The Underhanded C Contest was a programming contest to turn out code that is malicious, but passes a rigorous inspection, and looks like an honest mistake. The contest rules define a task, and a malicious component. Entries must perform the task in a malicious manner as defined by the contest, and hide the malice.
That's accomplished by the author publishing a sha256 hash and me following this workflow:
curl http://scriptname > scriptname.foo
sha256 scriptname # visually verify that it looks right from the web site
chmod 755
./scriptname.foo
Of course, if I'm downloading from an untrusted source, I review the script and any commands I miss.Note that, e.g., Calibre, has their Linux update procedure to be as follows[1]:
sudo python -c "import sys; py3 = sys.version_info[0] > 2; u = __import__('urllib.request' if py3 else 'urllib', fromlist=1); exec(u.urlopen('http://status.calibre-ebook.com/linux_installer').read()); main()"
I'm sorry, but I don't see any verifications that calibre has not been rooted and malware installed. It's not HTTPS either, so I won't even get an SSL warning for a MITM attack.To decode the Python: that command/script downloads a script from the internet without verification, and executes it as root.
I could download their install script, read it through and then proceed to run it
or,
Since I'm trusting rvm not to do any harm in the first place, I might as well use their handy one-liner and install it in one go. Anything they can do in their one-liner they can do to me when I install rvm anyways.