LAB 10 - WEB SECURITY

Command Injection

Kullanici girdisi shell komutuna dogrudan eklendiginde saldirgan ek komut calistirabilir. Guvenli dogrulama ve sabit komut modeli ile engelle.

Advanced OS Command Injection Input Validation
Ana Sayfaya Don

Host Check Demo

Vulnerable akista host girdisi shell komutuna dogrudan eklenir. Secure akista regex/allowlist ile filtrelenir.

Ornek Payloadlar 127.0.0.1; cat /etc/passwd, example.com && whoami, 8.8.8.8 | uname -a

Ogrenme Hedefleri

  • Shell komut birlestirmenin riskini gormek
  • Metacharacter tokenlari tanimak
  • Allowlist dogrulama uygulamak
  • Fix sonrasi payload retest yapmak

Bu Hata Neden Olustu?

  • Kullanici girdisi shell komutuna dogrudan eklendi.
  • Komut ayirici karakterler filtrelenmedi.
  • Ek komut calistirma (RCE benzeri etki) olusabildi.

Nasil Cozuldu?

  1. Host girdisi allowlist regex ile dogrulandi.
  2. Riskli tokenlar (`;`, `&&`, `|`, `$()`) reddedildi.
  3. Gercek sistemde shell yerine process argumanlari ayrik verilmeli.

Adim Adim Yol Haritasi

01 Vulnerable komut akisini calistir
02 Metacharacter payloadlari dene
03 Kök nedeni analiz et
04 Input allowlist ve token filtresi ekle
05 Secure akista retest yap
06 Shell-free process tasarimini not et