T09 · Insecure Skill Coding Practices
- Location
infra.md:141- Finding
Unvalidated Domain Input Permits Command-Line Option Injection
- Content
View full analysis
/dev/null | openssl x509 -noout -dates -subject -issuer # Check headers echo "=== Security Headers ===" curl -sI https://$DOMAIN | grep -iE "strict-transport|content-security|x-frame" ``` ### Technical Analysis The script assigns its first positional argument to `DOMAIN` and expands it without quoting or validation in commands executed by `nmap`, `openssl`, and `curl`. Unquoted shell expansion performs word splitting. Consequently, a value containing whitespace can become multiple command-line arguments. Downstream utilities may interpret the additional arguments as options rather than as part of the intended hostname. In particular, `curl` accepts options interspersed with URLs, while `nmap` also exposes options that materially alter scan behavior and output handling. Shell metacharacters embedded inside the variable are not reparsed as shell syntax during ordinary parameter expansion, so this is not direct arbitrary shell-command injection by itself. It is nevertheless command-line option injection that can expose unintended functionality of the invoked tools. ### Attack Path 1. An attacker gains the ability to supply the domain argument to the documented audit script, directly or through an automation system. 2. The attacker submits a crafted value containing whitespace and additional utility-specific options. 3. The shell splits the unquoted expansion into multiple arguments. 4. `nmap`, `openssl`, or `curl` interprets attacker-controlled arguments as command options or additional targets. 5. Depending on the utility and avai ...[truncated 856 chars]- Remediation
View remediation
&2 exit 2 fi echo "=== Protocols ===" nmap --script ssl-enum-ciphers -p 443 -- "$DOMAIN" | grep -E "TLSv|SSLv" echo "=== Certificate ===" echo | openssl s_client -servername "$DOMAIN" -connect "${DOMAIN}:443" 2>/dev/null | openssl x509 -noout -dates -subject -issuer echo "=== Security Headers ===" curl --silent --show-error --head -- "https://${DOMAIN}" | grep -iE "strict-transport|content-security|x-frame" ``` Additional hardening measures should include: - Decide explicitly whether IP addresses, IPv6 literals, ports, or internationalized domain names are supported and validate them with dedicated parsers. - Run network-audit scripts under a minimally privileged service account. - Apply network egress restrictions to prevent access to sensitive internal or metadata endpoints. - Add tests using values containing whitespace, leading hyphens, newlines, and utility-specific options. - Avoid composing host-and-port values from untrusted strings unless each component has been independently validated. ]]>
