Why copied terminal commands can be dangerous
Summary
Jann Horn demonstrates how invisible control characters inject extra shell commands when text is copied from a harmless-looking web page. The demonstration uses HTML and CSS. Pasted text can contain additional lines.
Ideas
- A browser selection can put invisible text into the clipboard.
- Control characters trigger commands immediately after pasting.
- What is displayed does not necessarily match the copied bytes.
- Terminal and browser interpret the same content differently.
Insights
- Clipboards cross trust boundaries between parsers.
- Visual inspection does not protect against invisible or reinterpreted characters.
- Convenience can remove confirmation steps unnoticed.
Facts
- The risk concerns interactive shells.
Recommendations
- Paste commands from elsewhere into a text editor first.
- Enable bracketed paste and check your shell supports it.
References
Links to the original source and the Web Archive open in a new tab.