Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
curl
35 Indlæg 26 Posters 113 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • tux0r@layer8.spaceT tux0r@layer8.space

    @larsmb Also, curl should require sudo!

    larsmb@mastodon.onlineL This user is from outside of this forum
    larsmb@mastodon.onlineL This user is from outside of this forum
    larsmb@mastodon.online
    wrote sidst redigeret af
    #4

    @tux0r You mean "--install --force"? Yes.

    1 Reply Last reply
    0
    • larsmb@mastodon.onlineL larsmb@mastodon.online

      I am uncertain if that's the patch I want to be known for though.

      But I have set a reminder for in 32 days.

      henryk@chaos.socialH This user is from outside of this forum
      henryk@chaos.socialH This user is from outside of this forum
      henryk@chaos.social
      wrote sidst redigeret af
      #5

      @larsmb You could then extend https://xkcd.com/1654/ with `curl --install "https://get${1}.dev/install.sh" &`

      benedikt_lauenburg@norden.socialB 1 Reply Last reply
      0
      • larsmb@mastodon.onlineL larsmb@mastodon.online

        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

        Finally a truly universal installer.

        vyskocilm@witter.czV This user is from outside of this forum
        vyskocilm@witter.czV This user is from outside of this forum
        vyskocilm@witter.cz
        wrote sidst redigeret af
        #6

        @larsmb
        --insecure is implicit in this mode, correct?

        larsmb@mastodon.onlineL 1 Reply Last reply
        0
        • vyskocilm@witter.czV vyskocilm@witter.cz

          @larsmb
          --insecure is implicit in this mode, correct?

          larsmb@mastodon.onlineL This user is from outside of this forum
          larsmb@mastodon.onlineL This user is from outside of this forum
          larsmb@mastodon.online
          wrote sidst redigeret af
          #7

          @vyskocilm Snark aside, with "https" probably as (in)secure as getting the respective package from any community distribution.

          1 Reply Last reply
          0
          • larsmb@mastodon.onlineL larsmb@mastodon.online

            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

            Finally a truly universal installer.

            agowa338@chaos.socialA This user is from outside of this forum
            agowa338@chaos.socialA This user is from outside of this forum
            agowa338@chaos.social
            wrote sidst redigeret af
            #8

            @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

            pianosaurus@c.imP 1 Reply Last reply
            0
            • larsmb@mastodon.onlineL larsmb@mastodon.online

              Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

              Finally a truly universal installer.

              totenlegionchris@metalhead.clubT This user is from outside of this forum
              totenlegionchris@metalhead.clubT This user is from outside of this forum
              totenlegionchris@metalhead.club
              wrote sidst redigeret af
              #9

              @larsmb This should work fine with openclaw!! You are ahead of the time.

              1 Reply Last reply
              0
              • henryk@chaos.socialH henryk@chaos.social

                @larsmb You could then extend https://xkcd.com/1654/ with `curl --install "https://get${1}.dev/install.sh" &`

                benedikt_lauenburg@norden.socialB This user is from outside of this forum
                benedikt_lauenburg@norden.socialB This user is from outside of this forum
                benedikt_lauenburg@norden.social
                wrote sidst redigeret af
                #10

                @henryk @larsmb misses an ai api call.

                1 Reply Last reply
                0
                • larsmb@mastodon.onlineL larsmb@mastodon.online

                  Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                  Finally a truly universal installer.

                  heiglandreas@phpc.socialH This user is from outside of this forum
                  heiglandreas@phpc.socialH This user is from outside of this forum
                  heiglandreas@phpc.social
                  wrote sidst redigeret af
                  #11

                  @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

                  pianosaurus@c.imP 1 Reply Last reply
                  0
                  • larsmb@mastodon.onlineL larsmb@mastodon.online

                    Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                    Finally a truly universal installer.

                    moritzboth@chaos.socialM This user is from outside of this forum
                    moritzboth@chaos.socialM This user is from outside of this forum
                    moritzboth@chaos.social
                    wrote sidst redigeret af
                    #12

                    @larsmb better naming: "--submit" or "--infect"

                    1 Reply Last reply
                    0
                    • larsmb@mastodon.onlineL larsmb@mastodon.online

                      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                      Finally a truly universal installer.

                      l29ah@qoto.orgL This user is from outside of this forum
                      l29ah@qoto.orgL This user is from outside of this forum
                      l29ah@qoto.org
                      wrote sidst redigeret af
                      #13

                      @larsmb This is much longer to type than |sh -

                      1 Reply Last reply
                      0
                      • larsmb@mastodon.onlineL larsmb@mastodon.online

                        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                        Finally a truly universal installer.

