[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: HELIX and potato



Hi Johann,

Quoth Johann Spies, 
> Excuse my ignorance, but after reading lynx's man page, I still do not
> understand what is actually happening in a command like this or let me
> put it this way: I do not understand how it can help to install
> helix-gnome or why it has to be run as root.  As I understand it 
> lynx is passing the html-source from go-gnome.org to bash.  Why would
> one like to do it and why is it a security risk?  Is it because it is
> run as root?

If you have a look at that page using a web browser, you'll see it's
just a bourne shell script. Thus you are using lynx to pipe the shell
script contained on the web page to STDOUT through the shell.

So what you are essentially doing is running the shell script contained
on that web site as root.

This is exactly the same as downloading the page (using wget or
something), saving it to a file, setting the executable bit, and running
it as root.

HTH,

damon

-- 
Damon Muller              | Did a large procession wave their torches
Criminologist/Linux Geek  | As my head fell in the basket,
http://killfilter.com     | And was everybody dancing on the casket...
PGP (GnuPG): A136E829     |                      - TBMG, "Dead"

Attachment: pgpmmxqD2B0Ln.pgp
Description: PGP signature


Reply to: