4 ms·
shoulda used 'cat
by dewlinedew2 6y ago
shoulda used 'cat
- jclulow 6y agoUsing cat with arbitrary input exposes you to many terminal-side security issues. It is insufficiently complex.
- cyberpunk 6y agoSuch as?
- jclulow 6y agoAny vulnerability in the escape sequence handling of the terminal emulator, and conceivably, depending on what sequences your terminal supports, access to facilities like local file generation or clipboard contents. There have been a number of issues with escape sequences injected into things people might copy and paste from a web page, or in git commit histories, that have done nefarious things.
- edgyquant 6y agoCat has long been known to expose you to code execution, among other things. https://security.stackexchange.com/questions/56307/can-cat-ing-a-file-be-a-potential-security-risk https://security.stackexchange.com/questions/56307/can-cat-i...
- cyphar 6y agoAlternatively use "cat -v" and any terminal escape characters will be escaped.
- bawolff 6y agoIt can do some sketchy things and rewrite your terminal in weird confusing ways, but afaik most of the out-and-out malicious escape sequences have been patched out at least a decade ago.
- aruggirello 6y agothat wouldn't work nicely with the mouse :)
- zrobotics 6y agoThat's what the on-screen keyboard is for. Even works with the touchscreen, no mouse required! Eminently usable.