12 ms·
Don't copy paste from a website to a terminal
- Albright 11y agoThe problem is that there's a lot of software out there that expects you to install it this way - particularly by piping into sh or bash or the like. See also http://www.seancassidy.me/dont-pipe-to-your-shell.html http://www.seancassidy.me/dont-pipe-to-your-shell.html and http://output.chrissnell.com/post/69023793377/stop-piping-curl1-to-sh1 http://output.chrissnell.com/post/69023793377/stop-piping-cu... and https://www.chef.io/blog/2015/07/16/5-ways-to-deal-with-the-install-sh-curl-pipe-bash-problem/ https://www.chef.io/blog/2015/07/16/5-ways-to-deal-with-the-... . There was also a blog out there collecting instances of this, but I couldn't find it again after a couple searches. I had to hold my nose and paste some commands like this in order to reinstall Composer [1] and Drupal Console [2] earlier this week. Ugh, it feels so dirty, but it's often the first and/or the easiest, if not the only, way that software like this documents how it's to be installed. 1. https://getcomposer.org/doc/00-intro.md#globally https://getcomposer.org/doc/00-intro.md#globally 2. http://drupalconsole.com http://drupalconsole.com
- dublinben 11y agoNone of those commands are so long that you shouldn't just be retyping them by hand. It's obviously not an ideal way to install anything, but it's much safer than copy and pasting.
- cortesoft 11y agoor copy them to a text editor first?
- jeffdavis 11y agoIs that safe? (Legitimate question)
- keithgabryelski 11y agoone can target specific editors... for instance, if I know you are using VI I can create a series of characters that will escape out of insert mode and run a shell command (note: ^[ is ESC (ascii 27)) git status ^[ :!echo foo
- robotkilla 11y agoI ran into this for the first time just recently when installing ruby and was very surprised and hesitant to follow the instructions ( see here https://www.digitalocean.com/community/tutorials/how-to-install-ruby-on-rails-on-ubuntu-14-04-using-rvm https://www.digitalocean.com/community/tutorials/how-to-inst... ). Glad to see people speaking out against it.
- nosir33 11y agoOne example: http://curlpipesh.tumblr.com/ http://curlpipesh.tumblr.com/
- Albright 11y agoThat was the blog I was looking for. Thanks.
- coldtea 11y ago>The problem is that there's a lot of software out there that expects you to install it this way - particularly by piping into sh or bash or the like. The real problem is that this is nothing different than trusting a binary download -- which many more millions (billions) do.
- deleted 11y ago[deleted]
- syntheticnature 11y agoOr, for that matter, a source download. Or one you've hashed (how do you know the hash hasn't been tampered with?), a microprocessor (have you looked at the microcode? the masks), a circuit, etc. Turtles^H^H^H^H^H^H^HTrust all the way down. I'm not being entirely facetious, either, given the advice about disposing of electronics after visiting certain countries.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- geerlingguy 11y agoLuckily both can be installed almost as easily without the curl pipe hack... Not sure why so many projects want to reduce install steps from three to one with a shell script. I could understand if you have 90 steps (in which case I would recommend you figure out a better install process in general), but not for simple 'download something, move it to a path, run a command, and you're done'. See my roles for both of the packages you mentioned above on Ansible Galaxy for more info; I tend to avoid doing the curl pipes for sanity even more so than security. I want to know what I'm doing with my server when I'm installing packages or other software!
- jjuhl 11y agoIf you don't know what it will do. Don't do it. Don't hide behind "I need this and this is how to install it". know what's going on or don't do it.
- vectorjohn 11y agoAlso the ever popular Docker. On the other hand, if it's over SSL, you're just as well off as installing the software any other way. Although, I noticed the Drupal console installer isn't even on SSL.
- voltagex_ 11y agoOn one hand, I'm glad people are working on easier ways to install software. On the other, everyone is ignoring distro package managers. Docker gets it right [1] and then gets it wrong [2] - depends which set of instructions you read. I know creating distro packages and self-hosted repos is difficult, maybe we should be attacking that as a problem instead of writing hundreds of different shell scripts. 1: https://docs.docker.com/engine/installation/ubuntulinux/ https://docs.docker.com/engine/installation/ubuntulinux/ 2: https://docs.docker.com/v1.8/installation/ubuntulinux/#installation https://docs.docker.com/v1.8/installation/ubuntulinux/#insta... Bonus: https://twitter.com/mjg59/status/655812609715769349 https://twitter.com/mjg59/status/655812609715769349
- hellofunk 11y agoI don't get it... even if the pasted content has stuff I don't expect, I still see it in my shell prompt before I press Enter, no?
