4 ms·
Using built-in libraries or using the array form of exec to call mkdir or writing your own directory creator feels like it's missing the nub of the problem. Yo
by JulianMorrison 5y ago
Using built-in libraries or using the array form of exec to call mkdir or writing your own directory creator feels like it's missing the nub of the problem.
You are accepting unsafe input, and trying to work around that without making the input safe.
What you should be doing: taking the raw path string and parsing it. Defining via the parser what the form of a permitted path is. Either the input data matches this pattern, in which case it almost doesn't matter how you turn it into directories, or it does not, in which case you can reject it as garbage.
- alecbz 5y agoIs there any language with a type system that enforces that possibly user-provided strings/data are tagged as such and forced to be sanitized before use in potentially dangerous functions? This seems like the kind of thing that if done well, could eliminate entire classes of bugs without being too burdensome.
- joshuamorton 5y agoA lot of (most?) type systems can enforce this, but don't by default. You'd define a class "SanitizedStr" (or in this particular case "Path") and have all path operations work on that. Python's pathlib sort of does this, although there's still attacks possible with stuff like joining with an absolute path.
- blandflakes 5y agoNot particularly mainstream, but I remember Ballerina having this: https://ballerina.io/1.0/learn/by-example/taint-checking.html https://ballerina.io/1.0/learn/by-example/taint-checking.htm...
- JulianMorrison 5y agoTaint mode in Perl.
- 2OEH8eoCRo0 5y agoThis is my instinct working with Perl. Test the input with a regex and move on.
- mst 5y agoBetter still, with -somebody elses- regexp. p3rl.org/File::Spec#no_upwards - after calling splitpath and splitdir from the same module - is very much my friend. (or for advanced mode, Path::Tiny, possibly with the help of App::FatPacker to condense back down to a single script if you're writing something you need to be able to copy around without thinking about dependencies)