3 ms·
Another issue is partially written responses. If the connection fails in the middle of your curl (or the source's application crashes) you can receive part of a
by vhost- 10y ago
Another issue is partially written responses. If the connection fails in the middle of your curl (or the source's application crashes) you can receive part of a shell script that could very well contain `rm -rf /usr`.
Edit: I cooked up an example actually. Here is a small Go program that will panic after 1 nanosecond: https://gist.github.com/kyleterry/dc304503dfca2d149b189694d13617b8 https://gist.github.com/kyleterry/dc304503dfca2d149b189694d1...
This will sometimes return partial responses.
Run this in a bash `while true` loop and curl localhost:8080 a few times. You will mostly see empty and full responses because my example isn't perfect, but occasionally you will only get part of the script dumped to the screen and that's the problem with curl|bash.
- mark-wagner 10y agoThe "curl | bash" usages I've seen from reputable sources avoid that by defining a single bash function f and then executing the the function as the final character, i.e.: function f { echo "hello world" } f
- vhost- 10y agoTotally, this is a good way to protect from that. It's just impossible to trust that is what someone is doing without going and looking at the script unfortunately.