|
11 | 11 | import java.util.Arrays;
|
12 | 12 |
|
13 | 13 | public class RuntimeExecTest {
|
14 |
| - public static void test(String[] args) { |
| 14 | + public static void test() { |
15 | 15 | System.out.println("Command injection test");
|
16 | 16 |
|
17 |
| - try { |
18 |
| - // 1. array literal |
19 |
| - String[] commandArray1 = new String[]{"/bin/sh", args[2], args[3], args[4]}; |
20 |
| - Runtime.getRuntime().exec(commandArray1); |
21 |
| - |
22 |
| - // 2. array assignment after it is created |
23 |
| - String[] commandArray2 = new String[4]; |
24 |
| - commandArray2[0] = "/bin/sh"; |
25 |
| - commandArray2[1] = args[2]; |
26 |
| - commandArray2[2] = args[3]; |
27 |
| - commandArray2[3] = args[4]; |
28 |
| - Runtime.getRuntime().exec(commandArray2); |
29 |
| - |
30 |
| - // 3. Stream concatenation |
31 |
| - Runtime.getRuntime().exec( |
32 |
| - Stream.concat( |
33 |
| - Arrays.stream(new String[]{"/bin/sh"}), |
34 |
| - Arrays.stream(new String[]{args[2], args[3], args[4]}) |
35 |
| - ).toArray(String[]::new) |
36 |
| - ); |
37 |
| - |
38 |
| - } catch (Exception e) { |
39 |
| - System.err.println("ERROR: " + e.getMessage()); |
| 17 | + String script = System.getenv("SCRIPTNAME"); |
| 18 | + |
| 19 | + if (script != null) { |
| 20 | + try { |
| 21 | + // 1. array literal in the args |
| 22 | + Runtime.getRuntime().exec(new String[]{"/bin/sh", script}); |
| 23 | + |
| 24 | + // 2. array literal with dataflow |
| 25 | + String[] commandArray1 = new String[]{"/bin/sh", script}; |
| 26 | + Runtime.getRuntime().exec(commandArray1); |
| 27 | + |
| 28 | + // 3. array assignment after it is created |
| 29 | + String[] commandArray2 = new String[4]; |
| 30 | + commandArray2[0] = "/bin/sh"; |
| 31 | + commandArray2[1] = script; |
| 32 | + Runtime.getRuntime().exec(commandArray2); |
| 33 | + |
| 34 | + // 4. Stream concatenation |
| 35 | + Runtime.getRuntime().exec( |
| 36 | + Stream.concat( |
| 37 | + Arrays.stream(new String[]{"/bin/sh"}), |
| 38 | + Arrays.stream(new String[]{script}) |
| 39 | + ).toArray(String[]::new) |
| 40 | + ); |
| 41 | + |
| 42 | + } catch (Exception e) { |
| 43 | + System.err.println("ERROR: " + e.getMessage()); |
| 44 | + } |
40 | 45 | }
|
41 | 46 | }
|
42 | 47 | }
|
0 commit comments