3 ms·
Can you elaborate on "pipe injection"? I can't find references to the term after brief searching, and I'm curious.
by asdfs 14y ago
Can you elaborate on "pipe injection"? I can't find references to the term after brief searching, and I'm curious.
- sophacles 14y agoSure, you know how SQL injection is just adding extra SQL statements to user input, and taking advantage of improper escaping to get the database to do your bidding? Pipe injection is the same thing but in cases where shell commands are called with arguments taken from user input. It was very common in older Unix systems to have various bits of a complicated system actually just be the result of another standard command with proper args/input. So you find a place where something like system is used, or there is a call to sh -c , or so on, and if the input is improperly escaped, add: |adduser ... or change the password, or so on to get a root shell or account. This has actually come back into style in certain places again, because so many devices are just linux boxes with busybox utils on constrained systems (think home routers for example a lot of those just display the output from various linux commands in their firewall stuff). But programmers don't always think about "what if someone is going to try and do pipe on this..." and you end up with a pipe injection. It also can be used for privilege escalation if you have a lot of custom setuid stuff available for your sysadmins and someone manages to get a local account. (unfortunately more common than one would hope).
- asdfs 14y agoAh, I see. Thanks for the explanation.
- pmh 14y agoYou'll find it under the slightly more general 'command injection'[1] which includes the use of other shell operators as well [1] https://www.owasp.org/index.php/Command_Injection https://www.owasp.org/index.php/Command_Injection