> sophisticated enough to send different contents to a browser and to curl
Checking the Accept header (or User-Agent or a bunch of other things) is very difficult :)
Checking the Accept header (or User-Agent or a bunch of other things) is very difficult :)
https://web.archive.org/web/20240520142212/https://www.idont...
But honestly it doesn't take a lot of sophistication to hide an exploit somewhere in an entire piece of software. The average person is very vulnerable to a malicious dev and the way they download is very unlikely to matter as long as it's not http://