3 ms·
Is that bad?
by syncbehind 4y ago
Is that bad?
- 10000truths 4y agoNo worse than downloading a pre-built binary off the internet and running it.
- chunk_waffle 4y agoIf you follow that to it's logical conclusion then "everything is terrible and nothing is secure" (which is probably the reality) My personal gripe with piping curl output to sh is about expectations. If I have some binary I'm running, I have _some_ expectations about what it will do, same for a Makefile, and RPM, etc. None of those things are guaranteed to do what they're supposed to but I have some idea what _should_ happen. Unless I read through the script, I have less expectations about what the script is going to do. It says it will install my program but is it going to pull in dependencies from my package manager? Download and compile something, shove binaries in my $PATH, edit dot files in $HOME?
- gowld 4y agoMakefile, RPM , and shell all essentially do the same thing and have the same power to violate your system.
- chunk_waffle 4y agoTo re-iterate, for me its not really about the potential for abuse, its more about expectations. You can abuse anything (though I'd also argue that signed packages from companies like RedHat and Canonical are usually up to a higher standard than the random Shell script plucked from the internet.) If someone places a shoe box on your doorstep you might expect shoes to be inside. Of course, there's a non zero chance its full of bees. But shoes are a reasonable guess. If someone places a cardboard box on your doorstep with no writing on it whatsoever, there's no expectation about whats in the box. (Unless you hear the bees buzzing from a distance.)
- eyelidlessness 4y agoExcept it's been demonstrated you can detect a pipe to shell server-side.
- antx 4y agoThe most probable issue related to this kind of behaviour is pastejacking. It's possible for the server to detect that you're actually using curl (with the help of the user agent of other methods) and also that you're piping it to an interpreter. Knowing that, the server could send you a malicious payload, that wouldn't be apparent when only downloading the file otherwise. Some people think this isn't the real issue, that (the lack of) code signing is the real problem. I don't disagree with that, but really, people should look at the code they're going to execute, whenever possible. And when I say "whenever possible", I sure believe a few lines of shell script deserves to be inspected. Even if you lose the 0.5 seconds of automation the pipe provided. I mean, we're not talking about millions of lines of kernel code, here.
- turboponyy 4y agoHow can the server tell whether you're just curling or curling and piping that output to an interpreter?
- franga2000 4y agoWeird timing magic, if I recally correctly: https://news.ycombinator.com/item?id=17636032 https://news.ycombinator.com/item?id=17636032