T09 · Insecure Skill Coding Practices
- Location
weather-cn-pro.sh:169- Finding
Remote Command Injection Through Unsafe Evaluation of Weather Data
- Content
View full analysis
[^<]*' | sed 's///' | sed 's/天气预报.*//' | head -1) fi rm -f "$tmpfile" echo "WEATHER=${weather:-未知}" echo "TEMP=${temp:-未知}" ``` The serialized values are subsequently evaluated as Bash code: ```bash format_output() { local city="$1" shift local data="$@" eval "$data" ``` ### Technical Analysis The script downloads HTML from `www.weather.com.cn` and treats that response as untrusted weather data. If the primary weather extraction does not produce a value, lines 61–62 obtain the weather description from the remote page's `<title>` element. The extracted title is not constrained to a safe weather-value character set. It is serialized into a string resembling a shell assignment: ```bash WEATHER=<remote value> ``` `main` combines this string with lifestyle data and passes it to `format_output`. Line 169 executes the resulting text with `eval`, causing Bash to parse shell metacharacters, command substitutions, variable expansions, and control operators in the remote value. For example, a malicious title containing a command substitution such as `$(attacker_command)` can survive extraction and be embedded into the `WEATHER` assignment. When `eval` parses that assignment, the command substitution is executed. HTTPS reduces ordinary network interception risk but does not make remote content safe to evaluate; exploitation remains possible through an upstream compromise, maliciously altered response, DNS/TLS trust compromise, or another mechanism capable of influencing the downloaded page. ### Attack Path 1. The attacker gains the ability to influence the HTML returned for the requested weather page. 2. The attacker provides ...[truncated 1458 chars]- Remediation
View remediation
` for later evaluation. 4. **Validate all remotely derived values.** Restrict weather descriptions and temperatures to the formats actually required by the application. Prefer an explicit allowlist of expected weather terms. Reject or replace values containing shell metacharacters, control characters, or unexpected newlines. Validation is defense in depth and is not a substitute for removing `eval`. 5. **Treat every HTTP response as attacker-controlled.** Continue using HTTPS, add `curl --fail --show-error`, validate response size and content type where practical, and fail safely when the response does not match the expected format. 6. **Add regression tests.** Test title values containing command substitutions, semicolons, quotes, backticks, newlines, and redirection operators, and verify that they are displayed only as inert text and never executed. ]]>
