T09 · Insecure Skill Coding Practices
- Location
scripts/monitor.sh:9- Finding
Unsafe filename parsing permits deletion of unrelated files
- Content
View full analysis
/dev/null | xargs -r stat --format="%Y %n" 2>/dev/null | while read timestamp filepath; do local age_days=$(( ($(date +%s) - timestamp) / 86400 )) if [ "$age_days" -gt 7 ]; then rm -f "$filepath" echo "$filepath" fi done) if [ -n "$deleted" ] && [ -n "$(echo "$deleted" | tr -d '[:space:]')" ]; then echo "🧹 已清理超过 7 天的历史日志" fi fi } ``` ### Technical Analysis The cleanup routine transports filenames through a whitespace-delimited pipeline: 1. `find` emits paths separated by newline characters. 2. `xargs` interprets whitespace, quotes, and backslashes rather than preserving each pathname exactly. 3. The output from `stat` is parsed again using `read timestamp filepath`. 4. The resulting path is passed to `rm`. Unix filenames may contain spaces, tabs, and newline characters. A specially crafted filename under the history directory can consequently be split into multiple arguments by `xargs`. One of those arguments can be an absolute path outside the history directory. If that external path exists and is older than seven days, `stat` reports it and the loop may pass it to `rm -f`. The `find` expression also lacks grouping: ```bash -type f -name "*.json" -o -name "*.log" ``` Because `-a` has higher precedence than `-o`, `-type f` applies only to the `*.json` branch. Although `rm -f` does not recursively remove directories, this expression is still broader than intended. Exploitation requires the attacker to be able to create crafted entries in the history directory. Privilege escalation in impact occurs only ...[truncated 1357 chars]- Remediation
View remediation
