T09 · Insecure Skill Coding Practices
- Location
references/cli-reference.md:166- Finding
Shell Command Injection Through Untrusted Log Timestamp Fields
- Content
View full analysis
Vulnerability Details
File Location:
references/cli-reference.md, lines 166–169 and 218–221
Vulnerability Type: Shell command injection through dynamically constructed commands
Risk Level: HighVulnerable Code
The timestamp conversion example at lines 166–169 contains:
awk awk '{ cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null" cmd | getline epoch; close(cmd) print epoch, $0 }' logfile.log | sort -n | cut -d' ' -f2-The correlation helper repeats the same vulnerable construction at lines 218–221:
awk awk -v target="$TARGET_EPOCH" -v win="$WINDOW" '{ cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null" cmd | getline epoch; close(cmd) if (epoch >= target-win && epoch <= target+win) print }' network.logTechnical Analysis
In AWK,
cmd | getlineexecutescmdthrough a command shell. The command incorporates$1,$2, and$3directly from each analyzed log record:awk cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null"These fields are enclosed in shell double quotes but are not validated or escaped. A hostile field containing a double quote can terminate the intended argument. Shell metacharacters placed after that quote can introduce additional commands.
Syslog records are not necessarily trusted input. They can originate from compromised network devices, forged UDP syslog packets, malicious applications, or users with permission to append to an analyzed log. Consequently, treating timestamp fields as safe shell syntax creates a command-injection boundary.
The issue is present in two documented helpers: general RFC 3164 timestamp normalization and extraction of events around a target time.
Attack Path
- An attacker gains the ability to submit a crafted record to the collector or modify a log file that will be analyzed.
- The attacker places shell-breaking syntax in one of the first three whitespace-delimited fie ...[truncated 1334 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not invoke a shell with timestamp text taken from log records.
- Replace the AWK
cmd | getlineconstruction with a script that parses timestamps through a date/time library without shell evaluation. - If an external process is unavoidable, pass arguments through an API that accepts an argument array rather than a command string.
- Strictly validate RFC 3164 fields before processing:
- Month must be one of
JanthroughDec. - Day must contain only one or two decimal digits and be within the valid range.
- Time must exactly match
HH:MM:SSwith valid ranges.
- Month must be one of
- Reject and separately preserve malformed records rather than attempting to normalize them.
- Run analysis under a dedicated, unprivileged account with read-only access to source logs.
- Add test cases containing quotes, command substitutions, semicolons, newlines, and other shell metacharacters to ensure malformed logs cannot trigger execution.
- Apply the corrected implementation to both occurrences at lines 166–169 and 218–221.
