T09 · Insecure Skill Coding Practices
- Location
scripts/root_memory_extractor.py:74- Finding
Android Device Command Injection Through Unvalidated Package Names
- Content
View full analysis
Optional[int]: self.log("getting_process_pid", package=package_name) try: result = subprocess.run( ["adb", "shell", f"pidof {package_name}"], capture_output=True, text=True, timeout=10 ) if result.returncode == 0 and result.stdout.strip(): pid_str = result.stdout.strip() if ' ' in pid_str: pid_str = pid_str.split()[0] try: pid = int(pid_str) self.log("pid_found", "SUCCESS", pid=pid) return pid except ValueError: self.log("pidof_invalid_output", "WARNING", output=pid_str) self.log("pidof_failed_trying_ps", "WARN") ps_result = subprocess.run( ["adb", "shell", f"ps -A | grep {package_name}"], capture_output=True, text=True, timeout=10 ) if ps_result.returncode == 0 and ps_result.stdout.strip(): lines = ps_result.stdout.strip().split('\n') for line in lines: parts = line.split() if len(parts) >= 9 and package_name in parts[-1]: try: pid = int(parts[1]) self.log("pid_found_via_ps", "SUCCESS", pid=pid) return pi ...[truncated 3912 chars]- Remediation
View remediation
str: if not PACKAGE_RE.fullmatch(value): raise ValueError("Invalid Android package name") return value ``` Call the validator immediately after argument parsing: ```python try: package_name = validate_package_name(args.package) except ValueError as exc: parser.error(str(exc)) ``` Where the Android command supports separate arguments, avoid constructing a shell command string: ```python subprocess.run( ["adb", "shell", "pidof", package_name], capture_output=True, text=True, timeout=10, check=False ) ``` Avoid remote pipelines entirely. Retrieve process data and filter it in Python: ```python result = subprocess.run( ["adb", "shell", "ps", "-A"], capture_output=True, text=True, timeout=10, check=False ) for line in result.stdout.splitlines(): fields = line.split() if fields and fields[-1] == package_name: # Parse the PID from the expected field. pass ``` For commands that cannot be expressed without an Android shell string: 1. Validate the package name with a strict allowlist. 2. Apply POSIX shell quoting as an additional defense. 3. Never rely on quoting alone for identifier validation. 4. Centralize all ADB execution in a helper that distinguishes structured arguments from shell commands. 5. Add tests containing `;`, `|`, `$()`, backticks, whitespace, newlines, redirections, and quote characters. 6. Reject package names that do not exactly match the expected Android identifier grammar. 7. Apply the same correction to every listed runner, including the enhanced extractor. ]]>
