3 ms·
> curl https://get.volta.sh https://get.volta.sh | bash Anyone doing this after seeing the Codecov hack is asking for pain and suffering. Make sure to read eve
by YPCrumble 5y ago
> curl https://get.volta.sh https://get.volta.sh | bash
Anyone doing this after seeing the Codecov hack is asking for pain and suffering. Make sure to read every line of that script before running it.
- smt88 5y agoThat's not really going to help most people. It's not hard to obfuscate the malicious parts of the script. I remember someone saying that you could essentially backdoor a target machine by rolling back certain libraries by a few weeks to undo security patches. I don't know modern *nix package management well enough to know if that's true, but it's a scary idea.
- jcla1 5y agoIt's not just that, i.e. you may be fooled if you read the script "in the wrong way". https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- runeks 5y agoWhat’s the problem, exactly? I don’t see how this is different from downloading a binary from the get.volta.sh domain and running it.