flawopen.com/command-injection/Ruby
Learn how to fix Command Injection (CWE-78) in Ruby. Side-by-side vulnerable vs secure code examples for Open3.capture2() and system() array arguments.
कल्पना करें कि आप एक सहायक से 'report.pdf' नामक दस्तावेज़ प्रिंट करने के लिए कहते हैं। कमांड इंजेक्शन तब होता है जब कोई फ़ाइल नाम 'report.pdf; whoami' देता है, और सहायक पूरी पर्ची टर्मिनल क्लर्क को सौंप देता है, जिससे रिपोर्ट प्रिंट होने के साथ-साथ व्यवस्थापक का पहचान पत्र भी पढ़ लिया जाता है।
Web Application SecurityCWE-918.CWE-918CWE-918): Standard Common Weakness Enumeration classification for command-injection-ruby.Defense-in-Depthएप्लिकेशन सीधे HTTP अनुरोध से होस्टनाम, फ़ाइल नाम या इनपुट स्वीकार करता है।
बैकएंड सुरक्षित आर्ग्यूमेंट ऐरे के बजाय सीधे स्ट्रिंग जोड़कर शेल कमांड बनाता है।
हमलावर ';', '&&', '|' जैसे शेल मेटाकैरेक्टर (उदा. '127.0.0.1; id') डालकर कमांड बाउंड्री से बाहर निकलता है।
ऑपरेटिंग सिस्टम शेल वेब प्रोसेस के पूर्ण अधिकारों के साथ दुर्भावनापूर्ण कमांड निष्पादित करता है।
# Backtick execution invokes /bin/sh
def fetch_git_log(branch)
# Input: "main; whoami"
`git log #{branch}`
end
# Multiple arguments to system/Open3 bypass the shell
require 'open3'
def fetch_git_log(branch)
# branch is passed as an isolated argument to git
stdout, stderr, status = Open3.capture3("git", "log", branch)
stdout
end
open() on user-supplied filenames; use File.open() न करें।