- remael 11y agoIf there's a newline in the pasted contend it's already too late.
- hellofunk 11y agoAh, thanks for pointing that out.
- RyanZAG 11y agoNo, if it includes a line break it will execute.
- wyldfire 11y agoNo, unfortunately not. I did a "cat >/dev/null" before pasting so I could see what it was. Clever masked/hidden content, with embedded shell commands and newline to commit the commands.
- jnbiche 11y agoI'm not understanding this approach. Cat is for files. How would you use it to protect against this trick? Do you mean you pre-typed "> /dev/null" and then pasted his git command where the cat is?
- wyldfire 11y agoNo, I just put my terminal into a mode where I could see what I pasted without any possibility executing it. If you don't give cat any arguments, it reads from stdin and writes to stdout. I could have just as easily opened vim/emacs/notepad and done the same, or for that matter, written the contents to an actual file instead of redirecting the contents to /dev/null.
- hasenj 11y agoA good terminal should show you the full pasted text in a confirmation popup before executing it. Also should never accept new lines from a paste. Or rather; if and when the paste contains new lines, it should show a confirmation popup so you know what the hell you're executing.
- vishnuks 11y agoElementary OS shows a warning message when a sudo command is copy pasted in to the terminal.
- Goopplesoft 11y agoiTerm2-Nightly (not sure about main) notifies you on multiple line paste, but does not provide the contents.
- amatic 11y agoSomething like windows? It should treat any newline signs in the pasted text as starts of new lines, not as "enter command". The person would need to press enter after pasting.
- wnevets 11y agoInteresting tidbit, I didn't know setting the position of text off the string would still be copied.
- nashashmi 11y agocopying and pasting to notepad or even the address bar reveals the hidden text.
- DeveloperExtras 11y agoFirst he says copy and paste to save for later.... Like in Notepad? Then switches to running things in the terminal. We already saw your 'trick' in step 1 when viwed in our Snippets Notepad file...
- spdy 11y agoAt the end of the day we have to have trust in others especially in opensource. Everything you incorporate in your apps/sites could be malicious.
- andreasvc 11y agoWhy especially in open source? The leap of faith is larger with a binary blob. (Although I admit it doesn't make much difference in practice, most people don't audit source code).
- hguant 11y agoI think the argument is that open source is based on the fundamental ideal of trust - I put this software out into the world so that people can better it, tweak it, make it their own. If those people don't trust you, and have to audit everything they install, the model breaks. Re binary blobs - honestly, for me at least, if I'm installing a blob it's probably because I purchased the software. Maybe it's naive but I more or less assume no company is going to actively screw over a paying customer
- andreasvc 11y agoProprietary software is equally if not more based on trust. Trust without being able to verify.
- jjuhl 11y agoWhich is why you should trust nothing and verify everything.
- SCdF 11y ago> Hello scdf! > That was a bad idea. Don't copy code from websites you don't trust! Or indeed, download software from websites you don't trust. I guess the worry would be that hackers would, as an example, take over brew.sh and do bad stuff with installation url. As opposed to taking over brew.sh (in an alternate world where brew.sh hosts a dmg file or something) and hosting an entirely different file. Bar the relative ease of hiding bad stuff in copy paste compared to making a fake dmg file, this seems to be basically the same situation no?
- kedean 11y agoMost terminal users these days are intelligent enough not to download a random executable from a google result and run it locally under root (without researching it). We've been well inundated not to ever run sketchy programs that you've never heard of. However, a huge portion of people (who this article is targeting), will freely copy and paste a terminal command from a random google result. That makes it a great attack vector for, say, intro to CS students who just want to make this linux thing work right.
