Nodejs API docs for exec say:
> Never pass unsanitized user input to this function. Any input containing shell metacharacters may be used to trigger arbitrary command execution.
I've always wondered what exactly the best way to do this is... searching about sanitising user input into shells always results in suggestions for something quite extreme like stripping non-alphanumerics or something similar. But much of the time user inputs are just passed as parameters or built into paths as in this case, so I wondered, is it enough to quote them instead? we don't need the features of double quotes when building the string in some other language in which case the rules for single quotes apply:
From GNU Bash 3.1.2.2 Single Quotes:
> Enclosing characters in single quotes (‘'’) preserves the literal value of each character within the quotes. A single quote may not occur between single quotes, even when preceded by a backslash.
In which case is it possible to get away with just "sanitizing" for single quote usage and then single quote all paramaters?:
exec(`cat '/sys/class/net/${iface.replace(/'/g, '')}/address'`, () => {})
Is it possible to break out of that? I think in order to use && or ; to start a new command you need to end the context of the string, but .replace(/'/g, '') seems to remove that ability? e.g
iface = `'; touch /uhoh;`
results in the following string passed to exec
cat '/sys/class/net/; touch /uhoh;/address'
=> cat: '/sys/class/net/; touch /uhoh/address': No such file or directory
Also you can't do further exec inside single quotes with backticks e.g
cat '/sys/class/net/` touch /uhoh `/address'
=> cat: '/sys/class/net/`touch /uhoh`/address': No such file or directory