4 ms·
Pastejacking is not the only possible attack by a compromised server, you can also change the content of the script when the user download it through curl or wg
by Un1corn 7y ago
Pastejacking is not the only possible attack by a compromised server, you can also change the content of the script when the user download it through curl or wget.
Oh My Zsh use GitHub for their script so I trust it more than if they hosted it themselves for example
- Carpetsmoker 7y agoIf people have access to change the content of the script then they can also change foo-1.2.3-src.tar.gz or foo-1.2.3-linux-amd64.gz. These are all general problems with downloading anything from the internet.
- Un1corn 7y agoRight but the attacker can make it look legit even for someone that look at the script. The attacker can change the content of the script by the user agent or even by detecting when you pipe it to bash[0] [0] https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- CoryG89 7y agoThe set of people who have access to the GitHub project (push privileges) might not be the same as the set of people who have access to said project's website.