4 ms·
Opening it in a text editor is not sufficient. With clever use of 'sleep' you can even have the server return a malicious payload only if it thinks its getting
by stable-point 10y ago
Opening it in a text editor is not sufficient. With clever use of 'sleep' you can even have the server return a malicious payload only if it thinks its getting immediately piped to sh[0].
If you're opening it in a browser to check, you've also got to worry that the server may be looking at curl's user agent to decide whether to serve up a malicious payload[1].
[0] https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
[1] https://jordaneldredge.com/blog/one-way-curl-pipe-sh-install-scripts-can-be-dangerous/ https://jordaneldredge.com/blog/one-way-curl-pipe-sh-install...