ShellShock: Do I need to be worried about this on OS X Mavericks?

I would err on the side of caution and wipe any server that you see odd behavior on that was exposed to the public internet in general without a logging firewall and/or some sort of tripwire or security scan set up to compare what changed since installation.

I think one of my OS X servers was compromised for the first time ever during this bash scripting vulnerability window. The time it would take me to search for a root kit is far longer than the time it took me to make one last backup and then wipe it from an external drive and start over.

In my case, I had a new user named A Lo created as a standard user. Pretty odd and very un-subtle of someone that manages to gain control of a server with a fixed IP address.

Basically, the more sophisticated black hat that has compromised your computer - the less likely you will notice it so from a reliability standpoint - if you notice instability it's likely cause the people that have compromised your server are inept or sloppy and will cause you to eventually have to reinstall.


Just to be clear, any server that's hidden behind a router with NAT is far less vulnerable than a server running live services 24/7 with a real, static IPv4 and no firewall whatsoever. People that just run OS X should have no concerns at all unless they have other reasons to think they are compromised.