← Back to context

Comment by ffsm8

7 hours ago

You can detect the use of curl|bash server side, hence it's an essentially undetectable attack vector. People have shown poc attacks of that kind all the way back in the 2010s

https://news.ycombinator.com/item?id=17636032

The original blog is no longer available though.

But I've not had that stop me from doing that myself, I am more towards the "I like easy" then the "I want to be secure" crowd

How would you do that? Just rely on the user agent? I use curl quite a lot, but don't pipe to a shell.