- javajosh 11y agoI'm not so sure we're really capable of distinguishing between "random executable" and everything else. What do you have to go on in making the distinction? Let's say you're installing a new version of Sublime, or curl, or Chrome. These aren't 'random executables' - or are they? If someone poisons DNS, they could be. If someone MITMs them, they could be. What about stack overflow? Surely they are trustworthy. But if someone hacks them, and inserts an attack like the OP's, then you are in trouble. There are two problems. First, the hardware we own is almost comically powerful, both in compute and network bandwidth. Second, that same hardware mediates between us and everything that is important to us: our lovers, friends, business partners, banks, and so forth. A subtle enough hacker might get into our system and we might not know it, ever. (Indeed, if the hardware manufacturer put some secret code into their stuff then such a hack might be very subtle and very universal indeed.) I'm not throwing my hands up and saying it's all pointless. But consider that your typical gigabyte program has a tremendous amount of surface area to check. And no, you can't discount "dumb" resources like images and videos because they aren't executable. A smart attacker will encode instructions in, say, a viral YouTube video that will trigger those hidden CPU instructions that will load a steganographically encoded program. For now we have to be practical, and not freak out. For the future, we have to move toward smaller, more efficient software that makes unexpected computation and resource usage obvious from an outside observer. This means small code, short call-chains, and minimal screen, network or disk interaction. (I'm particularly worried by the trend for basically all software to be constantly connected to multiple unknown external hosts, any of which could be controlling code on my machine at the same level as the program I installed!)
- amelius 11y agoIf only operating systems offered a way to undo changes, then this would be mostly a non-issue.
- andreasvc 11y agoWhat good would undo do you if you didn't realize something bad happened?
- jeeyoungk 11y agoyou can't undo sending network packets containing sensitive information to somewhere else.
- hk__2 11y agoHow would you free up space on your disk if for every removed file the OS has to keep a copy in order to let you undo the removal?
- chdir 11y agoShould I consider my browser betraying me by selecting stuff that's outside the viewport without a hint / warning ? (absolute positioned element, (-100,-100)). It's simply too convenient to copy/paste from the browser. P.S. I have a paranoid habit of pasting copied text into the address bar or a notepad to quickly check for unwanted characters. For once, I don't feel like I'm crazy.
- tajen 11y agoStart programming editors and you will understand. What you see in a rich text editor contains hundreds of debugging flags and formatting tweaks. When copying, you want to copy something clean which will paste nicely in Word or Excel. And you want to add some metadata, so you can trace is source if it's pasted back in one of your editors.
- redcap 11y agoThis is an edge case. Most of the time your average user is after the text and not the shitty formatting. Copy-Paste as WYSIWYG should be default, Copy-Special should be an expert-only option.
- jacquesm 11y agoIt's because for the browser the visual selection is not the same as the textual selection. I'd say this qualifies as a browser bug rather than a user failure. What you see is not what you get.
- mmagin 11y agoI think it's incredible that most of the comments here seem to accept or even defend that this is just the way things are, even explaining all the ways they work around it, rather than considering that this is a serious browser security issue and violates the idea that software should generally do what the user expects.
- Goopplesoft 11y agoAside: its not sufficient to look at a file you 'curl | bash' into bash via your browser. It is very trivial to detect curl/wget's UA (mine has: "User-Agent": "curl/7.43.0") and dynamically modify files depending on the request's UI. if 'curl' in request.UA: return 'something malicious' else: return 'something nice' Always create a local file with the content, read it, then perhaps run it.
- pyre 11y ago... so this: wget -qO- 'http://example.com/script.sh' | less won't work to review the script?
- lqdc13 11y agono but if you change the user agent of the wget to the same one the curl uses, it would be much harder to figure out the differences.
- ryan-c 11y agoI'm pretty sure wget still makes it's http requests as version 1.0 rather than 1.1 (which nearly everything else uses), and if you want to change that you need to patch it.
- lqdc13 11y agoof course. There are also other differences. Actually, I have no idea why it even matters unless you are specifically exploiting curl. And they are not in this case. You can redirect wget output to stdout too...
- vectorjohn 11y agoI think he's suggesting using wget both times, not curl. So it doesn't matter what the UA is. As other have suggested, there are still possible ways to trick you, but it's getting more and more remote.
- 11y ago
- such_a_casual 11y agoIs there some firefox addon that will prevent websites from changing what I copy?
