Embed Notice
HTML Code
Corresponding Notice
- Embed this notice> shell scripts looks innocent and can be run
yeah you'd think that Mr. Aboukhadijeh but i'm old enough to remember debian installing 'beep' setuid root with a "it's pretty innocent, the whole program is what 6 lines of code? go read the code and then say yes" warning on install for like a decade that turned out to be a bad idea because those 6 lines of code contained a privilege escalation attack allowing any user on the system to get root access using "beep"