4 ms·
My thing with piping curl to a shell was always that a severed connection will run a partial script, which can have weird consequences. I wrote about it awhile
by bqe 12y ago
My thing with piping curl to a shell was always that a severed connection will run a partial script, which can have weird consequences. I wrote about it awhile back:
http://blog.seancassidy.me/dont-pipe-to-your-shell.html http://blog.seancassidy.me/dont-pipe-to-your-shell.html
- Igglyboo 12y agoWould something like curl http://google.com/keylogger.sh > temp.sh && sh temp.sh work?
- sarciszewski 12y agoMore like: curl http://google.com/keylogger.sh http://google.com/keylogger.sh > temp.sh less temp.sh # actually read the fucking thing sh temp.sh rm temp.sh
- edwintorok 12y agoI'd also check at least the size, and checksum/GPG signature if available.
- dllthomas 12y agoIt avoids that particular problem, yes. It is still inadvisable to do it over http, and checking a digital signature might be even better. Looking at the results might be better still if you have the expertise, though at that point it is more or less isomorphic what everyone happily does in trusting repositories, make files in signed source tarballs, and similar.
- kolev 12y agoI use something different: bash -c "$(curl -sfL git.io/wshare || echo "echo 'Installation failed'; exit 1")" My script itself is the core file and the installer (I used the $BASH_EXECUTION_STRING to grab the source code), i.e. it doesn't download anything additionally. I'm also planning to add a build script that checks the hash of $BASH_EXECUTION_STRING to prevent tampering.