I've legitimately seen one project that basically says to do that, but with "your ai agent". At least piping to sh is deterministic and, you can pipe to a filw and check the script
you can detect `curl | bash` server-side and serve a different payload for those (compared to curl -O file, wget etc), hence its an effectively undetectable attack vector.
Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.
neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much
(and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)
0: https://news.ycombinator.com/item?id=49297469
https://news.ycombinator.com/item?id=49307700
I wish more people would point this out.
https://github.com/0xeb/ghidrasql
Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.
neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much
(and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)
I giggled.
https://news.ycombinator.com/newsguidelines.html