Command Execution
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If your application calls out to the OS, you need to be sure command strings are securely constructed.
- Prevalence
- Common
- Exploitability
- Moderate
- Impact
- Devastating
What is a command execution attack?
Command execution, also called command injection, is an injection attack in which an attacker submits input that an application passes to an operating system shell. Because the input is concatenated into a command string, the attacker can append commands of their own and run them on the server with the privileges of the web application.
What you'll learn
- How unescaped input lets an attacker append commands to a shell call
- How to avoid shell calls, and escape their inputs when you cannot
- Why running the web server with restricted permissions limits the damage
Where this lesson counts
OWASP Top 10
Untrusted input reaches an interpreter as part of a command or query, including SQL, OS and cross-site scripting.
Learn more about A05PCI DSS v4.0.1
Requirement 6.2.4: engineering techniques must prevent injection, data-structure, cryptographic, business-logic and access-control attacks in bespoke software.
Injection flaws are the first attack class named in requirement 6.2.4.
Learn more about 6.2.4Requirement 6.4.1: public-facing web applications must be protected against known attacks by regular vulnerability review or an automated technical solution.
Learn more about 6.4.1This lesson includes
-
Command Execution lab
A DNS lookup site passes its domain parameter straight into a shell command. Watch Slim append an echo command to prove the hole exists, then do it yourself: add cat /etc/shadow to the search and read the server's password file.
-
How to prevent Command Execution
The prevention guide covers five approaches:
- Try to Avoid Command Line Calls Altogether
- Escape Inputs Correctly
- Restrict the Permitted Commands
- Perform Thorough Code Reviews
- Run with Restricted Permissions
-
Command Execution quiz
Two questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
SQL Injection
If you are vulnerable to SQL Injection, attackers can run arbitrary commands against your database.
Remote Code Execution
If an attacker can smuggle code into your web-server process, you have a serious problem.
Directory Traversal
Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.
File Upload Vulnerabilities
File uploads are an easy way for an attacker to inject malicious code into your application.