3 ms·
It can be detected if your adversaries are clever enough: https://lukespademan.com/blog/the-dangers-of-curlbash/ https://lukespademan.com/blog/the-dangers-of-cu
by posnet 3y ago
It can be detected if your adversaries are clever enough: https://lukespademan.com/blog/the-dangers-of-curlbash/ https://lukespademan.com/blog/the-dangers-of-curlbash/
- thinkmassive 3y agoCongrats, you just defeated the attack by manually downloading the script before running it!
- post- 3y agoTbh, I’m put on more on alert by the spelling errors in the linked post than I am by the ostensible threat of a server timing my requests in order to serve malware. It’s good practice to check anything that you’ll pipe to `sudo`, but this article’s level of paranoia is kind of self-defeating, no? At some point, we all trust the things we run on our machines. We rely on communities — and our participation in them — to vet installations. There is no perfect solution. Someone will always be misled.