Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
rascul
on Dec 27, 2022
|
parent
|
context
|
favorite
| on:
Detecting the use of “curl | bash” server side (20...
How would it become truncated?
bqmjjx0kac
on Dec 27, 2022
|
next
[–]
A cat unplugs the router?
layer8
on Dec 27, 2022
|
parent
|
next
[–]
When a dog does it, would it be trundoged instead?
fathyb
on Dec 27, 2022
|
prev
|
next
[–]
In the case of curl it can happen if the server did not use Content-Length and the connection gets closed.
Arnavion
on Dec 27, 2022
|
parent
|
next
[–]
All the presence of the content-length header would do is change curl's exit code when the connection breaks. The part where curl output the truncated script and bash executed it would be unchanged.
Arnavion
on Dec 27, 2022
|
prev
[–]
The whole context of this conversation is >If the connection fails for any reason, the script will stop, potentially breaking or corrupting things.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: