hrbrmstr,
@hrbrmstr@mastodon.social avatar

Thanks to the great work by @klmr & @idavydov I've put together this repo: https://github.com/hrbrmstr/rdaradar that will help sanity check R data files in as safe a way as possible.

It's super basic and I'm rly tight on time this week, so issues (and, eventual PRs) are welcome.

You're still better off not trusting R data files not created by you.

cc: @AlexandreSieira

frod_san,
@frod_san@ecoevo.social avatar

@hrbrmstr

Nice! Thanks so much.

I was thinking of potentially running that script as another check within the {safeinstall} package (https://github.com/Pakillo/safeinstall). Does that sound like a good idea to you? Or better just warn that rds/rda files have been found, and point users to your repo?

hrbrmstr,
@hrbrmstr@mastodon.social avatar

@frod_san i think that’d be a super cool enhancement to {safeinstall}!

hrbrmstr,
@hrbrmstr@mastodon.social avatar

I would ask that nobody share the links on Fosstodon if at all possible. Nobody there will see my post or boosts of it, and I kind of want everyone still on that server to suffer b/c of the daft folks who operate that instance.

DataAngler,
@DataAngler@vis.social avatar

@hrbrmstr @klmr @idavydov @AlexandreSieira Holy cow. So if I read this correctly, I could potentially pull down an .rda file and the exploit would go undetected by any antivirus and be activated upon a call to read_rds()?

hrbrmstr,
@hrbrmstr@mastodon.social avatar

@DataAngler @klmr @idavydov @AlexandreSieira "yes” is the quickest answer. Download the rda in that repo, load it and quit R for a demo. Lots of paths for shenanigans.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • slotface
  • kavyap
  • thenastyranch
  • everett
  • tacticalgear
  • rosin
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • InstantRegret
  • Youngstown
  • khanakhh
  • ethstaker
  • JUstTest
  • ngwrru68w68
  • cisconetworking
  • modclub
  • tester
  • osvaldo12
  • cubers
  • GTA5RPClips
  • normalnudes
  • Leos
  • provamag3
  • anitta
  • megavids
  • lostlight
  • All magazines