Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
curl
35 Indlæg 26 Posters 113 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • larsmb@mastodon.onlineL larsmb@mastodon.online

    I am uncertain if that's the patch I want to be known for though.

    But I have set a reminder for in 32 days.

    henryk@chaos.socialH This user is from outside of this forum
    henryk@chaos.socialH This user is from outside of this forum
    henryk@chaos.social
    wrote sidst redigeret af
    #5

    @larsmb You could then extend https://xkcd.com/1654/ with `curl --install "https://get${1}.dev/install.sh" &`

    benedikt_lauenburg@norden.socialB 1 Reply Last reply
    0
    • larsmb@mastodon.onlineL larsmb@mastodon.online

      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

      Finally a truly universal installer.

      vyskocilm@witter.czV This user is from outside of this forum
      vyskocilm@witter.czV This user is from outside of this forum
      vyskocilm@witter.cz
      wrote sidst redigeret af
      #6

      @larsmb
      --insecure is implicit in this mode, correct?

      larsmb@mastodon.onlineL 1 Reply Last reply
      0
      • vyskocilm@witter.czV vyskocilm@witter.cz

        @larsmb
        --insecure is implicit in this mode, correct?

        larsmb@mastodon.onlineL This user is from outside of this forum
        larsmb@mastodon.onlineL This user is from outside of this forum
        larsmb@mastodon.online
        wrote sidst redigeret af
        #7

        @vyskocilm Snark aside, with "https" probably as (in)secure as getting the respective package from any community distribution.

        1 Reply Last reply
        0
        • larsmb@mastodon.onlineL larsmb@mastodon.online

          Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

          Finally a truly universal installer.

          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.socialA This user is from outside of this forum
          agowa338@chaos.social
          wrote sidst redigeret af
          #8

          @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

          pianosaurus@c.imP 1 Reply Last reply
          0
          • larsmb@mastodon.onlineL larsmb@mastodon.online

            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

            Finally a truly universal installer.

            totenlegionchris@metalhead.clubT This user is from outside of this forum
            totenlegionchris@metalhead.clubT This user is from outside of this forum
            totenlegionchris@metalhead.club
            wrote sidst redigeret af
            #9

            @larsmb This should work fine with openclaw!! You are ahead of the time.

            1 Reply Last reply
            0
            • henryk@chaos.socialH henryk@chaos.social

              @larsmb You could then extend https://xkcd.com/1654/ with `curl --install "https://get${1}.dev/install.sh" &`

              benedikt_lauenburg@norden.socialB This user is from outside of this forum
              benedikt_lauenburg@norden.socialB This user is from outside of this forum
              benedikt_lauenburg@norden.social
              wrote sidst redigeret af
              #10

              @henryk @larsmb misses an ai api call.

              1 Reply Last reply
              0
              • larsmb@mastodon.onlineL larsmb@mastodon.online

                Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                Finally a truly universal installer.

                heiglandreas@phpc.socialH This user is from outside of this forum
                heiglandreas@phpc.socialH This user is from outside of this forum
                heiglandreas@phpc.social
                wrote sidst redigeret af
                #11

                @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

                pianosaurus@c.imP 1 Reply Last reply
                0
                • larsmb@mastodon.onlineL larsmb@mastodon.online

                  Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                  Finally a truly universal installer.

                  moritzboth@chaos.socialM This user is from outside of this forum
                  moritzboth@chaos.socialM This user is from outside of this forum
                  moritzboth@chaos.social
                  wrote sidst redigeret af
                  #12

                  @larsmb better naming: "--submit" or "--infect"

                  1 Reply Last reply
                  0
                  • larsmb@mastodon.onlineL larsmb@mastodon.online

                    Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                    Finally a truly universal installer.

                    l29ah@qoto.orgL This user is from outside of this forum
                    l29ah@qoto.orgL This user is from outside of this forum
                    l29ah@qoto.org
                    wrote sidst redigeret af
                    #13

                    @larsmb This is much longer to type than |sh -

                    1 Reply Last reply
                    0
                    • larsmb@mastodon.onlineL larsmb@mastodon.online

                      Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                      Finally a truly universal installer.

                      aspragg@ohai.socialA This user is from outside of this forum
                      aspragg@ohai.socialA This user is from outside of this forum
                      aspragg@ohai.social
                      wrote sidst redigeret af
                      #14

                      @larsmb Bonus, it would stop people getting confused from typing `sudo curl $URL | sh -` instead of `curl $URL | sudo sh -`

                      ...nope, still nope! 😆

                      1 Reply Last reply
                      0
                      • larsmb@mastodon.onlineL larsmb@mastodon.online

                        Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                        Finally a truly universal installer.

