Post B5ptv9gn3fg4VCfu6K by Zettour@gearlandia.haus
 (DIR) More posts by Zettour@gearlandia.haus
 (DIR) Post #B5pg5ksoEE8zOWSO12 by rysiek@mstdn.social
       3 likes, 3 repeats
       
       A lot of people are apparently happily running a script clearly marked as a root exploit from some random website using curl | bash :blobsweat: Some do inspect the script, but then still run it using curl | bash anyway. :thaenkin: Incidentally, this very relevant blogpost about detecting curl | bash and serving different scripts based on that is almost exactly a decade old:https://web.archive.org/web/20230318063325/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/#CopyFail #InfoSec
       
 (DIR) Post #B5pgAN3gEemAx3k6fQ by mgleadow@mastodon.green
       0 likes, 1 repeats
       
       @rysiek it astounds me that curlbash nonsense still happens
       
 (DIR) Post #B5pgETRYRCnNuerl8y by rysiek@mstdn.social
       0 likes, 0 repeats
       
       @mgleadow "still"? it is going strong! :sadcat1:
       
 (DIR) Post #B5pgETgnWWzMfvzvu4 by mgleadow@mastodon.green
       0 likes, 1 repeats
       
       @rysiek but it was a bad idea 10+ years ago
       
 (DIR) Post #B5pgIpucqCTkl0XmwS by rysiek@mstdn.social
       0 likes, 1 repeats
       
       @mgleadow yes. yes it was. and remains so.
       
 (DIR) Post #B5ptv9gn3fg4VCfu6K by Zettour@gearlandia.haus
       0 likes, 0 repeats
       
       @rysiek Live a little, run strange files as admin
       
 (DIR) Post #B5qoMRci59s9NNM6me by star@amazonawaws.com
       0 likes, 0 repeats
       
       @rysiek what's the issue with doing that? if you expect that command to run an exploit, malware, whateveryouwannacallit, and you are fine with what that may imply, then i don't quite see the issue; i more see an issue with literally any other curl | bash oneliner from random websites