T09 · Insecure Skill Coding Practices
- Location
douyin_pipeline.py:13- Finding
Shell Command Injection Through a Remotely Controlled Video URL
- Content
View full analysis
{ const v = document.querySelector('video'); if (v && v.src && v.src.includes('douyin')) return v.src; return null; } """) ``` ```python def download_video(url, path): print(f"📥 Downloading video...") code, _, err = run( f'curl -L -o "{path}" --max-time 120 -s ' f'-H "User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1" ' f'-H "Referer: https://www.douyin.com/" ' f'"{url}"', timeout=130 ) ``` ### Technical Analysis The `run` helper executes command strings through a system shell by setting `shell=True`. The video URL extracted from the loaded page is inserted directly into the curl command without shell-safe argument handling. The only relevant validation checks whether the full URL contains the substring `douyin`. This is not a hostname or syntax validation step. A page controlled by an attacker can expose a crafted `video.src` containing that substring together with shell metacharacters or command-substitution syntax. Surrounding the URL with double quotes does not prevent all command injection. In common POSIX shells, command substitutions such as `$()` remain active inside double-quoted strings. Consequently, a malicious value reaching this command can cause local commands to run under the privileges of the pipeline process. ### Attack Path 1. An attacker provides a URL leading to a page under the attacker's control. 2. The page creates a `video` element whose `src` includes th ...[truncated 1097 chars]- Remediation
View remediation
