Closed Bradisverycool closed 1 month ago
um
Sorry - I reviewed the commit and noted that it downloads and executes anonymous code from someone else's account as root.
curl -fsSL https://raw.githubusercontent.com/Bradisverycool/BradTV/refs/heads/main/P2Install.sh | sudo bash
this could be used to inject almost anything into the users system. Is there a way to do this using only public packages from known sources (pypy etc)?
thats my account
That was a lot of work.