Hacker News new | ask | show | jobs
by hoophoop 2328 days ago
That major point is plain wrong.

https://sysdig.com/blog/friends-dont-let-friends-curl-bash/

https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...

These attacks can be mounted on the network side.

Also you can inadvertently execute data from a benign captive portal or a server error page and so on.

1 comments

I can do similar attacks on ANYTHING in the form of grabbing code and running it on my machine.. If you aren't doing 'curl | bash' recklessly it isn't a problem.