4 ms·
How is this the slightest bit different than faking a site and altering the binary/source package on the other end of a regular old Download link? (edit: Oh. Y
by rhymeswithcycle 16y ago
How is this the slightest bit different than faking a site and altering the binary/source package on the other end of a regular old Download link?
(edit: Oh. You're doing user-agent sniffing for curl. Fair enough, but this still isn't any less secure than downloading and executing a binary.)
- jcapote 16y agoThis is why most packages are distributed with checksums, so you can be sure that what you're running is what the author intended.
- rhymeswithcycle 16y ago... if you're getting the checksum from a trusted source that is separate from the package distribution server, or if the checksum is cryptographically signed. But I've never seen people get up in arms about someone publishing, say, a github link to some code that isn't accompanied by a checksum signed with a published PGP key you deem trustworthy.
- jcapote 16y agoRight, because a single git clone can't rm -rf your drive. A single "| sh", can, which is the point.
- tlrobinson 16y agoAnd what's the first thing people do after cloning a project they want to try out? Some might read all of the code, most will just run "./configure" or "make" or "rake" or "script/server" or whatever. All of which can execute arbitrary code. Piping a file to a shell isn't inherently less secure than downloading a zip or cloning a repo and blindly executing something from it. I'm willing to bet the majority of people who are complaining about the "curl URL | sh" trick also regularly download and execute code without verifying it won't own them.
- mukyu 16y agoI was looking for something in the shell script that was nefarious rather than the obvious "explicitly downloading and running things is a bad idea". A good example of the fake downloads can be found with people running ads for VLC that link to their malware/adware invested versions (presumably, I've never actually bothered to investigate them).
- michh 16y agothe user-agent sniffing is a pretty neat trick. if people catch on to that and start checking with curl first, you could even serve the friendly content the first time someone fetches it with curl.