Skip to content

Problema di sicurezza #1

@jamnaga

Description

@jamnaga

Process process = Runtime.getRuntime().exec("ping " + args[1] + " -c 1");

E' possibile che concatenando comandi, sia possibile un attacco Remote Code Execution, un esempio:

Telegram: /ping 1.1.1.1 && comando arbitrario && echo

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions