command injection
käsusüst
olemus
rünne kahjustavate opsüsteemikäskude täitmisega
rakenduse nõrkuste kaudu,
näiteks puuduliku kontrolliga sisestusväljade kaudu
=
an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application
ülevaateid
https://en.wikipedia.org/wiki/Code_injection
https://owasp.org/www-community/attacks/Command_Injection
https://www.aldeid.com/wiki/Command-injection-to-shell
https://portswigger.net/web-security/os-command-injection
https://www.netsparker.com/blog/web-security/command-injection-vulnerability/
https://www.hackingarticles.in/comprehensive-guide-to-os-command-injection/
https://www.cs.ucdavis.edu/~su/publications/popl06.pdf
tõrje
https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html
https://www.hacksplaining.com/prevention/command-execution
https://affinity-it-security.com/how-to-prevent-command-injection/
https://blog.securityinnovation.com/blog/2013/12/preventing-command-injection-in-php-with-a-few-simple-techniques.html