Don't copy-paste commands from webpages – you can get hacked
bleepingcomputer.com
bleepingcomputer.com
https://news.ycombinator.com/item?id=24797720
You can mostly avoid this problem with a little configuration if bracketed-paste-mode isn't default on whatever you're using.
Make sure it's supported and/or active on your terminal (e.g. urxvt, xterm) and the CLI/TUI programs (e.g. vim, bash/libreadline) on which you want to paste.
At the link above is a link to an SE answer I wrote years ago:
https://security.stackexchange.com/questions/39118/how-can-i...
It has a table showing what terminals support bracketed paste mode, and also provides a urxvt plugin to fix a bug in urxvt's implementation.
<pre>echo 'normal code, nothing to see here :)'<span style="color:transparent;font-size:0">; echo 'evil stuff'</span>
echo 'nothing suspicious at all :)'</pre>Like do they just smash ctrl+v//enter super fast? Why would anyone do that
Always have them show you exactly what they did. No descriptions of what they did, let them show you. Yes, do ask the obvious 'did you replace the placeholders?' question.
Very common answer: 'What placeholders?'
> Not only do you get a completely different command present on your clipboard, but to make matters worse, it has a newline (or return) character at the end of it.
> This means the above example would execute as soon as it's pasted directly into a Linux terminal.