- ssharp 11y agoIt's not changing what you copy, rather when you highlight that, it's also selecting text that you can't see because it's been positioned outside of the viewport.
- ajmarsh 11y agoI usually go web --> text editor --> terminal. It's a pain but, it works.
- tolle 11y agoShouldn't have to be a pain? Browser plugin to paste content to editor window. Then something that runs the document its pasted into when you've read it? However, copy, paste, (save as a script|paste in terminal), run isn't exactly the most strenuous task in the history of man either. So it'd be a fairly meaningless chain of plugins for close to zero benefit.
- leejo 11y agoCTRL-X CTRL-E will take you into your editor[1] from the command line, where you can paste away and see/edit if necessary. Once you exit from the editor the commands that were entered will be run. So (if vi): CTRL-X CTRL-E i CTRL-V[2] ESC :wq [1] at least in bash, possibly others. [2] or whatever your paste shortcut is, and then edit if necessary Edit: seems this is also possible for zsh but needs some config first: http://nuclearsquid.com/writings/edit-long-commands/ http://nuclearsquid.com/writings/edit-long-commands/
- mikeash 11y agoThat's a lovely hint, thanks!
- pskocik 11y agoIf you bother to compose half a page on a software problem, might as well provide a solution, no? runCb(){ cb; echo -e '\n\nGo on? (y/n)'; read -sn 1 ans; if [ "$ans" = y ]; then eval "`cb`"; else true; fi; } #cb should output the contents of your clipboard Or another option would be to switch your terminal to editing mode (v in the normal mode of `set -o vi`), paste it there, and do `:wq` to run it.
- teleclimber 11y agoYou don't even need to be that crafty with CSS. Just a few lines of JS will do. Try copying the Hello World text in this fiddle and paste it in a text editor: http://jsfiddle.net/teleclimber/8q6sp5ga/ http://jsfiddle.net/teleclimber/8q6sp5ga/ (Tested in Chrome)
- cbg0 11y agoI believe the point was to show it will work even on people with js disabled.
- eveningcoffee 11y agoWorks with FF on Ubuntu latest stable.
- RyanMcGreal 11y agoWorks in Firefox 42.0 as well.
- friendzis 11y agoI personally do web stuff in GUI with a mouse (I have vimium chrome extension, but old habits die hard) and select text by multitap: 60% of the time it works all the time. When it does not work I just drag-select and paste to terminal. Seems rather safe, as this does not work on this example. tripple-tap on both urls give "git://git.kernel.org/pub/scm/utils/kup/kup.git" (with the exception that the first one contains a newline), and in such cases I am too lazy to reselect and just prepend the url with muscle memory git clone.
- delinka 11y agoOff-topic/meta: "Oh, and it seems that other people wrote a detailed text about this issue in 2008." Well ... yeah. We've known about this. And yes, we need to keep making people aware. I'm also amused by all the young people and their containers: always doing things in a root shell. I'm waiting for that to implode in a few more years. My point here is that maybe it's time we started designing some curricula around these things that people keep rediscovering: Why you do indeed want a relational database manager and probably not a 'NoSQL' store; and when you do want a NoSQL store. Multiplexing existing systems with VMs; how your VPS works and why it worked so well on mainframes back in the day. (and oh, btw did you know that you can just pull hardware, including CPUs, right out of the mainframe and it'll keep doing its job?) Dangerous things we've all done at some point and prime (hands-on) examples of the failures that might ensue... And no, I don't mean (necessarily) to teach in schools. Maybe an online collection. "So you wanna 'do computers' without getting hacked and without re-inventing everything..."
- samstave 11y agoI made a very similar suggestion, perhaps less well articulated, just a few minutes ago on HN re: instragram v2 going to multi-DC; When there is a write up of "We just did this super awesome scaling migration to the new hotness!" -- there will be mini-how-to articles in them... or at least more in-depth reasons why and for what problem they were specifically solving. A how-to-wiki-gist? with "this is how you connect X with Y over ABC service in order to eliminate problem XYZ" would be great and allow for people to contribut to the how-to... But we've been saying this for 15+ years... :-)
- j42 11y agoAs someone who develops high-performance systems and is continually learning, I think this is a fantastic idea! Honestly, something that seems desperately needed as that knowledge is currently spread out among hundreds of thousands of blog posts, forums and threads -- diamonds in the rough. I'm going to try to get something published on gumroad (and open-sourced on github) in this vein, if you're interested let me know and I'll reach out when it's done :)
- noobermin 11y ago
- rnovak 11y agoGenerally I take a "Trust, but Verify" approach to most everything, and luckily, modern browsers have a nifty "search google for..." context menu option that lets me check anything that I highlight out on google (what a wonderful world), so the second I right clicked on what was highlighted the 'hidden' content was revealed.
