-
Notifications
You must be signed in to change notification settings - Fork 102
Open
Description
http://learn.perl.org/installing/osx.html contains
curl -L http://xrl.us/installperlosx | bash
which is a horrible security anti-pattern.
Yes, it's extremely simple, but we shouldn't be encouraging people to do this without enough warnings to dissuade them. What happens if someone changes where that short link redirects to? What if someone changes the result to do sudo rm -rf /.
VynceMontgomery, tacerus and briandfoy
Metadata
Metadata
Assignees
Labels
No labels