Slacker News Slacker News logo featuring a lazy sloth with a folded newspaper hat
  • top
  • new
  • show
  • ask
  • jobs
Library
← Back to context

Comment by jamescostian

7 years ago

This is immune to the attack:

    bash -c "$(curl -sSLf $URL)"

The key is to download first and then run

2 comments

jamescostian

Reply

benchaney  7 years ago

Or better yet:

curl $URL

less $FILE

bash $FILE

This attack only works at all if you download something and execute it immediately without looking at it.

arendtio  7 years ago

Do you know if

  . <(curl -sL $url)

works (sourcing from a Process Substitution)?

Slacker News

Product

  • API Reference
  • Hacker News RSS
  • Source on GitHub

Community

  • Support Ukraine
  • Equal Justice Initiative
  • GiveWell Charities