5 ms·
Ask HN: Why is curl | sh so frowned upon?
I'd like to know why curl | sh is so frowned upon on community forums. Is the risk of being compromised with curl | sh higher than wget; sh?
When I install software the normal way (without curl | sh), I don't audit the complete source code of the software anyway. So in either case I have to trust the domain that is serving me the software.
Then if curl | sh is frowned upon, should wget and sh and other ways of installing software be also frowned upon?
- jjgreen 3y agoBecause the use of "piping to a shell" can be detected server-side, so if compromised, it can serve hostile code only in that case. And you don't have a record of that hostile code. I'd like to know why curl | sh is so frowned upon on community forums. That depends on the community, mentioning that Rust encourages the practice will typically earn downvotes on this list.
- Someone 3y ago> Because the use of "piping to a shell" can be detected server-side AFAIK, it’s not “piping to a shell” that can be detected, but the use of curl. That is trivial to do by looking at the user agent string. I don’t know whether it can also be done if that is spoofed using -A "user agent". Doing that makes that curl | sh command a lot less nice, though.
- jjgreen 3y agoIn fact one does not need the user-agent to detect curl | sh, details here https://web.archive.org/web/20230325190353/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://web.archive.org/web/20230325190353/https://www.idont... [original article has an expired cert]
- borplk 3y agoIt can be detected even without looking at the user agent (as another user mentioned). They typically rely on the fact that the downloaded source code is being executed as it is being downloaded so you can leave things like "sleep 5" and detect the delay in fetching from the client. The best thing to do is to download first and then execute. Also good installer scripts first define a function and then call the function at the very end of the script so that they don't half-execute some function in case the network connection is disrupted.
- dkga 3y agoSo curl specifically transmits to the server what its terminal call was (including post-curl steps via piping)?
- earthling8118 3y agoI am a major proponent of Rust and definitely push for it. However rustup's installation method is somewhat of a disgrace in my opinion. I don't use rustup at all and use nix instead (yes, I'm that guy).
- gryfft 3y agoEven if you don't actually audit the source, you can at least check the checksums. A malicious host (or a malicious actor who has compromised a trusted host) can detect that you're piping to bash in a few ways, and then by modifying the response, they're executing commands undetectably outside your shell history, potentially setting up reverse shells, installing rootkits etc. If you're doing it in a sealed environment... Still yikes honestly. I would prefer acquiring software from auditable sources.
- lesserknowndan 3y agoYou can also run the script as an unprivileged user (nobody) and see what privilege related errors occur.
- johnklos 3y agoThink about it: if you don't see, can't see, and have no record about what's run (because what's downloaded abd run isn't saved), you're just making your computer untrustworthy, especially if you're piping to a root shell. At least if you download the file before you run it, you can check the checksum / do a sanity check of the file before you run it, as others have mentioned. But nobody is saying or has ever said that it has anything at all to do with the download tool. Piping wget versus curl makes zero difference. Also, suggesting that installing via sh is a related issue is completely incorrect thinking. You might as well suggest that using a keyboard on your computer can be frowned upon since doing things on a keyboard could lead to compromise. The statement is true, but ridiculous and not helpful.
- hayst4ck 3y agoI don't think I would ever do that in a production environment. Maybe on my personal laptop. It's just not great from a security and trust point of view. It's also important to remember that bit-squatting is a thing, and just because you think you're making a request to github.com doesn't mean you are, a bit might flip from gamma rays or heat and you end up requesting a shell script from jithub that can now straight own your machine. Use an `http` url or ignore cert warnings? the great firewall of china or someone who's owned the cafe you are sitting in can own your machine. It also sidesteps the hygiene of checksumming the resources you download to ensure that the thing you downloaded is what you expected to download. copy pasting things from the web and putting them on your terminal is also considered insecure: https://www.wizer-training.com/blog/copy-paste https://www.wizer-training.com/blog/copy-paste That's also ignoring that you can curl the wrong url and then pass a whole lot of crap to sh. Here's a HN post on the topic that doesn't necessarily agree with me: https://news.ycombinator.com/item?id=12766049 https://news.ycombinator.com/item?id=12766049