                        agateau@mastodon.xyzA This user is from outside of this forum
                        agateau@mastodon.xyzA This user is from outside of this forum
                        agateau@mastodon.xyz
                        wrote sidst redigeret af
                        #15

                        @larsmb What could possibly go wrong? 🙂

                        1 Reply Last reply
                        0
                        • tux0r@layer8.spaceT tux0r@layer8.space

                          @larsmb Also, curl should require sudo!

                          ozzelot@mstdn.socialO This user is from outside of this forum
                          ozzelot@mstdn.socialO This user is from outside of this forum
                          ozzelot@mstdn.social
                          wrote sidst redigeret af
                          #16

                          @tux0r
                          doas users made a sad face. all five of us.
                          @larsmb

                          tux0r@layer8.spaceT 1 Reply Last reply
                          0
                          • larsmb@mastodon.onlineL larsmb@mastodon.online

                            Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                            Finally a truly universal installer.

                            amenonsen@mastodon.socialA This user is from outside of this forum
                            amenonsen@mastodon.socialA This user is from outside of this forum
                            amenonsen@mastodon.social
                            wrote sidst redigeret af
                            #17

                            @larsmb Or `curl --bash`

                            1 Reply Last reply
                            0
                            • ozzelot@mstdn.socialO ozzelot@mstdn.social

                              @tux0r
                              doas users made a sad face. all five of us.
                              @larsmb

                              tux0r@layer8.spaceT This user is from outside of this forum
                              tux0r@layer8.spaceT This user is from outside of this forum
                              tux0r@layer8.space
                              wrote sidst redigeret af
                              #18

                              @ozzelot @larsmb (sad pfexec noises)

                              1 Reply Last reply
                              0
                              • agowa338@chaos.socialA agowa338@chaos.social

                                @larsmb But does it also leak to the server that you're using "--install" and not just try to download the file so that when you're trying to just download the malicious script the server can send you a version without the malware instead?

                                pianosaurus@c.imP This user is from outside of this forum
                                pianosaurus@c.imP This user is from outside of this forum
                                pianosaurus@c.im
                                wrote sidst redigeret af
                                #19

                                @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                                mrshark@mathstodon.xyzM 1 Reply Last reply
                                0
                                • heiglandreas@phpc.socialH heiglandreas@phpc.social

                                  @larsmb 🤣 I was shortly thinking that that is a chicken/egg situation if you want to install cURL via the `--install` option... 🙈

                                  pianosaurus@c.imP This user is from outside of this forum
                                  pianosaurus@c.imP This user is from outside of this forum
                                  pianosaurus@c.im
                                  wrote sidst redigeret af
                                  #20

                                  @larsmb @heiglandreas Let's just do a Microsoft, and ship every OS with something that isn't curl aliased as curl.

                                  1 Reply Last reply
                                  0
                                  • larsmb@mastodon.onlineL larsmb@mastodon.online

                                    Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                    Finally a truly universal installer.

                                    fargate@tech.lgbtF This user is from outside of this forum
                                    fargate@tech.lgbtF This user is from outside of this forum
                                    fargate@tech.lgbt
                                    wrote sidst redigeret af
                                    #21

                                    @larsmb This is a plan without a flaw nor any possibility of error!

                                    1 Reply Last reply
                                    0
                                    • pianosaurus@c.imP pianosaurus@c.im

                                      @larsmb @agowa338 Lets have curl add a "Variant: without_vulnerabilities" header when --install is specified.

                                      mrshark@mathstodon.xyzM This user is from outside of this forum
                                      mrshark@mathstodon.xyzM This user is from outside of this forum
                                      mrshark@mathstodon.xyz
                                      wrote sidst redigeret af
                                      #22

                                      @pianosaurus @larsmb @agowa338

                                      I think RFC 3514 "The Security Flag in the IPv4 Header" have place here.

                                      https://www.rfc-editor.org/rfc/rfc3514

                                      1 Reply Last reply
                                      0
                                      • tux0r@layer8.spaceT tux0r@layer8.space

                                        @larsmb Also, curl should require sudo!

                                        busterb@infosec.exchangeB This user is from outside of this forum
                                        busterb@infosec.exchangeB This user is from outside of this forum
                                        busterb@infosec.exchange
                                        wrote sidst redigeret af
                                        #23

                                        @larsmb @tux0r you don't have curl setuid root already?

                                        1 Reply Last reply
                                        0
                                        • larsmb@mastodon.onlineL larsmb@mastodon.online

                                          Hot take: If we added a "--install" option to #curl, we could optimize many a "| sh -" pipeline away.

                                          Finally a truly universal installer.

                                          cos@sauna.socialC This user is from outside of this forum
                                          cos@sauna.socialC This user is from outside of this forum
                                          cos@sauna.social
                                          wrote sidst redigeret af
                                          #24

                                          @larsmb it should default to sudo to make things easy.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper