3 ms·
> curl -sL -H "Accept: text/roff" https://jamesg.blog/2024/02/28/programming-projects/ https://jamesg.blog/2024/02/28/programming-projects/ > post.page && man .
by Crestwave 3y ago
> curl -sL -H "Accept: text/roff" https://jamesg.blog/2024/02/28/programming-projects/ https://jamesg.blog/2024/02/28/programming-projects/ > post.page && man ./post.page && rm post.page
What if I have a post.page in my current directory?
> curl -sL -H "Accept: text/roff" https://jamesg.blog/2024/02/28/programming-projects/ https://jamesg.blog/2024/02/28/programming-projects/ > /tmp/post.page && man /tmp/post.page
What if another user runs the command at the same time, then?
Or what if a malicious user creates a 666 mode /tmp/post.page file beforehand, detects when you finish writing to it, then attaches a payload right before `man` reads it?
Unfortunately, there is no perfect solution for this problem; I run arbitrary html, css, and javascript every day by browsing the web. It's debatable whether switching to command chains instead of piping results in overall benefits. Of course, the same goes for vice versa as well.
- godelski 3y agoSure, but aren't you being pedantic at this point? If you're that concerned, add a small random number. But of course there's no perfect solution. But we still are mitigating the main concerns.