T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:71- Finding
Unsafe Domain Argument Handling Enables OpenSSL Argument Injection and Denial of Service
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:71-109
Vulnerability Type: Incorrect positional argument handling and unquoted shell expansion
Risk Level: MediumThe command handlers incorrectly read the target domain from
$2, even thoughmainremoves the command name withshiftbefore dispatching the remaining arguments. Consequently, the documented invocation supplies the domain as$1, not$2.The selected argument is also expanded without quotation when passed to OpenSSL and to internal shell functions.
bash cmd_check() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME check <domain>" echo | openssl s_client -connect $2:443 -servername $2 2>/dev/null | openssl x509 -noout -subject -issuer -dates 2>/dev/null } cmd_grade() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME grade <domain>" echo | openssl s_client -connect $2:443 2>/dev/null | openssl x509 -noout -dates 2>/dev/null; echo 'Full grade: use ssllabs.com' } cmd_chain() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME chain <domain>" echo | openssl s_client -connect $2:443 -showcerts 2>/dev/null | grep -E 's:|i:' } cmd_protocols() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME protocols <domain>" for p in tls1 tls1_1 tls1_2 tls1_3; do echo | openssl s_client -connect $2:443 -$p 2>/dev/null | grep -q 'Cipher' && echo "$p: OK" || echo "$p: FAIL"; done } cmd_expiry() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME expiry <domain>" echo | openssl s_client -connect $2:443 -servername $2 2>/dev/null | openssl x509 -noout -enddate 2>/dev/null } cmd_ciphers() { local domain="${2:-}" [ -z "$domain" ] && die "Usage: $SCRIPT_NAME ciphers <domain>" echo | openssl s_client -connect $2:443 2>/dev/null | grep 'Cipher' } cmd_report ...[truncated 2938 chars]- Remediation
View remediation
Remediation Suggestions
-
Read the domain from
$1after dispatch and use the local variable consistently:bash local domain="${1:-}" [[ -n "$domain" ]] || die "Usage: $SCRIPT_NAME check <domain>" -
Quote every expansion used as an argument:
bash openssl s_client \ -connect "${domain}:443" \ -servername "$domain" -
Quote arguments passed between functions:
bash cmd_check "$domain" cmd_protocols "$domain" -
Validate the target before invoking OpenSSL. If only DNS names are supported, enforce an appropriate hostname policy. If IPv4 or IPv6 addresses are also required, parse them separately rather than weakening the hostname expression.
bash [[ "$domain" =~ ^([A-Za-z0-9-]+\.)*[A-Za-z0-9-]+$ ]] || die "Invalid domain" -
Reject unexpected argument counts so an attacker cannot supply hidden trailing arguments:
bash [[ $# -eq 1 ]] || die "Usage: $SCRIPT_NAME check <domain>" -
Use OpenSSL's explicit option terminator if supported by the deployed OpenSSL version, while retaining validation and quoting. Do not rely on an option terminator as the sole defense.
-
Add regression tests covering:
- A normal hostname.
- Missing and excessive arguments.
- Values beginning with
-. - Spaces, tabs, wildcard characters, and newlines.
- IPv4 and IPv6 targets if those formats are intentionally supported.
-
