

- ![Tom Thomas](https://app.hubspot.com/settings/avatar/e41f6ff1ce36a4adb2ac1b537c6e4645)[Tom Thomas](https://blog.aujas.com/author/tom-thomas)
- Oct 6, 2014
- [Article](https://blog.aujas.com/topic/article)

SHARE

<https://twitter.com/intent/tweet?url=https://blog.aujas.com/2014/10/06/shellshock-part-1/>

# Introduction

Shellshock is a fatal bug in found in the popular Bourne- Again Shell or Bash. This bug was publically disclosed on 24th Sept 2014 by security researcher Stephane Chazelas. This bug had been affecting all the versions of Bash thus making it one of the most fatal security bugs in the recent times.

But, what is a shell in the first place? The shell (also known as the command shell) is by far one of the most important software on a \*nix based system (including linux). At minimum, it takes commands from the users, finds out where they are installed and executes it.

There are a plethora of shells available for Linux, ranging from the nimble Almquist Shell all the way to the behemoth that is ZSH. But, by far, the most common and widely used shell is the Bourne-Again Shell (Bash), which was based on the original Bourne shell of Unix.

Aside from the functionality of executing commands given by the user, Bash (as well as other shells) can also read said commands from a file and execute them. These files, called shell scripts are a fundamental building block of starting, functioning and maintenance of a Linux system.

These scripts need not just be a sequential list of commands to be executed in order. A Bash script is essentially a programming language on its own, supporting features like variables, loops and functions. A function is defined starting with () {}. The part within the curly braces { } is considered to be the part of the function.

**Example:**

```

  function () {echo hello world}<br>
  VAR=() {echo hello world}
```

Another important feature in bash are environment variables. Environment variables are global variables that are generally used to provide a context to the program like, username, home folder location and temporary file. These variables provide information about the environment and affect the way the processes behave on the system.

When a process is created, it inherits a duplicate of all the environment variables from the shell. As an alternate, it is also possible to modify these values that are passed to the child process. The \`env\` command can be used to do that.

The child process can also be another Bash shell. And in that case, we can pass functions as environment variable too. When that happens, the child bash shell, converts the function definition to an internal representation. There is a vulnerability in the implementation of this feature in Bash.

Bash allows us to export shell variables as well as functions to other bash instances(Child process). Thus the child process.

The critical vulnerability that was discovered in Bash was that if there was a code/command appended after the function definition and if this function was exported into another child bash process, - This appended code/commands were being executed in the child bash instance.

**Structure of a declared function:**

```
$   SomeFunc=() { some legitimate action ; } ; Code1;
```

Here *‘SomeFunc’*  is the declared function and *‘Code1’*(and the remaining commands/codes mentioned thereafter) is a /are malicious code that has been appended after the function declaration.

**Example:**

```
$ XFunc= () { echo  &ldquo; WYSIWYG&rdquo; ;};  top;
```

Ideally Bash should not execute anything after the function declaration (i.e XFunc in our case). But if the above code in our example is imported by another bash instance (child) the command ***top*** would get executed and print the list of running processes.

To demonstrate this lets declare a function and export it to another bash instance.

**Case 1: This is how functions would be declared and exported in the Uthopian World .**

```

  &gt;$  env XFunc=&rsquo;() {  :/tmp/;};&rsquo; bash –c &ldquo;echo Uthopian World&rdquo;
```

![clip_image002](https://blog.aujas.com/hs-fs/file-4112377908-gif/blog-files/clip_image002.gif)

Here the environment function XFunc is defined and imported by another instance of bash and the result are as expected.

**Case 2: This is how functions would be declared and exported in the real world.**

```
&gt;$ XFunc=&rsquo;() { :/tmp/;}; top&rsquo; bash  –c &ldquo;echo Uthopian World&rdquo;
```

![clip_image004](https://blog.aujas.com/hs-fs/file-4112377918-gif/blog-files/clip_image004.gif)

Now here XFunc is defined and after the definition the command “top” is defined. In Linux ‘top’ is a commandline utility that displays a listing of the most CPU-intensive tasks on the system, and can provide an interactive interface for manipulating processes. So here the moment the function is exported the appended command (top) also runs.

