8000 testssl.sh allows for cli injection · Issue #35 · PrivacyScore/privacyscanner · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

testssl.sh allows for cli injection #35

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact i 7BBF ts maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
underdarknl opened this issue Mar 13, 2020 · 0 comments
Open

testssl.sh allows for cli injection #35

underdarknl opened this issue Mar 13, 2020 · 0 comments

Comments

@underdarknl
Copy link

As noted in testssl.sh:
#TODO: Still no shell injection safe but if just run it from the cmd line: that's fine

The testssl mail program does no input checking on the A records IP data, and simply injects this into the the subprocess.run command argument.

From where testssl.sh will possible hit the issue noted in its code.
Inserting a bash script into the dns records data of a domain that is tested will trip this up.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant
0