logoalt Hacker News

ffsm8 • yesterday at 3:43 PM • 2 replies • view on HN

You can detect the use of curl|bash server side, hence it's an essentially undetectable attack vector. People have shown poc attacks of that kind all the way back in the 2010s

https://news.ycombinator.com/item?id=17636032

The original blog is no longer available though.

But I've not had that stop me from doing that myself, I am more towards the "I like easy" then the "I want to be secure" crowd


Replies

throooooo • yesterday at 5:58 PM

How would you do that? Just rely on the user agent? I use curl quite a lot, but don't pipe to a shell.