Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Did anyone search github yet for similar head | tail tricks ? I doubt it was invented just for this.


I've generally seen this with Unix installers from commercial software vendors.

You get a giant .sh file that displays a license, asks you to accept, then upon acceptance, cats itself, pipes through head/tail, into cpio to extract the actual assets.


It’s clever but not entirely novel, this is kind of the intended usecase for these


The use of head/tail for deobfuscation also isn’t visible as plain text in the repository or release tarball, which makes searching for its use in other repositories more difficult (unless a less obfuscated version was tested elsewhere).


Opportunity to write a paper


Maybe some analysis of odd patterns in entropy of binary files committed to repositories could pick out some to look at a bit deeper?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: