I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script that appears safe.

It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.

  • neidu3@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    edit-2
    22 hours ago

    Running arbitrary text from the internet through an interpreter… what could possibly go wrong.

    I need to set up a website with

    fork while 1
    

    …Just so I can (try to) convince people to

    curl | perl
    

    it

    …rhyme intended.