Skip to main content


A lot of people are apparently happily running a script clearly marked as a root exploit from some random website using curl | bash :blobsweat:

Some do inspect the script, but then still run it using curl | bash anyway. :thaenkin:

Incidentally, this very relevant blogpost about detecting curl | bash and serving different scripts based on that is almost exactly a decade old:
web.archive.org/web/2023031806…

#CopyFail #InfoSec