5 ms·
I disagree with some of this, I.e paste jacking. Plenty of software projects put more care and focus into their software and not in their website, if you're ru
by LIV2 7y ago
I disagree with some of this, I.e paste jacking.
Plenty of software projects put more care and focus into their software and not in their website, if you're running a vulnerable version of Wordpress or whatever CMS it'd be easy for someone to insert something malicious without being noticed whereas something that modified your code would show up in git, code reviews etc
- Carpetsmoker 7y agoPastejacking should be mitigated if you use zsh, as it will never run pasted commands automatically. From quick test it seems that recent(?) versions of bash also implemented this feature and have it enabled by default. I don't know about fish or other shells.
- Un1corn 7y agoPastejacking is not the only possible attack by a compromised server, you can also change the content of the script when the user download it through curl or wget. Oh My Zsh use GitHub for their script so I trust it more than if they hosted it themselves for example
- Carpetsmoker 7y agoIf people have access to change the content of the script then they can also change foo-1.2.3-src.tar.gz or foo-1.2.3-linux-amd64.gz. These are all general problems with downloading anything from the internet.
- Un1corn 7y agoRight but the attacker can make it look legit even for someone that look at the script. The attacker can change the content of the script by the user agent or even by detecting when you pipe it to bash[0] [0] https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- CoryG89 7y agoThe set of people who have access to the GitHub project (push privileges) might not be the same as the set of people who have access to said project's website.
- minitech 7y agoNot running pasted commands automatically isn’t a security feature on its own, because the paste “brackets” of bracketed paste can be inside the clipboard. It’s kind of ridiculous that most terminal emulators don’t defend against that by default.
- heinrich5991 7y agoFish also does this.
- Rapzid 7y agoAre you talking about the shell or the terminal protecting against paste jacking? I'm aware of terminals now protecting against this.
- aasasd 7y agoThis is pretty much the only real answer to the article. However, if the software itself is distributed via the site then the same caveat applies since replacing the release itself is much more enticing. It comes down to either the software being published on Github where a hijacked release might be noticed, and/or files having signatures that you can somehow trust.
- mehrdadn 7y agoHow is this any different from just downloading a binary from their website and running it? Which people have been doing for ages?
- cameronbrown 7y agoPlenty of installation scripts ask for root.
- theamk 7y ago... and this is a red flag which generally forces me to stop and check why if I download latest music editor, and it wants root, I will be very suspicious.
- Rapzid 7y agoIt's different because in a lot of cases there are more layers of security in place that haven't been discussed. For instance it would be typical in the past to sign the packages/software and publish the public key either to the site or somewhere else. Private keys used to sign the software would never touch the website infrastructure and would live on, typically, much more secure build or sign-only infrastructure. The public keys used to verify the software could also be delivered through a separate channel, signed by a trusted third party, and etc. With Trust on First Use(TOFU) you'd trust the key when you first obtain it and be notified if the key ever changed unexpectedly. I agree with the general point of this article. This is the weakest part of the arguments IMHO.