15–25 min Updated

Command Execution

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

If your application calls out to the OS, you need to be sure command strings are securely constructed.

Prevalence
Common
Exploitability
Moderate
Impact
Devastating

What is a command execution attack?

Command execution, also called command injection, is an injection attack in which an attacker submits input that an application passes to an operating system shell. Because the input is concatenated into a command string, the attacker can append commands of their own and run them on the server with the privileges of the web application.

What you'll learn

  • How unescaped input lets an attacker append commands to a shell call
  • How to avoid shell calls, and escape their inputs when you cannot
  • Why running the web server with restricted permissions limits the damage

Where this lesson counts

OWASP Top 10

PCI DSS v4.0.1

  • Command Execution lab

    A DNS lookup site passes its domain parameter straight into a shell command. Watch Slim append an echo command to prove the hole exists, then do it yourself: add cat /etc/shadow to the search and read the server's password file.

  • How to prevent Command Execution

    The prevention guide covers five approaches:

    • Try to Avoid Command Line Calls Altogether
    • Escape Inputs Correctly
    • Restrict the Permitted Commands
    • Perform Thorough Code Reviews
    • Run with Restricted Permissions
  • Command Execution quiz

    Two questions. Passing marks the lesson complete.

Sources

  • SQL Injection

    If you are vulnerable to SQL Injection, attackers can run arbitrary commands against your database.

  • Remote Code Execution

    If an attacker can smuggle code into your web-server process, you have a serious problem.

  • Directory Traversal

    Ensure file paths are safely interpreted, or hackers can access sensitive files on your server.

  • File Upload Vulnerabilities

    File uploads are an easy way for an attacker to inject malicious code into your application.