27

Show HN: Mezz, a curl-able WiFi sandbox for IoT pentesting

I was confused what was curl-able about this and it just refers to being installable via “curl | sh”

8 hours agopimlottc

curl | bash and pentesting go well together

6 hours agoredrove

There's no `curl | sh` going on. "curl-able" means what it says: you curl down a single docker-compose file and run `docker compose up`. You don't clone the repo and you don't pipe anything into a shell. The whole point of the project is that it ships as one compose file you can fetch and run, which is why I called it curl-able.

I'm not sure how familiar you are with Docker and Docker Compose, but this is pretty common practice when you want to let people run a whole stack from a single compose file. If you have security concerns, you can (and always should) review the compose file and the Docker images to see what they do. Everything is available in the repo. But to actually run it, one curl is enough.

4 hours agoABGEO

> "curl-able" means what it says: you curl down a single docker-compose file

Are you familiar with the term "download"?

3 hours agothaumasiotes

Uh, being easy to transport makes it portable. "curl-able" is so freaking ambiguous

an hour agoLoganDark

This is very interesting - instead of curl you can integrate https://voiden.md/ maybe.

5 hours agodhruv3006

[dead]

4 hours agoABGEO

Cool stuff! GH star added.

2 hours agobigger_fish

Would be nice to have this for an AP running OpenWRT which should already be 90% of the way.

8 hours agoteiferer

Thanks for the suggestion. If you mean running the project on a "real" router with OpenWRT, then the project is not really for that purpose. OpenWRT already gives you everything you need to achieve the same thing. The idea of Mezz is that it runs on any Linux device, like a laptop or a Raspberry Pi, if you don't have a router or don't want to work with one.