ブックマーク / www.djm.org.uk (1)

  • The hidden dangers of piping curl

    Unless you haven't been installing developer focused 3rd party software recently, you will probably have seen the following command line used as a suggested way of installing a particular software package direct from the web: This post is not here to debate whether or not this is a good idea but rather to make those that use this pattern aware of a non-obvious flaw, aside from all the obvious issu

    tmatsuu
    tmatsuu 2014/10/13
    curl <url> | shは不正なプログラムに書き換えられていた場合に危険なので、実行されるスクリプトを必ず確認するようにしましょう。vipe知らなかった。
  • 1