7 ms·
> sophisticated enough to send different contents to a browser and to curl Checking the Accept header (or User-Agent or a bunch of other things) is very diffic
by Repulsion9513 2y ago
> sophisticated enough to send different contents to a browser and to curl
Checking the Accept header (or User-Agent or a bunch of other things) is very difficult :)
- soraminazuki 2y agoGP likely meant differentiating `curl` and `curl | bash`. https://web.archive.org/web/20240520142212/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://web.archive.org/web/20240520142212/https://www.idont...
- Repulsion9513 2y agoDid they? IDK, just differentiating browser from curl is incredibly likely to be "good enough" as an attacker.
- Dylan16807 2y agoI did have that attack in mind, yes. But honestly it doesn't take a lot of sophistication to hide an exploit somewhere in an entire piece of software. The average person is very vulnerable to a malicious dev and the way they download is very unlikely to matter as long as it's not http:// http://