15–25 min Updated

Remote Code Execution

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

If an attacker can smuggle code into your web-server process, you have a serious problem.

Prevalence
Occasional
Exploitability
Easy
Impact
Devastating

What is remote code execution (RCE)?

Remote code execution (RCE) is a code injection attack in which an attacker runs code of their choosing on a server from across the network. On a web server it usually happens when untrusted input from an HTTP request is evaluated as code or unsafely deserialized. It gives the attacker control of the process, and often the whole system.

What you'll learn

  • How dynamic evaluation turns a string into running code
  • Why evaluating input from an HTTP request hands over your server
  • How to run a domain-specific language inside a sandbox

Where this lesson counts

OWASP Top 10

  • Remote Code Execution lab

    See how dynamic evaluation turns a string into running code, and what follows when that string comes from an HTTP request. The lab uses an analytics site with its own query language to show why a domain-specific language needs a tight sandbox.

  • How to prevent Remote Code Execution

    The prevention guide covers two approaches:

    • Only Pass Trusted Strings to Code Execution APIs
    • Execute Domain Specific Languages in a Sandbox
  • Remote Code Execution quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Command Execution

    If your application calls out to the OS, you need to be sure command strings are securely constructed.

  • Prototype Pollution

    If an attacker can access and modify prototype objects in JavaScript, you are in danger.

  • File Upload Vulnerabilities

    File uploads are an easy way for an attacker to inject malicious code into your application.

  • Buffer Overflows

    An attacker can use buffer overflows to take your site offline or to inject malicious code.