- bronson 11y agoI couldn't see what was weirding everyone out. I'd selected it by double-clicking the first word and dragging. If you click outside the text and drag across it, this page makes a lot more sense.
- brunosutic 11y agoAnother reason against copy-pasting from the web is using unicode characters that look like ASCII ones. This was on HN a week or so ago, but it doesn't hurt to repeat. Example shell command: eⅽho 'hello world' Copy-pasting the above command will fail with the message `eⅽho: command not found`. The reason? 'ⅽ' in 'eⅽho' is a unicode character "SMALL ROMAN NUMERAL ONE HUNDRED" that looks identical to regular ascii 'c'. The above can also be mis-used for any programming language, not just shell commands.
- steveklabnik 11y agoIt looks very different on my system.
- MiddleEndian 11y agoThere are some good clipboard viewers on most platforms. I've used Butler on OS X, Klipper on Linux w/ KDE, and Ditto on Windows. A quick keyboard shortcut will show you what's in your clipboard and tons of recent clipboard entries.
- jimrandomh 11y agoThis is properly viewed as a bug in bash (and most other shells). Shells can tell terminals to do "bracketed paste": the start and end of a pasted block is marked with escape sequences. The correct behavior is to use bracketed paste, and to treat newlines inside pastes as multiline text input, not as a ready-to-execute signal. Apparently that hasn't happened because of compatibility problems with broken terminals, plus perhaps a bit of work that no one's stepped up to do. If anyone wants to tackle this, the GNU readline library would be the place to do it.
- jwilk 11y agoBracketed paste can save you from accidental damage, but not from malicious pastes. As the fine article says, the end sequence can be inside the text you paste unless your terminal emulator filters out the bracketed paste characters (and last time I checked, at least urxvt didn't). Besides, teaching shell about bracketed paste could only help for pasting directly to shell; it won't help if you're pasting to vim (think of "^[:q!echo pwned^J") or cat (think of "^Decho pwned^J").
- jimrandomh 11y agoOk, sounds like it's two bugs - terminals definitely shouldn't pass through a bracketed paste end-marker, and probably shouldn't pass any control characters at all (ie, no esc or ^D). Passing special control characters through the clipboard is already unreliable, so I don't think this change would break anything legitimate.
- dang 11y agoDiscussed in 2013: https://news.ycombinator.com/item?id=5508225 https://news.ycombinator.com/item?id=5508225
- mcoliver 11y agoFor those trying to find it...the added code is injected in the space character between "git clone" and "git://git.kernel.org/pub/scm/utils/kup/kup.git"
- mixmastamyk 11y agoReminds me of a time a few years back when many vigorously defended a similar process with sublime text: https://news.ycombinator.com/item?id=4247566 https://news.ycombinator.com/item?id=4247566 TL:DR "Just paste this obscure python code into the console!" I'm still surprised, looking back at that thread today.
- balls187 11y agoSadly I am guilty of doing this. It boils down to trust. I trust that Mint won't screw up securing my bank credentials. I also trust that OSX HomeBrew's install instructions aren't fubar.
- hackbinary 11y agoWell, that is why I always paste stuff into a text editor first. git clone /dev/null; clear; echo -n "Hello ";whoami|tr -d '\n';echo -e '!\nThat was a bad idea. Don'"'"'t copy code from websites you don'"'"'t trust! Here'"'"'s the first line of your /etc/passwd: ';head -n1 /etc/passwd git clone git://git.kernel.org/pub/scm/utils/kup/kup.git
- jgome 11y agoOr just paste it in the address bar and copy it again (ctrl+l ctrl+v, then ctrl+a ctrl+c). This removes newlines, though.
