I know they dont, I didn't say they do. But my non up-to-date Ubuntu server wasn't vulnerable when I checked about a month after shellshock vulnerable went public.
Have you considered you may be using a software stack that is not (obviously) vulnerable? Not every software is vulnerable by default on all URLs, just the ones that wind up calling out to bash in a specific way.
If I am not wrong the vulnerability test on shellshocker.net tests bash directly. Either way I could very well be wrong and I might have missed something.
No, you would need a vulnerable service running on the VPS in order to exploit it.
Yes that's the one I was talking about. Ran the test before and after updating. It was the same (negative). I ran the same test on the relative up todate home computer (Ubuntu) and it was vulnerable on some of the tests. This IS weird.
The scary possibility is that someone hacked you, backdoored the server, and then patched the vulnerability to keep others out.
So somebody used shellshock to break in, then plugged the hole to prevent others from accessing the server, and is now using your server for... whatever?