• flyingSock@feddit.org
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    This type of attack is also a risk for novice linux users, who tend to paste things in the terminal they do not understand.

    • Akasazh@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      As a novice linux user, how can I avoid this?

      I try to avoid running terminal code, but sometimes it is the only way to get things to work.

      • Limerance@piefed.social
        link
        fedilink
        English
        arrow-up
        3
        ·
        37 minutes ago

        Look at a terminal command and try to understand what it does. You can do this by checking out the commands it’s made of and learning about them.

      • flyingSock@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        ·
        36 minutes ago

        Verify the commands by looking them up in the docimentation. So if the advice is to run foo --bar afile first do man foo or foo --help and check what the command does and what option --bar does.

        Good documentation, i esepicially like the gentoo docs and also the arch docs for this, will specifically say run this command where these options are added to do a thing.

        Don’t run anything where you don’t know what it will do based on the docukentation, so not based on the surrounding text where you are copying froom saying trust me bro.

        But of course this can end up being a lot of effort and is just a long way of saing rtfm.

        • Akasazh@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          27 minutes ago

          Thanks for the summary. I need to look into this, but as a filthy casual it looks a bit daunting.

          Still I love having transitioned but some aspects still feel a bit scary.

      • Horse {they/them}@lemmygrad.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        35 minutes ago

        little tip:
        if it contains wget or curl then it’s downloading something, check that it’s both necessary and the url isn’t suspicious

        just realized you’re a .worlder and can’t see this, but fuck it, might be useful for someone else