- ABS 11y agoHighly recommend the entertaining talk Ben Huges from Esty gave at Operability.IO in London on "Security for non-unicorns" https://www.youtube.com/watch?v=B4ra9_KnMdk&list=PLK4VB0cauli7-_RIvpmn651ePtddw9_Fp&index=15 https://www.youtube.com/watch?v=B4ra9_KnMdk&list=PLK4VB0caul... He talks about this as well
- deleted 11y ago[deleted]
- lovboat 11y agocopy and paste but before do cat -A - and here paste text, you can see what is going on.
- niccaluim 11y agoDuh, everyone knows you should pipe curl into bash instead.
- intrasight 11y agoI like the <!-- Oh noes, you found it! --> in the HTML I always paste into Emacs notes first
- codegeek 11y agoI never paste anything directly anywhere when copied from a webpage. I first paste it on Notepad to handle any formatting and hidden text. Once pasted on notepad, I copy/paste to the final destination.
- duncan_bayne 11y agoNotepad? Sounds like your machine is already infested with malware ;-)
- Gigablah 11y agoRun Atom/ST3 with random plugins downloaded from around the web instead, that's much safer :)
- duncan_bayne 11y agoI prefer Emacs with MELPA for my editor based vulnerabilities ;-)
- Smushman 11y agoGuilty as charged. I LOL'ed when I pasted this in to notepad first. Luckily I usually do the paste, but not for security reasons, to make sure formatting is as expected. Now I have a reason to do that every time. Thanks poster!
- jacquesm 11y agoSo, ok. Don't copy and paste from a website to a terminal, I get it and I got it the last time that this kind of thing was posted. But if I look around I put so incredibly much trust in total strangers all the time that compared to say ordering a pizza (where the cook could put anything in the food they wanted), driving on the highway (where anybody could swerve any moment if they wanted) and simply walking down the street (where that old lady on the left of me could pull a knife and stab me any time they wanted) that you have to wonder if the downsides weigh up against the upsides of simply trusting the website you get the information from and getting on with your life (besides the fact that it is the browser acting in an un-expected way here, the bit selected does not mirror the visual feedback given to the user, this might even simply qualify as a bug). What is the actual risk here, how many people have been bitten by this sort of thing and what was the resulting damage? I'm not saying there isn't any risk, clearly there is a possibility for exploitation here so chances are this is an actual risk. But I find it hard to make the case that we should all now start re-typing all the text in how-to's and scripts. It's one thing to run wget | curl, quite another to distrust each and every snippet of code on the web. I don't see much difference compared to say installing Ubuntu from a website whose contents I haven't inspected and that may have been built with a bunch of malicious stuff in it, I did not actually inspect all the source code this machine was built up with and I would be busy for half a lifetime if I did, so I outsourced the trust and verify that trust by looking at some checksum but that's about the extent of it. Is there anybody that can quantify this risk somehow? Has anybody been personally burned by this?
- dedward 11y agoPaste into a text buffer first, which is generally a good idea anyway to deal with formatting issues.
- jacquesm 11y agoI do that regardless because I'm super paranoid about stuff like this but I'm really wondering if I'm not taking it a bit too far. I've also yet to run into any kind of attempt to pull a stunt like this in a very long time of activity so I'm wondering what the actual incidence is.
- baby 11y agoCan't remember which oh-my-zsh plugin it is but you can prevent pasting-and-executing in the terminal. What it does is that you still have to hit enter when you paste something, even if there are breaklines in it. That way you can read what you will execute.
- anotheryou 11y agovimperator (firefox add-on) ftw: it says "Yank git clone dev/null..." (and changes the whole FF, not recommended as a remedy for this issue :)
- halayli 11y agoI have this habit of always pasting in the url bar then copying it from there. it clears formatting, and merges the lines.
- orionblastar 11y agoI found out the hard way that a lot of websites on Linux are either out of date or give instructions that can ruin your system. In trying to solve a black screen with Mint 17.2 I followed directions on adding a PPA to install Nvidia drivers and then remove the open source drivers. When I rebooted I still got the black screen and in recovery mode I could not log in because it said an ACL for a card was missing a file. When I went to reinstall Mint it didn't want to overwrite the partition and wanted to create a new one alongside it. Forcing me to delete the Linux partition and start all over again. A lot of websites just give wrong advice and if you aren't an advanced user who knows how to fix things when they break, you could be stuck with an unusable system.
