4 ms·
I don't understand how the curl http://site.com http://site.com | bash anti-pattern has become so widespread. Especially with -k.
by syoc 8y ago
I don't understand how the curl http://site.com http://site.com | bash anti-pattern has become so widespread. Especially with -k.
- johnchristopher 8y agoI don't know why you are being downvoted but I'd like to know. I have a very official and very governmental API that isn't properly set up and the official doc says to use curl -k to talk to it. I had a long argument with one of the dev, with a PoC and a live example, about how it was a bad idea, especially considering how it can easily be fixed but... the 'feature' is still there. I suppose the next $2,000 a day consultant will get them the memo.
- BluSyn 8y agoIt originated as a way for people who aren't familiar with CLI to install things. People have now been trained to expect this level of simplicity. I've worked with people that will blindly copy and paste these lines into terminals, having absolutely no idea what they do, and even blindly type in sudo password when prompted. It's basically the worst of all worlds from a security perspective. In my opinion this should be burned to the ground. Normally when I see this I will manually download the bash script, read through exactly what it does, and manually type in each command instead of running the script directly. This way I know what it is doing, and it can't hide command output by piping into /dev/null and doing something without my knowledge. Seriously people. Never. Trust. Bash Scripts.
- type0 8y agoThere's these cautionary tale you might find interesting https://www.vidarholen.net/contents/blog/?p=746 https://www.vidarholen.net/contents/blog/?p=746 and seriously just Shellcheck it should be in your repos.
- mindslight 8y agoDownloading and reading the bash script isn't a solution either. Even if it isn't deliberately malicious, those things usually want to just puke files into some arbitrary corner of your system or homedir - really the author just made a "works fine on my system" crutch rather than doing the actual work of packaging. Then to double down, they'll often add some "clever" hooks to self-auto-update your local junkheap from their git nightly, because releasing deliberate versions doesn't "move fast and break enough things". I either want to pull from the standard distribution repositories and rely on things updating automatically, compile from source tarballs with explicit version numbers, or at the very worst have a path-independent binary tarball that can be unpacked anywhere. If you can't manage any of these, then your project simply isn't ready for general availability.
- ksaj 8y agoI've seen scripts that "clean up" with an 'rm *.o' statement (for example), which strongly suggests the potential for total disaster if you blindly run it from the wrong directory. Glad I'm not the only one with script paranoia.
- deleted 8y ago[deleted]
- Sylamore 8y agoEspecially since it is possible to detect merely downloading from actually piping to a shell serverside[0], you should never do this even if you've examined the script first. [0] - https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...