T09 · Insecure Skill Coding Practices
- Location
scripts/log-analyzer.sh:97- Finding
Terminal Control-Sequence Injection Through Untrusted Log and Pattern Output
- Content
View full analysis
/dev/null \ | tr '[:upper:]' '[:lower:]' \ | sed 's/^[[:space:]]*//;s/[[:space:]]*$//' \ | sort | uniq -c | sort -rn \ | head -20 \ | awk '{printf "%-5s %-10s %s\n", NR, $1, substr($0, index($0,$2))}' ``` The pattern is printed again in the main summary: ```bash echo -e "${BOLD}Log Analyzer${NC} — Pattern: \"$ERROR_PATTERN\" | Window: ${TIME_WINDOW}h\n" ``` ### Technical Analysis The script handles log files and custom regular-expression patterns as untrusted input, but emits values derived from those inputs directly to an interactive terminal. No filtering or visible encoding of control characters is performed. There are two related injection mechanisms: 1. A custom pattern supplied through `-p` is interpolated into strings passed to `echo -e`. Because `echo -e` interprets backslash escapes, specially constructed pattern text can introduce terminal control characters when displayed. 2. Matched log text is passed through `awk printf` unchanged. Literal ANSI, OSC, or other terminal control sequences embedded in a malicious log record are therefore written directly to the operator's terminal. Depending on terminal capabilities and configuration ...[truncated 1832 chars]- Remediation
View remediation
