Hacker News new | ask | show | jobs
by codeguy 5102 days ago
haha. Always good advice. But I checked. It's fine :)
1 comments

It's fine now until someone hacks their site or poisons their DNS.
Or writes a script which checks the user agent and only serves up malware to curl.

Or the second time that an IP address hits it.

Or something else that you haven't thought of.

Update: Such as doing something nasty to http://getcomposer.org/composer.phar instead - a 520KB php file that the first script downloads and runs without even md5ing first. Did you audit that too? Did you understand everything that it was doing?

Or social engineers their registrar and changes their dns.