T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:96- Finding
Username Regex and sed Injection Can Modify Unintended Accounts
- Content
View full analysis
/dev/null } # Validate username (no colons, no whitespace) validate_username() { local user="$1" if [[ -z "$user" ]]; then die "Username cannot be empty" fi if [[ "$user" =~ : ]]; then die "Username cannot contain ':' character" fi if [[ "$user" =~ [[:space:]] ]]; then die "Username cannot contain whitespace" fi if [[ "${#user}" -gt 255 ]]; then die "Username too long (max 255 characters)" fi } ``` ```bash if user_exists "$file" "$user"; then # Update existing user local tmp tmp="$(mktemp)" sed "s|^${user}:.*|${user}:${hash}|" "$file" > "$tmp" mv "$tmp" "$file" ``` ```bash if ! user_exists "$file" "$user"; then die "User '${user}' not found in '${file}'" fi local tmp tmp="$(mktemp)" grep -v "^${user}:" "$file" > "$tmp" || true mv "$tmp" "$file" ``` ```bash local stored_hash stored_hash="$(grep "^${user}:" "$file" | head -1 | cut -d: -f2-)" ``` ### Technical Analysis The username is directly interpolated into Basic Regular Expressions interpreted by `grep` and `sed`. The validation function only rejects empty usernames, colons, whitespace, and values longer than 255 characters. It does not reject or escape metacharacters such as `.`, `*`, `[`, `]`, `^`, `$`, `\`, `&`, or `|`. Consequently, the supplied username is not treated as a literal htpasswd field. For example, `.*` produces the pattern `^.*:`, which matches every valid account record. In the update path, the same value is also inserted into the sed replacement string, where characters such as `&`, `\`, and the selected `|` delimiter h ...[truncated 1914 chars]- Remediation
View remediation
