3 ms·
https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b... This outlines a PO
by toothbrush 10y ago
https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
This outlines a POC for detecting whether your script is being downloaded or piped into Bash. Beware.
- lifthrasiir 10y agoGood point, but the domain `raw.githubusercontent.com` is a dumb CDN that a possible attacker cannot control.
- MaulingMonkey 10y agoCan you say the same about raw.gjthubusercontent.com ? Also, the attacker can push an update if they can successfully guess the window between you reviewing a file and you installing a file. Not nearly as reliable as that POC, but hardly impossible. Best to avoid building bad habits. Perhaps worthwhile to build good ones - even when it's "safe" to skip.
- brazzledazzle 10y agoI think your point about building good habits is really worth thinking about for anyone that thinks they can evaluate the entire set of risks every time they do something like this. Or pretty much anything really. You can't count on always having the clarity of mind you have at this moment. It's easy to get distracted and good habits protect you when you're vulnerable, not when you're at 100%.