jerry , (edited )
@jerry@infosec.exchange avatar

curl [whatever.ru]| bash

Is a perfectly reasonable way to install software.

planetf1 ,
@planetf1@mastodon.social avatar

@jerry What could possibly go wrong.... That being said it's a popular bootstrap - for example homebrew, rust & many other apps...

JustinDerrick , (edited )
@JustinDerrick@infosec.exchange avatar

@jerry This has always made my skin crawl, especially when prefixed with 'sudo'....

sudo curl https://FMyShitUp.com/ShitMyFUp.sh | sh

EDIT: Had to edit because I never expected that domain to actually exist.

itgrrl ,
@itgrrl@infosec.exchange avatar
b00ga ,
@b00ga@infosec.exchange avatar

@jerry bonus points if it’s:

curl [whatever.ru]| sudo bash

jerry OP ,
@jerry@infosec.exchange avatar

@b00ga the # at the front was intends to denote it running as root. I mean, why not go all the way?

b00ga ,
@b00ga@infosec.exchange avatar

@jerry I _should _ have realized that, but go for the gusto! You don’t expect those top notch security experts to ssh in as root before running their cut-n-paste curl bash, do you?

ParadeGrotesque ,
@ParadeGrotesque@mastodon.sdf.org avatar

@jerry

"Perfectly"

18+ vertana ,
@vertana@infosec.exchange avatar

@jerry Servers can detect when you are using curl like this and serve you different content on the fly.

I’m assuming most of the thread already knows that, but there are tools to help with this issue. Here’s a random one I found: https://github.com/mplewis/shed

So it’s not a great default, but it can be worked with.

michal ,
@michal@kottman.xyz avatar

@jerry You forgot sudo

elusiveman ,
@elusiveman@infosec.exchange avatar

@jerry you forgot the sudo 😝

jerry OP ,
@jerry@infosec.exchange avatar

@elusiveman the “#” was supposed to denote it running as root

elusiveman ,
@elusiveman@infosec.exchange avatar

@jerry OK, way ahead of me, I see 😄

iagox86 ,
@iagox86@infosec.exchange avatar

@jerry Make sure it starts with http://

gary_alderson ,
@gary_alderson@infosec.exchange avatar

@jerry and always manage your bank account from your phone - perhaps the most important security tip

Andres ,
@Andres@mastodon.hardcoredevs.com avatar

@jerry
It always inspire so much confidence.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines