5 ms·
I see this comment a lot regarding piping an untrusted script to a shell with sudo permissions. Do you feel much safer downloading something as a package (mayb
by nuggien 10y ago
I see this comment a lot regarding piping an untrusted script to a shell with sudo permissions. Do you feel much safer downloading something as a package (maybe installer executable) and then running it with sudo? What's to prevent the same kind of dangers as the scripted version? At least with the scripted version I can quickly glance at it and figure out all that it does, rather than try to unpackage an installer exe.
- scaryclam 10y agoNever, ever run a cli command from a website on the Internet that pipes through sudo...ever. There's nothing to save the latter, it's just not as common, and if you don't know the origin, the same advice applies: don't do it. Anyone executing a random executable is being stupid. Difference is, anyone directing users to install via a sudo piped command is just plain irresponsible. Don't ask your users to do something so daft!
- toothbrush 10y agohttps://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b... This outlines a POC for detecting whether your script is being downloaded or piped into Bash. Beware.
- lifthrasiir 10y agoGood point, but the domain `raw.githubusercontent.com` is a dumb CDN that a possible attacker cannot control.
- MaulingMonkey 10y agoCan you say the same about raw.gjthubusercontent.com ? Also, the attacker can push an update if they can successfully guess the window between you reviewing a file and you installing a file. Not nearly as reliable as that POC, but hardly impossible. Best to avoid building bad habits. Perhaps worthwhile to build good ones - even when it's "safe" to skip.
- brazzledazzle 10y agoI think your point about building good habits is really worth thinking about for anyone that thinks they can evaluate the entire set of risks every time they do something like this. Or pretty much anything really. You can't count on always having the clarity of mind you have at this moment. It's easy to get distracted and good habits protect you when you're vulnerable, not when you're at 100%.
- addicted 10y agoCan't you checksum verify installers and packages? You can't do that with these curlpipesudos. You are taking a leap of faith anytime you install something however you do it. The problem with the CPS seems to me that it's much easier for you to correctly trust the originator of the content, but have the content hijacked by a 3rd malicious party.
- shawabawa3 10y agoChecksum from where? The same site you download it from? What's the point?
- mikeyjk 10y agoDoes anyone regularly use checksums as part of their 'routine' for downloading normal, or special files? It seems like a great system, that isn't used regularly by people in my circle.