**Case 3: Guess what happens when you do something like this …???**

```
&gt;$   XFunc=&rsquo;() { :/tmp/;}; bash;&rsquo; bash –c &ldquo;echo Uthopian World&rdquo;
```

![clip_image006](https://blog.aujas.com/hs-fs/file-4112377938-gif/blog-files/clip_image006.gif)

**How To Identify & Fix the ShellShock Bug :**

1. Enter
   
   ```
   <strong><em>env x='() { :;}; echo vulnerable' bash -c &quot;echo  Testing for ShellShock&rdquo; </em></strong>
   ```
   
    in the bash.   
    If you receive the following output, your system is vulnerable.
   
   ```
   <strong><em>&gt; vulnerable</em></strong>
   ```
   
   ```
   <strong><em>&gt; Testing for ShellShock</em></strong>
   ```
2. To Fix this bug update Bash to the latest version.  
   For Debian based Machines (eg. Debian, Ubuntu, Kali)
   
   ```
   $&gt; <strong><em>sudo apt-get update  &amp;&amp; -y apt-get install bash.</em></strong>
   ```
   
   For Red-Hat based systems (eg. CentOS,Fedora,Red-Hat)
   
   ```
   $&gt;<strong><em> sudo yum update bash</em></strong>
   ```
3. Restart Bash after it has been successfully updated and now re-enter
   
   ```
   <strong><em>env x='() { :;}; echo vulnerable'  bash -c &quot;echo Testing for ShellShock&rdquo;  </em></strong>
   ```
   
   in the terminal to check if the patch has been installed successfully.   
    You are safe if the output reads as :
   
   
   ```
   <strong><em>&gt; Testing for ShellShock</em></strong>
   ```
   
   ## References:
   
     1. [http://seclists.org/oss-sec/2014/q3/650](http://seclists.org/oss-sec/2014/q3/650)
     2. [http://garage4hackers.com/entry.php?b=3087](http://garage4hackers.com/entry.php?b=3087)
     3. [http://en.wikipedia.org/wiki/Shellshock\_(software\_bug)](http://en.wikipedia.org/wiki/Shellshock_(software_bug))
     4. [https://access.redhat.com/articles/1200223](https://access.redhat.com/articles/1200223)
   
    
   
   ## Authors
   
   [Jovin Lobo](mailto:jovin.lobo@aujas.com) , [Rishi Narang](mailto:rishi.narang@aujas.com); [Naresh T A](mailto:naresh.ta@aujas.com)

![Footer-Logo](https://blog.aujas.com/hubfs/Aujas%202019/Footer/Footer-Logo.png "Footer-Logo")

## Reach Us

[+1 201 389 9011](tel:+1%20201%20389%209011)

## Write To Us

**Sales:** [contact@aujas.com](mailto:contact@aujas.com)  
**Jobs:** [careers@aujas.com](mailto:careers@aujas.com)  
**HR Queries:** [HRopsteam@aujas.com](mailto:hropsteam@aujas.com)

 

- [1](https://www.linkedin.com/company/aujas-cybersecurity)
- [2](https://twitter.com/AujasIRM)
- [3](https://www.facebook.com/AujasCybersec/?ref=py_c)
- [4](https://www.youtube.com/@AujasCybersecurity)

## [Identity and Access Management](https://www.aujas.com/identity-access-management-services)

- [Identity Governance Fast Track](https://www.aujas.com/iam-identity-governance-fast-track)
- [PIM Fast Track](https://www.aujas.com/privileged-identity-management)
- [Cloud Single Sign-on Fast Track](https://www.aujas.com/cloud-sso)
- [Robotics Driven IAM](https://www.aujas.com/robotics-iam-services)
- [Risk Aware IAM](https://www.aujas.com/risk-aware-iam)
- [Consumer IAM](https://www.aujas.com/consumer-identity-and-access-management)

## [Cybersecurity Advisory Services](https://www.aujas.com/cybersecurity-advisory-services)

- [Cyber Risk Management](https://www.aujas.com/cyber-risk-management-services)
- [Integrated Compliance Management](https://www.aujas.com/cybersecurity-compliance-services)
- [GRC Automation](https://www.aujas.com/grc-technology-automation-service)
- [Third Party Risk Management](https://www.aujas.com/third-party-risk-management-old)
- [Privacy and Data Protection](https://www.aujas.com/data-privacy-data-protection-services)

## Company

- [About us](https://www.aujas.com/about-us)
- [Careers](https://www.aujas.com/cybersecurity-careers)
- [Contact us](https://www.aujas.com/contact-us)