- psyonix 11y agoI ran into a similar issue with a black screen in Ubuntu, seemingly a result of driver issues too. It turns out the normal installation wasn't partitioning enough space for it to run in (I installed it alongside Windows 7). I had to manually partition the disk to give it ample room. Once I did that, everything ran just fine. Along the way I encountered a lot of advice similar to what you did, and it set me back several hours before I realized what the actual cause was.
- lottin 11y agoIs it me or the issue isn't copy-pasting here? The problem is downloading and running a piece of code you haven't looked at. I don't know if git is supposed to work this way but it sure looks dangerous.
- mrmondo 11y agoWhile by no means a be-all and end-all fix - here is a simple add on for Firefox in which you can set the default copy method to plain text: https://addons.mozilla.org/en-us/firefox/addon/copy-as-plain-text/ https://addons.mozilla.org/en-us/firefox/addon/copy-as-plain...
- totoroisalive 11y agoMy approach is in the same lines of short urls I checked the long url first, so whenever I do the copy and paste I open my text editor, because almost every time need adjustments.
- hebdo 11y agoDo not cat log files either: http://unix.stackexchange.com/questions/15101/how-to-avoid-escape-sequence-attacks-in-terminals http://unix.stackexchange.com/questions/15101/how-to-avoid-e...
- jjuhl 11y agoCommon sense.
- condescendence 11y agoTotally arbitrary. If you're simply copy and pasting commands you probably don't know what you're doing, OR you're just looking for the quick shortcut. Either way, when I paste I usually put it through a scrapped terminal. Meaning I have to hit enter twice for any command to actually be executed. If you're not checking your commands before you hit enter it's like getting in a car for the first time and bringing it to top speed hoping that it won't rattle apart and kill you. To further this analogy, if I were to get a car from a dealership brand new it might have some issues but for the most part it's brand new and safe. If I'm buying a car from some shady lot behind a Waffle House, well then I should probably bring it to a mechanic to get inspected and such. To detract from the analogy, dealerships are giving out different new cars while copy/pasting code from tutorials such as Linode are always giving the user the same content, they've been checked numerous times and hopefully the bullshit has been caught already.
- mod 11y ago> when I paste I usually put it through a scrapped terminal How does this work / how do you do it?
- osxrand 11y agoI've noticed when copying stuff like this that the selected text looks different on iOS. This is how it looks in this instance : http://imgur.com/ddZ4ytL http://imgur.com/ddZ4ytL
- acd 11y agoHere is a demo why this is not a good idea #!/bin/bash sudo rm -rf / | curl
- deleted 11y ago[deleted]
- Mojah 11y agoThis is an excellent example that shows the dangers of terminal escape sequences. Just a shameless plug, but here's a more detailed post (of mine) on the subject: Terminal escape sequences – the new XSS for Linux sysadmins: https://ma.ttias.be/terminal-escape-sequences-the-new-xss-for-linux-sysadmins/ https://ma.ttias.be/terminal-escape-sequences-the-new-xss-fo...
- Pxtl 11y agoExcept that every help forum about the more idiosyncratic OSS tools is full of text you need to copy and paste from a website into a terminal. It's virtually the main workflow. I mean, even venerable Git is well-known for having this workflow: http://m.xkcd.org/1597/ http://m.xkcd.org/1597/ not to mention tar https://m.xkcd.com/1168/ https://m.xkcd.com/1168/ ... I wonder how many "google-oriented development" OSS tools has xkcd made a comic about?
- hollerith 11y agoOne possible response to this information is to try to educate all users of the web not to copy paste from a web site into a terminal. Another possible response -- the one I prefer -- is to change the web browsers so that the copy operation only ever copies selected text visible to the user. That is how the copy operation works in my text editor and how it used to work in web browsers in the 1990s. Copying and pasting are useful. The fact that some are trying to persuade all web users to stop doing it -- or to stop doing one common kind of it -- is a sign that there is something wrong with current web browsers. Yes, I know that Unicode contains glyphs that look so much like common ASCII glyphs that a user can be fooled into, e.g., curling from a site controlled by an attacker when he thinks he is curling from github.com or some other trusted site. Maybe that means that the browser warns the user whenever the copied extent of text contains non-ascii characters; maybe the browser simply refuses to copy the non-ascii characters. Regardless of how we deal with malicious use of obscure Unicode characters, I think my previous paragraph holds up. (Users of languages other than English should replace "non-ascii" above with "characters not commonly used by writers of the languages that the user usually uses".)
