data:image/s3,"s3://crabby-images/1e4ed/1e4eddac879ab199cbe55d538d12881ae28fcb91" alt=""
data:image/s3,"s3://crabby-images/08f3d/08f3d007634a3fc57beba6b33b37bce0e47def92" alt=""
7·
1 month agoAgreed.
Also gtfobins is a great resource in addition to shellcheck to try to make secure scripts.
For instance I felt upon a script like this recently:
#!/bin/bash
# ... some stuff ...
tar -caf archive.tar.bz2 "$@"
Quotes are OK, shellcheck is happy, but, according to gtfobins, you can abuse tar, so running the script like this:
./test.sh /dev/null --checkpoint=1 --checkpoint-action=exec=/bin/sh
ends up spawning an interactive shell…
So you can add up binaries insanity on top of bash’s mess.
Nice! It’s using xclip or xsel to copy magnet links, afaik it’s only working on Xorg. What is the Wayland alternative for xclip?