I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script that appears safe.
It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.
I set up a quick demonstration to show risks of curl|bash and how a bad-actor could potentially hide a malicious script that appears safe.
It’s nothing new or groundbreaking, but I figure it never hurts to have another reminder.
Signatures do not help if your distribution infra gets compromised. See Solarwinds and the more recent node.js incidents.
Please tell me you are not seriously equating a highly sophisticated attack line the Solarwind compromise with piping curl to bash?