5 ms·
`$ curl -L https://raw.githubusercontent.com/kamranahmedse/git-standup/master/installer.sh https://raw.githubusercontent.com/kamranahmedse/git-standup/... | sud
by _RPM 10y ago
`$ curl -L https://raw.githubusercontent.com/kamranahmedse/git-standup/master/installer.sh https://raw.githubusercontent.com/kamranahmedse/git-standup/... | sudo sh
`
nice. this shit again
- nuggien 10y agoI see this comment a lot regarding piping an untrusted script to a shell with sudo permissions. Do you feel much safer downloading something as a package (maybe installer executable) and then running it with sudo? What's to prevent the same kind of dangers as the scripted version? At least with the scripted version I can quickly glance at it and figure out all that it does, rather than try to unpackage an installer exe.
- scaryclam 10y agoNever, ever run a cli command from a website on the Internet that pipes through sudo...ever. There's nothing to save the latter, it's just not as common, and if you don't know the origin, the same advice applies: don't do it. Anyone executing a random executable is being stupid. Difference is, anyone directing users to install via a sudo piped command is just plain irresponsible. Don't ask your users to do something so daft!
- toothbrush 10y agohttps://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b... This outlines a POC for detecting whether your script is being downloaded or piped into Bash. Beware.
- lifthrasiir 10y agoGood point, but the domain `raw.githubusercontent.com` is a dumb CDN that a possible attacker cannot control.
- MaulingMonkey 10y agoCan you say the same about raw.gjthubusercontent.com ? Also, the attacker can push an update if they can successfully guess the window between you reviewing a file and you installing a file. Not nearly as reliable as that POC, but hardly impossible. Best to avoid building bad habits. Perhaps worthwhile to build good ones - even when it's "safe" to skip.
- brazzledazzle 10y agoI think your point about building good habits is really worth thinking about for anyone that thinks they can evaluate the entire set of risks every time they do something like this. Or pretty much anything really. You can't count on always having the clarity of mind you have at this moment. It's easy to get distracted and good habits protect you when you're vulnerable, not when you're at 100%.
- addicted 10y agoCan't you checksum verify installers and packages? You can't do that with these curlpipesudos. You are taking a leap of faith anytime you install something however you do it. The problem with the CPS seems to me that it's much easier for you to correctly trust the originator of the content, but have the content hijacked by a 3rd malicious party.
- shawabawa3 10y agoChecksum from where? The same site you download it from? What's the point?
- mikeyjk 10y agoDoes anyone regularly use checksums as part of their 'routine' for downloading normal, or special files? It seems like a great system, that isn't used regularly by people in my circle.
- eridius 10y agoThere's nothing at all wrong with this. I'd say 99.999% of the time someone runs an installer script to install something, they don't read it first. And if you're not reading the script first, then there's no benefit whatsoever to downloading it prior to executing, as opposed to just executing directly. The only reason to say "don't pipe into sh" is if you're saying "review the installer script 100% of the time before executing it", which, honestly, is advice nobody's going to follow.
- riquito 10y ago> There's nothing at all wrong with this. Sure, no server has ever been compromised and his binaries replaced... The good old pgp signatures, circle of trusts, etc are not for show. Eck, it's not even served from github.com but from a random proxy
- eridius 10y agoNothing you're describing applies to the scenario of "download, then execute" either, which is the alternative to "pipe to bash". Anyone who's willing to read the script first, or verify PGP keys, or whatnot, is perfectly capable of doing so even if the instructions tell you to pipe to bash. But the overwhelming majority of people don't do that.
- rejschaap 10y agoI feel this comment would be more justified if they didn't mention three other ways to install the tool.