if 'curl' in request.UA:
return 'something malicious'
else:
return 'something nice'
Always create a local file with the content, read it, then perhaps run it. if 'curl' in request.UA:
return 'something malicious'
else:
return 'something nice'
Always create a local file with the content, read it, then perhaps run it. curl example.org | vipe | bash -
Which opens vim in the middle there.https://ma.ttias.be/terminal-escape-sequences-the-new-xss-fo...
wget -qO- 'http://example.com/script.sh' | less
won't work to review the script?As other have suggested, there are still possible ways to trick you, but it's getting more and more remote.
Browser exploit kits commonly will return different stuff depending on user agent, and will track what IPs they have interacted with so that if after someone clicks the link you try to look at it, you'll get something harmless. Nasty business. The only way to be sure is to save it, inspect what you saved (make sure you use something that will show tricky escape sequences trying to hide things), then maybe run it.
There are any number of scenarios where any given solution could be broken. Why not point out that you OS might be compromised and the wget/curl binary that you're using is patched to present the wrong information to you?