T09 · Insecure Skill Coding Practices
- Location
SKILL.md:58- Finding
Remote Command Injection Through Unescaped Deployment Parameters
- Content
View full analysis
:~/ scp references/docker-compose.yml :~/thehive-cortex/docker-compose.yml ssh "bash ~/setup.sh '' ''" ``` ### Technical Analysis The documented SSH invocation embeds the password and organization name directly in a remote shell command. Wrapping a value in single quotes is not safe if the value itself can contain a single quote. Because the SSH command is interpreted by a shell on the target host, a crafted parameter can close the quoted argument and append arbitrary shell commands. No validation or shell-safe escaping is applied before constructing the command. ### Attack Path 1. An attacker supplies a crafted organization name or password, such as: ```text SOC'; attacker-command; # ``` 2. The agent substitutes that value into the documented SSH command. 3. The resulting remote command is equivalent to: ```bash bash ~/setup.sh '' 'SOC'; attacker-command; #' ``` 4. The remote shell runs `attacker-command` with the privileges of the SSH account. ### Impact Assessment Successful exploitation provides arbitrary command execution on the deployment target as the SSH user. If the SSH user can run Docker, the attacker may be able to mount the host filesystem or start privileged containers, potentially escalating the compromise to the entire host. ]]>- Remediation
View remediation