- leejo 11y agoOK, i've replied with this elsewhere in the thread but will repeat it here for those who miss it. If you're on the command line and want to drop into your editor to paste, or just write a long command, and then have the command(s) executed after exiting the editor: CTRL-X CTRL-E If using zsh: http://nuclearsquid.com/writings/edit-long-commands/ http://nuclearsquid.com/writings/edit-long-commands/
- deadlycrayon 11y agoDon't beat a dead horse
- xlvio 11y agoI don't copy paste from anything to a terminal really. I was dealing with an enterprise client once who had an 'IT guy' who insisted for months that the Git repo was broken because the URL I had provided was invalid. dude was copy-pasting directly from the PDF guide I'd sent them (and copying incorrect characters), which actually specifically sates never to copy-paste any commands into the terminal as a basic security guideline. hah.
- totony 11y agoRxvt unicode has a perl plugin that enables you to confirm whether or not you really want to paste the text
- totony 11y agoRxvt unicode has a perl plugin that enables you to confirm whether or not you really want to paste the text
- totony 11y agoRxvt unicode has a perl plugin that enables you to confirm whether or not you really want to paste the text
- graycat 11y agoSpecial case of the first rule of computer security: Do not let data from untrusted sources execute as code.
- andrew_mason1 11y agoDon't copy paste from a website, just curl into ruby! http://brew.sh/ http://brew.sh/
- psyonix 11y agoSuper guilty of this. I'm a novice to Linux, so I didn't really know this was a thing (until now!) That said, I'm glad this was posted so that going forward I will be mindful of the risks and can mitigate them.
- aaossa 11y agoWow, this is interesting, thanks! :)
- nickpsecurity 11y agoI decided an alternative route: copied the text and pasted it into a text editor first. Shows the attack. So, I think the lesson is to do two things: 1. Copy in a harmless way first to be sure WYSIWYG. 2. Compare the commands against the man page or local docs to make sure they look right. This is the method I created after someone posted this in response to me using an online cheat sheet for console app. I appreciated that person bringing it to my attention. However, this should knock out most risk in that area. Other objections were essentially about how one shouldn't use commands from sources they couldn't totally trust. That's a BS double standard easily countered by, "Oh and I guess you don't run any code/binary you get from proprietary vendors or FOSS repositories unless you inspect every line to be sure it's safe?" Hell will both be empirically proven to exist and freeze over before those people's preaching and practices are consistent.
- moey 11y agoHere's my biggest secret. I almost always use Chome's URL address bar as a text buffer. Not only to make sure what I copied is what I expected, but to remove new-lines, and if it's a terminal command, to allow me to edit the arguments in free-form before pasting into terminal.
- krick 11y agoNeat trick, but besides that… At the time I'm typing it the post has 516 points and 201 comments, so many people have been here. Now: how many people will actually stop doing that after reading the post? Because I don't think I will.
- torbjorn 11y agoRunning this code doesn't actually do anything bad. It just demonstrates the shell's access to sensitive data and downloads a file upload utility.
- sizofworld 11y agoIt is more likely a practical joke.
- kowdermeister 11y agoJust use control+shift+v that drops any formatting on the clipboard and keeps the text part. Incredibly helpful for wysiwyg editors too.
- enobrev 11y agoDoes not seem to work on ubuntu, unfortunately.
- kowdermeister 11y agoYeah, it's a Windows thing, forgot to add.
- Kristine1975 11y agoThis sounds like a browser bug to me: When I select text and then copy it, only the text that is actually visible should be selected and copied to the clipboard.
- bipin_nag 11y agoThe middle mouse paste (select to copy) in Ubuntu makes it even more seductive. In many occasions I have accidentally pasted code into my terminal window and many times without even knowing (debugging phantom menaces). I have started using Clipit/gedit to screen code now.