Skip to content

Security Fix for Command Injection - huntr.dev#11

Open
huntr-helper wants to merge 3 commits into
es128:masterfrom
418sec:1-npm-serial-number
Open

Security Fix for Command Injection - huntr.dev#11
huntr-helper wants to merge 3 commits into
es128:masterfrom
418sec:1-npm-serial-number

Conversation

@huntr-helper

Copy link
Copy Markdown

https://huntr.dev/users/alromh87 has fixed the Command Injection vulnerability 🔨. alromh87 has been awarded $25 for fixing the vulnerability through the huntr bug bounty program 💵. Think you could fix a vulnerability like this?

Get involved at https://huntr.dev/

Q | A
Version Affected | ALL
Bug Fix | YES
Original Pull Request | 418sec#4
Vulnerability README | https://github.com/418sec/huntr/blob/master/bounties/npm/serial-number/1/README.md

User Comments:

📊 Metadata *

Bounty URL: https://www.huntr.dev/bounties/1-npm-serial-number

⚙️ Description *

serial-number is a simple Node.js module for accessing the serial number (a.k.a. Dell Service Tag, asset tag) of the local machine, this package are vulnerable to Command Injection.

The cmdPrefix argument in serialNumber function is used by the exec function without any validation.

💻 Technical Description *

Arbitary Code Execution is avoided by using execFile() instead of exec()
- cmdPrefix param can be path or comand like sudo, both cases are handled
- grep was used, on non win systems, for piped comand to filter string, this is achived by usng spawn

🐛 Proof of Concept (PoC) *

Install the package and run the below code:

var root = require("./");
var cmdPrefix = "echo vulnerable > HACKED # ";

root((e,res) => {
    if(e) console.log(e);
    else  console.log('Result:\n\t'+res);
}, cmdPrefix);

It will create a file named HACKED in the working directory.

🔥 Proof of Fix (PoF) *

After fix no file is created

👍 User Acceptance Testing (UAT)

Commands can be executed normally

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants