T09 · Insecure Skill Coding Practices
- Location
scripts/install.sh:46- Finding
Command Injection in Privileged Firewall Configuration
- Content
View full analysis
/tmp/injection-proof; # ``` 3. The script constructs a command equivalent to: ```bash sudo ufw allow from 203.0.113.10; id > /tmp/injection-proof; # to any port 22 proto tcp ``` 4. ...[truncated 1030 chars]- Remediation
View remediation
65535 )); then printf '%s\n' "Invalid SSH port" >&2 exit 1 fi if [[ -n "$ALLOW_SSH_FROM" ]]; then if ! ipcalc -c "$ALLOW_SSH_FROM" >/dev/null 2>&1; then printf '%s\n' "Invalid source IP or CIDR" >&2 exit 1 fi UFW_ARGS=(allow from "$ALLOW_SSH_FROM" to any port "$SSH_PORT" proto tcp) else UFW_ARGS=(allow "${SSH_PORT}/tcp") fi if confirm "Allow SSH in UFW"; then sudo ufw "${UFW_ARGS[@]}" fi ``` The exact address-validation command should be tested for the target distribution and should explicitly support every accepted IPv4, IPv6, and CIDR format. ]]>
