4 ms·
> exec("sudo ... " . $user_input_string ...) Wow, this is always a mistake and a huge one. exec() is dangerous, exec calling with sudo more so, and should neve
by droithomme 7y ago
> exec("sudo ... " . $user_input_string ...)
Wow, this is always a mistake and a huge one. exec() is dangerous, exec calling with sudo more so, and should never be used in conjunction with unprivileged user input like this. Granted a weak attempt was made to sanitize the user string, but so weak one might wonder if it is Underhanded Code at play here.
The big problem with this sort of issue is that it indicates that there almost certainly are massive security problems elsewhere in this code base since this one is low hanging fruit that never should have made it past even rudimentary code review by anyone with a bare minimum knowledge of security.
- jrwr 7y agoCode review on a open source project.... Mind you they trusted a regex that looks pretty sane (A preg_replace might of been better)
- deleted 7y ago[deleted]
- corndoge 7y agoSo find the rest and fix them
- droithomme 7y agoI'd be happy to help you with this. My rate is $235/hr, minimum 30 hours. When can I expect your deposit so we can get started?
- deleted 7y ago[deleted]
- Disposition 7y agoYes, how dare he ask you to donate some of your time to contribute back to the open source community, tsk.
- droithomme 7y agoWow you created a brand new account just to post that one comment? I'm honored. On to the response. First, doing something I don't want to do that someone else told me to do and not getting paid for it is slavery. Slavery is bad. Second, I don't use their solution. I have my own custom DNS intercept system I wrote myself which is much better and also enjoys security by obscurity. With a single user it's hardly worth the time to mess with. Third, I already donated to their project, above. I reviewed their code, agreed it was complete shit, and concurred with the consensus that they need a complete security audit. That is extremely valuable advice which is worth $3000. So I donated $3000 and all you've done is sit and whine and create anonymous coward accounts to troll people. Tsk.
- Disposition 7y agoIt's funny that I'm apparently the troll here, your comment just made me consider finally making an account. If somebody prompts you to do something on the internet do you give it any concern? You must be swimming in free iPhone X's then. He suggested you donate time to an open source project which is about as equivalent to slavery as a cashier at Burger King trying to upsell you a large whopper menu. You've donated absolutely nothing to the project by commenting here if you didn't provide the feedback directly via the projects public tools. I actively contribute to many open source projects. Writing a shell script to generate dnsmasq hosts files isn't exactly rocket science. It doesn't matter if you don't use the project, lesser informed people do, by improving it you improve a large amount of people's security. Call it virtual herd immunity, it affects you too indirectly.
- neuralzen 7y agoUsing sudo in the exec() isn't really a problem, since any RCE an attacker would get will have the same privileges as the pihole service...they could just use sudo in their RCE if the user is in sudousers (assuming they could even use sudo on their bash session when establishing the reverse shell). In the case of the PoC here, sudo doesn't even come into play, they are stacking commands with && which would require another sudo call to elevate (which they don't do in the example).