4 ms·
That is really true. Any solution you propose? I mean, it is all open source, but if the author of the PoC repository were to put malicious code into the file,
by Arinerron 10y ago
That is really true. Any solution you propose? I mean, it is all open source, but if the author of the PoC repository were to put malicious code into the file, how would we know before reading the source?
Do you think I should host the file somewhere I trust, and make it check the hash of the downloaded file from a different to ensure it isn't compromised? My worry then is, what if the hash was compromised too?
I appreciate your response. Thanks!
- bastijn 10y agoI think it all starts with educating the careless. Remind them of the risks so in due time they learn to think before they act. Do you have a responsibility as the provider of the script? I do not know, as a true hero you could put a statement on the top of your readme. Like a warning message. One step ahead you can become an even greater hero and host the zip yourself on a secure source. However, this places the burden of maintenance to you which is something which you might not like. In addition it brings the question of ownership.\ I think there is no real answer here. Warn them, and warn them often might be the mitigation.
- Arinerron 10y agoThanks! What kind of warning message would you suggest? A "the exploit might be compromised" message, a "verify your download with this hash" message, or something else?
- anilgulecha 10y agoOne thing you can do is simply fork the repo, and use your repo as the path in the script. So you're not at the mercy of upstream author's changes.
- Arinerron 10y agoThanks, I'll do that. One problem though is that I've already published the script here, and migrating to a new repository would leave everyone with a dead link, etc. I could post the script in the fork too, though.
- bastijn 10y ago"Careful. Running scripts from unidentified sources can comprimise your device. Never copy and paste something directly from an untrusted source to an executable context. Never ever." That should do the job. More good reads on why you don't want to do this: http://www.ush.it/team/ascii/hack-tricks_253C_CCC2008/wysinwyc/what_you_see_is_not_what_you_copy.txt http://www.ush.it/team/ascii/hack-tricks_253C_CCC2008/wysinw...
- userbinator 10y agobut if the author of the PoC repository were to put malicious code into the file, how would we know before reading the source? You might not know but there are probably quite a few who do analyse these things and would "blow the whistle" if they found something amiss. Thus, if you're really unsure you can wait a short while before using it, to see others' experiences first. In general, the same principle goes for warez and any other unofficial, reputation-driven community where there is no central authority. If you wanted to be absolutely "safe" you would not be wanting to root anyway... it's risky and I'd say that's even part of the fun for those who do.