S/party/hack like it's 1999
openwall.com
openwall.com
So you could TYPE (cat) a file and then later press a harmless key like D and ANSI.SYS could output something like whatever the DOS equivalent of "rm -fr /" was (probably DELTREE /Y C:\) as though it had come from your very keyboard.
This was very common in the BBS era. Anti-virus software would usually detect those sequences. People who wanted to look at ANSI art but were aware of this would use alternative ANSI implementations like the one from PC Magazine, which I am a bit surprised to find out can still be downloaded from their website, which also still exists: http://www.pcmag.com/article2/0,2817,5343,00.asp
FORMAT C: /S /U
Good night boot disk.> Hint: > 'less' doesn't interpret escape sequences unless the -r switch is used, > so stop aliasing it to 'less -r' just because there's no colored output.
Instead you can just use `less -R` which allows colored output but doesn't interpret any other escape sequences.
I can't decide whether this is evil, genius or disturbing. I don't typically copy paste curl commands, but it never occurred to me that even if you check the URL curl is pointing to with your browser that's no guarantee that the same script will be downloaded and parsed in the server.
The kind of vulnerabilities that are basically just subverting a user's trust are totally fascinating to me.
s/party/hack/ like it's 1999 s/party/hack/g like it's 1999
...But I supposed we'd be distracting attention away from the point... ;)Anyway, does anyone know of any escape sequences or similar content which would cause GNU or OSX to perform and action? Or, of any buffer-overflow-type scenarios for the escape sequence handlers? (Surely most graphical terminals rely on some well-known library...)
party\033[5D\033[Khack
Not as catchy, though :/NO CARRIER
or:
ATM0
... and watching 10-20-30 people suddenly disappear from the channel as their DOS based comm program passed them as commands directly to the modem.
ATM0 would just silence the speaker. What you want is:
+++ATH0
Wouldn't work on properly implemented modems, as the standard required a quarter (or possibly half) a second pause between the +++ escape, and the hayes command.
Now, you sending this to IRC wouldn't do much at all. What you would want to do was rather take a look at their IP address, and use the "ping -p" command, as that allows you to specify up to 16 bytes padding that will be echoed back. You would then encode +++ATH0 as the pattern, which would be sent back from them to you .. and if it was a silly modem, it would hang up.
Another cool thing, besides icebergs, would be a service checking for escapes given the URL. Or for other caveats (e.g. is the url https? Is it editing weird files (follows list of files))
"'less' doesn't interpret escape sequences unless the -r switch is used, so stop aliasing it to 'less -r' just because there's no colored output."
However, I honestly don't see why I should do something foolish as `curl | sh`, even though from time to time I see websites suggesting this crazy approach. The first thing I think of is "why should I give you control on my shell?".
…I guess, however, this is kind of a natural behavior for the user who doesn't know the shell-fu. I've seen a similar article once about Ubuntu Forums. Unfortunately I can't recall the URL.
col -bx strips nonprintable characters. I have been using this for many years. Especially since the spread of Unicode. As for _viewing_ nonprintable characters, I am a heavy sed user and honestly I rarely use the l command except occassionally to view newlines, tabs and carriage returns. I prefer od or xxd.