Remote Code Execution
By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security
If an attacker can smuggle code into your web-server process, you have a serious problem.
- Prevalence
- Occasional
- Exploitability
- Easy
- Impact
- Devastating
What is remote code execution (RCE)?
Remote code execution (RCE) is a code injection attack in which an attacker runs code of their choosing on a server from across the network. On a web server it usually happens when untrusted input from an HTTP request is evaluated as code or unsafely deserialized. It gives the attacker control of the process, and often the whole system.
What you'll learn
- How dynamic evaluation turns a string into running code
- Why evaluating input from an HTTP request hands over your server
- How to run a domain-specific language inside a sandbox
Where this lesson counts
OWASP Top 10
Untrusted input reaches an interpreter as part of a command or query, including SQL, OS and cross-site scripting.
Learn more about A05This lesson includes
-
Remote Code Execution lab
See how dynamic evaluation turns a string into running code, and what follows when that string comes from an HTTP request. The lab uses an analytics site with its own query language to show why a domain-specific language needs a tight sandbox.
-
How to prevent Remote Code Execution
The prevention guide covers two approaches:
- Only Pass Trusted Strings to Code Execution APIs
- Execute Domain Specific Languages in a Sandbox
-
Remote Code Execution quiz
Three questions. Passing marks the lesson complete.
Sources
Related lessons
Browse all 45 lessons
Command Execution
If your application calls out to the OS, you need to be sure command strings are securely constructed.
Prototype Pollution
If an attacker can access and modify prototype objects in JavaScript, you are in danger.
File Upload Vulnerabilities
File uploads are an easy way for an attacker to inject malicious code into your application.
Buffer Overflows
An attacker can use buffer overflows to take your site offline or to inject malicious code.