Post #2426759
2025-07-17 11:46 UTC
@agowa338@chaos.social @filippo@abyssdomain.expert I've thought the same. This has a PoC: https://lukespademan.com/blog/the-dangers-of-curlbash/
Replies (1)
-
@agowa338@chaos.social 2025-07-17 11:52
@fooker@corteximplant.com @filippo@abyssdomain.expert Interesting, now I've to think what if they'd send you a different script when they detect this? Like one that is just designed to waste your time as a security researcher but does nothing. Combined with just sending a malicious script to a fraction of the victims would probably make it quite hard for researchers. Or imagine you make this look like a legit service and 1/10th of the users running it get malwared 🤔