Anyone that wants to inspect the shell script can amend that line
to first save and view the script.
They can, but they may well not get the same output since, as is well-known, curl | sh can be detected on the server. Anyone that wants to inspect the shell script can amend that line
to first save and view the script.
They can, but they may well not get the same output since, as is well-known, curl | sh can be detected on the server.I'd love to hear the mechanism that the server would use to do that, if you have the time!
Or the script could also signal through an active mechanism, a different innocuous-looking HTTP request that makes the server switch the content to a malicious payload if it happens at the same time.