首页
学习
活动
专区
圈层
工具
发布
首页
学习
活动
专区
圈层
工具
社区首页 >问答首页 >将URL参数作为命令行脚本参数传递安全注意事项

将URL参数作为命令行脚本参数传递安全注意事项
EN

Stack Overflow用户
提问于 2018-07-21 19:32:07
回答 1查看 62关注 0票数 0

我正在编写一个web应用程序,我需要将一些url参数作为命令行参数传递给另一个脚本。我应该做些什么来避免安全问题?我使用Sympfony的进程来执行bash命令,使用Laravel来构建应用程序。

下面是一些代码,查看buildScreenshotCommand以查看我是如何构建命令字符串的,还要注意,$urlRequest是使用Laravel的Request $request类填充的:

代码语言:javascript
代码运行次数:0
运行
复制
<?php

namespace App\Logic;

use App\Logic\TimeHelper;
use App\UrlRequest;
use Illuminate\Support\Facades\Storage;
use Symfony\Component\Process\Exception\ProcessFailedException;
use Symfony\Component\Process\Process;

class Screenshot {

    static function take(UrlRequest $urlRequest)
    {
        $name = self::generateName($urlRequest);
        $command = self::buildScreenshotCommand($name, $urlRequest);

        $startTime = TimeHelper::milliseconds();

        $process = new Process($command);
        $process->run();

        $endTime = TimeHelper::milliseconds();

        if (!$process->isSuccessful())
        {
            throw new ProcessFailedException($process);
        }

        $output = $process->getOutput();

        if (trim($output) === '')
        {
            $urlRequest->successful = 1;

            $file = self::uploadToS3($name);
            $urlRequest->image_url = $file['url'];
            $urlRequest->file_size = $file['size'];
            $urlRequest->file_name = $name;
            $urlRequest->time_it_took_to_take_screenshot_ms = $endTime - $startTime;

            if ($urlRequest->save())
            {
                return $urlRequest;
            }
        }
        else
        {
            $urlRequest->error = $output;
            $urlRequest->save();
        }

        return false;
    }

    static function uploadToS3($name)
    {
        $name = 'screenshots/' . $name;

        Storage::disk('s3')->put($name, Storage::disk('local')->get($name), ['visibility' => 'public']); // upload to S3

        $fileSize = Storage::disk('local')->size($name);
        Storage::disk('local')->delete($name);

        return [
            'url' => Storage::disk('s3')->url($name),
            'size' => $fileSize
        ];
    }

    static function generateName($urlRequest)
    {
        $name = time() . rand(10000, 99999);
        $extension = '.png';

        if (isset($urlRequest->pdf) AND $urlRequest->pdf == 1)
        {
            $extension = '.pdf';
        }

        while (UrlRequest::where('file_name', '=', $name . $extension)->first())
        {
            $name = time() . rand(10000, 99999);
        }

        return $name . $extension;
    }

    static function buildScreenshotCommand($name, $urlRequest)
    {
        $command = 'cd ' . base_path() . ' && node puppeteer-screenshots-init.js ';
        $command .= "--url={$urlRequest->url} ";

        $fullPath = storage_path('app') . '/screenshots/' . $name;

        $command .= "--path={$fullPath} ";

        if (isset($urlRequest->pdf))
        {
            $command .= "--pdf=true ";
        }

        if (isset($urlRequest->viewport_width))
        {
            $command .= "--viewportWidth={$urlRequest->viewport_width} ";
        }

        if (isset($urlRequest->mobile))
        {
            $command .= '--mobile=true ';
        }

        if (isset($urlRequest->media_type_print))
        {
            $command .= '--mediaTypePrint=true ';
        }

        if (isset($urlRequest->user_agent))
        {
            $command .= '--userAgent="' . $urlRequest->user_agent . '" ';
        }

        $command .= '2>&1 &';

        return $command;
    }

}
EN

回答 1

Stack Overflow用户

发布于 2018-07-21 19:41:42

我认为这是一个非常糟糕的主意。如果$urlRequest->url是:

代码语言:javascript
代码运行次数:0
运行
复制
 // urlencoded
 http%3A%2F%2Fgoogle.com%3F%3Brm+-Rf+%2F%3B

 http://google.com?;rm -Rf /;

你在做什么类型的输入清理?

票数 1
EN
页面原文内容由Stack Overflow提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://stackoverflow.com/questions/51455627

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档