Searching for "semicolon injection" bugs in embedded Linux devices
newsoft-tech.blogspot.com
newsoft-tech.blogspot.com
<img src="http://192.168.0.1/admin.cgi?remote_admin=1&passwd=foo&confirm_passwd=foo">
or <img src="http://192.168.0.1/ping.cgi?addr=\"127.0.0.1`rm -rf /`\"">
Not the most convenient attack, but hardly impossible.nonce required is another good layer
Create a web site with user-friendly instructions on configuring your router for popular games. (Port forwarding, etc..) Hustle for good Google rankings.
For each game, have an instruction sheet. Each instruction sheet is two pages long.
The first page tells you how to log into your router.
The second page contains the malicious <img> tag as described by JoachimSchipper, as well as genuine instructions to complete your router config. (If you want to hit multiple router firmwares, just include multiple <img> tags, each with its own parameters.)
From there, you can gain remote admin access to the router. Presumably, you'd want to automate whatever you're doing to people. So, after people visit the second instruction page, run a script that reconfigures the router however you please.
At this point, the sky's the limit, but might I suggest uploading your own firmware such as DD-WRT. From there, you could do all kinds of things, from the silly (replacing all downloaded images with kittens) to the nefarious (stealing passwords on all non-SSL sites).
Standard disclaimer: I'm not writing this to help the bad guys. They already know what to do. This is food for thought for the good guys.
Makes it more likely someone will notice and you'll get flagged though I suppose.
I'm sure every shell has different quirks. Not to mention new versions of the shell come out, which could cause problems if you want the output of the format string to remain comparable with old data.
The worst problem of course is you end up with things like PHP's real_mysql_escape_string($str), which i would hate to have condensed into sprintf(buff, "%rmes", str). Let alone different versions for ksh/zsh/{insert thirty years of UNIX history here}.
Also, the most common case would be system(sprintf(...)). This should just pass the command onto the shell in compatibility mode, meaning most of the extra sugar should be disabled. Even all of zsh's string parsing sugar needs to be turned on (disabled by default).
Ignoring all of that, the most common thing that you want properly escaped would be:
- Semi-colon to prevent injection.
- Spaces to make sure that the string is parsed as a single arg.
- Quotes and double-quotes because you want them to be part of the argument text and not part of the shell's syntax.
Even that short list of requirements would be useful.