|
11 | 11 | import java.util.Arrays; |
12 | 12 |
|
13 | 13 | public class RuntimeExecTest { |
14 | | - public static void test(String[] args) { |
| 14 | + public static void test() { |
15 | 15 | System.out.println("Command injection test"); |
16 | 16 |
|
17 | | - try { |
18 | | - // 1. array literal |
19 | | - String[] commandArray1 = new String[]{"/bin/sh", args[2], args[3], args[4]}; |
20 | | - Runtime.getRuntime().exec(commandArray1); |
21 | | - |
22 | | - // 2. array assignment after it is created |
23 | | - String[] commandArray2 = new String[4]; |
24 | | - commandArray2[0] = "/bin/sh"; |
25 | | - commandArray2[1] = args[2]; |
26 | | - commandArray2[2] = args[3]; |
27 | | - commandArray2[3] = args[4]; |
28 | | - Runtime.getRuntime().exec(commandArray2); |
29 | | - |
30 | | - // 3. Stream concatenation |
31 | | - Runtime.getRuntime().exec( |
32 | | - Stream.concat( |
33 | | - Arrays.stream(new String[]{"/bin/sh"}), |
34 | | - Arrays.stream(new String[]{args[2], args[3], args[4]}) |
35 | | - ).toArray(String[]::new) |
36 | | - ); |
37 | | - |
38 | | - } catch (Exception e) { |
39 | | - System.err.println("ERROR: " + e.getMessage()); |
| 17 | + String script = System.getenv("SCRIPTNAME"); |
| 18 | + |
| 19 | + if (script != null) { |
| 20 | + try { |
| 21 | + // 1. array literal in the args |
| 22 | + Runtime.getRuntime().exec(new String[]{"/bin/sh", script}); |
| 23 | + |
| 24 | + // 2. array literal with dataflow |
| 25 | + String[] commandArray1 = new String[]{"/bin/sh", script}; |
| 26 | + Runtime.getRuntime().exec(commandArray1); |
| 27 | + |
| 28 | + // 3. array assignment after it is created |
| 29 | + String[] commandArray2 = new String[4]; |
| 30 | + commandArray2[0] = "/bin/sh"; |
| 31 | + commandArray2[1] = script; |
| 32 | + Runtime.getRuntime().exec(commandArray2); |
| 33 | + |
| 34 | + // 4. Stream concatenation |
| 35 | + Runtime.getRuntime().exec( |
| 36 | + Stream.concat( |
| 37 | + Arrays.stream(new String[]{"/bin/sh"}), |
| 38 | + Arrays.stream(new String[]{script}) |
| 39 | + ).toArray(String[]::new) |
| 40 | + ); |
| 41 | + |
| 42 | + } catch (Exception e) { |
| 43 | + System.err.println("ERROR: " + e.getMessage()); |
| 44 | + } |
40 | 45 | } |
41 | 46 | } |
42 | 47 | } |
0 commit comments