I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script that appears safe.

It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.

  • It_Is1-24PM@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    I never thought about opening it in a browser. I always used curl to download such a script and view it where it was supposed to be run.