## Resources

- [Blog](https://blog.aujas.com)
- [Collaterals](https://www.aujas.com/collaterals)
- [Case Study](https://www.aujas.com/case-study)

## [Security Verification](https://www.aujas.com/security-verification-services)

- [Threat Simulation](https://www.aujas.com/threat-simulations)
- [loT Security](https://www.aujas.com/internet-of-things-security-assessment)
- [Penetration Testing](https://www.aujas.com/crest-certified-penetration-testing-services)

## [Security Engineering](https://www.aujas.com/security-engineering-services)

- [Secure Development](https://www.aujas.com/secure-software-development)
- [Ecosystem Engineering](https://www.aujas.com/ecosystem-engineering)
- [CodeSign Platform](https://codesign.aujas.com/)
- [Custom Security Development](https://www.aujas.com/custom-security-solution-development)

## [Managed Detection and Response](https://www.aujas.com/managed-threat-detection-and-response-services)

- [Threat Management](https://www.aujas.com/threat-management)
- [SIEM & Security Monitoring](https://www.aujas.com/siem-security-monitoring)
- [Automated & Continous Attack Simulation](https://www.aujas.com/automated-continuous-attack-simulation)
- [SecOps Orchestration](https://www.aujas.com/security-orchestration-automation-and-response)
- [Google SecOps](https://www.aujas.com/googlesecops)

## [Identity and Access Management](https://www.aujas.com/identity-access-management-services)

- [Identity Governance Fast Track](https://www.aujas.com/iam-identity-governance-fast-track)
- [PIM Fast Track](https://www.aujas.com/privileged-identity-management)
- [Cloud Single Sign-on Fast Track](https://www.aujas.com/cloud-sso)
- [Robotics Driven IAM](https://www.aujas.com/robotics-iam-services)
- [Risk Aware IAM](https://www.aujas.com/risk-aware-iam)
- [Consumer IAM](https://www.aujas.com/consumer-identity-and-access-management)

## [Cybersecurity Advisory Services](https://www.aujas.com/cybersecurity-advisory-services)

- [Cyber Risk Management](https://www.aujas.com/cyber-risk-management-services)
- [Integrated Compliance Management](https://www.aujas.com/cybersecurity-compliance-services)
- [GRC Automation](https://www.aujas.com/grc-technology-automation-service)
- [Third Party Risk Management](https://www.aujas.com/third-party-risk-management-old)
- [Privacy and Data Protection](https://www.aujas.com/data-privacy-data-protection-services)

## [Security Verification](https://www.aujas.com/security-verification-services)

- [Threat Simulation](https://www.aujas.com/threat-simulations)
- [loT Security](https://www.aujas.com/internet-of-things-security-assessment)
- [Penetration Testing](https://www.aujas.com/crest-certified-penetration-testing-services)

## [Security Engineering](https://www.aujas.com/security-engineering-services)

- [Secure Development](https://www.aujas.com/secure-software-development)
- [Ecosystem Engineering](https://www.aujas.com/ecosystem-engineering)
- [CodeSign Platform](https://codesign.aujas.com/)
- [Custom Security Development](https://www.aujas.com/custom-security-solution-development)

## [Managed Threat Detection and Response](https://www.aujas.com/managed-threat-detection-and-response-services)

- [Threat Management](https://www.aujas.com/threat-management)
- [SIEM & Security Monitoring](https://www.aujas.com/siem-security-monitoring)
- [Automated & Continous Attack Simulation](https://www.aujas.com/automated-continuous-attack-simulation)
- [SecOps Orchestration](https://www.aujas.com/security-orchestration-automation-and-response)
- [Google SecOps](https://www.aujas.com/googlesecops)

## Company

- [About us](https://www.aujas.com/about-us)
- [Careers](https://www.aujas.com/cybersecurity-careers)
- [Contact us](https://www.aujas.com/contact-us)

## Resources

- [Blog](https://blog.aujas.com)
- [Collaterals](https://www.aujas.com/collaterals)
- [Case Study](https://www.aujas.com/case-study)

Copyrights © 2025 All Rights Reserved by Aujas.

- [Terms of Use](https://www.aujas.com/terms-of-service)
- [Privacy Policy](https://www.aujas.com/privacy-policy)
- [Cookie Policy](https://www.aujas.com/cookie-policy)

![](https://px.ads.linkedin.com/collect/?pid=656027&fmt=gif) ![websights](https://ws.zoominfo.com/pixel/62839c658f43f50012ae3b9a)