                        aspragg@ohai.socialA This user is from outside of this forum
                        aspragg@ohai.socialA This user is from outside of this forum
                        aspragg@ohai.social
                        wrote sidst redigeret af
                        #14

                        @larsmb Bonus, it would stop people getting confused from typing `sudo curl $URL | sh -` instead of `curl $URL | sudo sh -`

                        ...nope, still nope! 😆

                        1 Reply Last reply
                        0
                        • larsmb@mastodon.onlineL larsmb@mastodon.online

                          Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                          Finally a truly universal installer.

                          agateau@mastodon.xyzA This user is from outside of this forum
                          agateau@mastodon.xyzA This user is from outside of this forum
                          agateau@mastodon.xyz
                          wrote sidst redigeret af
                          #15

                          @larsmb What could possibly go wrong? 🙂

                          1 Reply Last reply
                          0
                          • tux0r@layer8.spaceT tux0r@layer8.space

                            @larsmb Also, curl should require sudo!

                            ozzelot@mstdn.socialO This user is from outside of this forum
                            ozzelot@mstdn.socialO This user is from outside of this forum
                            ozzelot@mstdn.social
                            wrote sidst redigeret af
                            #16

                            @tux0r
                            doas users made a sad face. all five of us.
                            @larsmb

                            tux0r@layer8.spaceT 1 Reply Last reply
                            0
                            • larsmb@mastodon.onlineL larsmb@mastodon.online

                              Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                              Finally a truly universal installer.

                              amenonsen@mastodon.socialA This user is from outside of this forum
                              amenonsen@mastodon.socialA This user is from outside of this forum
                              amenonsen@mastodon.social
                              wrote sidst redigeret af
                              #17

                              @larsmb Or `curl --bash`

                              1 Reply Last reply
                              0
                              • ozzelot@mstdn.socialO ozzelot@mstdn.social

                                @tux0r
                                doas users made a sad face. all five of us.
                                @larsmb

                                tux0r@layer8.spaceT This user is from outside of this forum
                                tux0r@layer8.spaceT This user is from outside of this forum
                                tux0r@layer8.space
                                wrote sidst redigeret af
                                #18

                                @ozzelot @larsmb (sad pfexec noises)

                                1 Reply Last reply
                                0
                                • agowa338@chaos.socialA agowa338@chaos.social

                                  @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

                                  pianosaurus@c.imP This user is from outside of this forum
                                  pianosaurus@c.imP This user is from outside of this forum
                                  pianosaurus@c.im
                                  wrote sidst redigeret af
                                  #19

                                  @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                                  mrshark@mathstodon.xyzM 1 Reply Last reply
                                  0
                                  • heiglandreas@phpc.socialH heiglandreas@phpc.social

                                    @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

                                    pianosaurus@c.imP This user is from outside of this forum
                                    pianosaurus@c.imP This user is from outside of this forum
                                    pianosaurus@c.im
                                    wrote sidst redigeret af
                                    #20

                                    @larsmb @heiglandreas Let's just do a Microsoft, and ship every OS with something that isn't curl aliased as curl.

                                    1 Reply Last reply
                                    0
                                    • larsmb@mastodon.onlineL larsmb@mastodon.online

                                      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                      Finally a truly universal installer.

                                      fargate@tech.lgbtF This user is from outside of this forum
                                      fargate@tech.lgbtF This user is from outside of this forum
                                      fargate@tech.lgbt
                                      wrote sidst redigeret af
                                      #21

                                      @larsmb This is a plan without a flaw nor any possibility of error!

                                      1 Reply Last reply
                                      0
                                      • pianosaurus@c.imP pianosaurus@c.im

                                        @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                                        mrshark@mathstodon.xyzM This user is from outside of this forum
                                        mrshark@mathstodon.xyzM This user is from outside of this forum
                                        mrshark@mathstodon.xyz
                                        wrote sidst redigeret af
                                        #22

                                        @pianosaurus @larsmb @agowa338

                                        I think RFC 3514 "The Security Flag in the IPv4 Header" have place here.

                                        https://www.rfc-editor.org/rfc/rfc3514

                                        1 Reply Last reply
                                        0
                                        • tux0r@layer8.spaceT tux0r@layer8.space

                                          @larsmb Also, curl should require sudo!

                                          busterb@infosec.exchangeB This user is from outside of this forum
                                          busterb@infosec.exchangeB This user is from outside of this forum
                                          busterb@infosec.exchange
                                          wrote sidst redigeret af
                                          #23

                                          @larsmb @tux0r you don't have curl setuid root already?

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper