Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Register
  • Sign in
  • V vte
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 363
    • Issues 363
    • List
    • Boards
    • Service Desk
    • Milestones
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Artifacts
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Container Registry
    • Model experiments
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GNOMEGNOME
  • vte
  • Issues
  • #92

Prevent Pastejacking: attacks on users via copy & pasting

See http://thejh.net/misc/website-terminal-copy-paste and https://github.com/dxa4481/Pastejacking. (Overview article also here)

I don't know whether this has already been discussed before (think so, but could not find anything in GitLab).

In my tests, it did not work with zsh and GNOME Terminal, but with bash the examples did work.

Solution

Maybe as shown here you can do it like iTerm and display a warning if a "suspicious" command is pasted. (One with newlines or so)

At least as an optional security feature, it would be very nice.

Edited Feb 09, 2019 by rugk
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking