Block ";" in input string


 
Thread Tools Search this Thread
Top Forums Programming Block ";" in input string
# 1  
Old 06-19-2006
Block ";" in input string

To prevent injection, I want to exit the attached routine if a semi-colon is in the input string. I am using gcc as the compiler.

#include<stdio.h>
#include<stdlib.h>
int sysrun(char *command) {
int num;
char str[80];
char process[39] = "/xxxx/xxxx/xxxxx/xxxxx/xxxxxx2unix.sh ";
num=0;
strcpy(str,process);
strncat(str,command,35);
num = system(str);
return num;
}

Any thing that is passed via the command string, will be appended as replacement values on the command line. What I want to do is detect if a ";" is in the command string so that I can exit the application without allowing injection. Any help would be appreciated.
# 2  
Old 06-19-2006
I don't quite get what you are trying to do, but this is probably what you want.
Code:
if(strstr(command,";")) {
                fprintf(stdout,"command strings has a ';' in it!\n");
                exit(-1);
}

# 3  
Old 06-19-2006
Shells let you do stuff like this:
command1 ; command2
and that is exactly what you want to prevent. But what about:
command1 && command2
command || command2
One of those would work, depending on the exit code from your shell script. This is probably legal too:
command1 & command2
And there are other variants. The best way to protect yourself is to get rid of system() and instead just fork() and exec().
# 4  
Old 06-20-2006
I am passing a command line option to an oracle external procedure script. Internally the shell script will parse the command line option, but I needed to protect my invokation from imbedded unix commands, which is why I wanted to exit on a semi colon.
# 5  
Old 06-20-2006
I think I get what you want.
Code:
#!/bin/ksh
echo "$@" | grep -q ';' 
if [ $? -eq 0 ] ; then
   echo "invalid parameters"
   exit 1
fi

# 6  
Old 06-20-2006
Quote:
Originally Posted by jim mcnamara
I think I get what you want.
Code:
#!/bin/ksh
echo "$@" | grep -q ';' 
if [ $? -eq 0 ] ; then
   echo "invalid parameters"
   exit 1
fi

Thanks for the idea, however the test needed to be inside my "C" application.
# 7  
Old 06-20-2006
ok -
Code:
for(i=1;i<argc;i++)
{
   if(strchr(argv[i],';')!=NULL)
   {
       fprintf(stderr,"%s\n","invalid parameter");
       exit(EXIT_FAILURE);      
   }
}

Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Delete all log files older than 10 day and whose first string of the first line is "MSH" or "<?xml"

Dear Ladies & Gents, I have a requirement to delete all the log files in /var/log/test directory that are older than 10 days and their first line begin with "MSH" or "<?xml" or "FHS". I've put together the following BASH script, but it's erroring out: for filename in $(find /var/log/test... (2 Replies)
Discussion started by: Hiroshi
2 Replies

2. Shell Programming and Scripting

How to avoid "Too many arguments" error, when passing a long String literal as input to a command?

Hi, I am using awk here. Inside an awk script, I have a variable which contains a very long XML data in string format (500kb). I want to pass this data (as argument) to curl command using system function. But getting Too many arguments error due to length of string data(payloadBlock). I... (4 Replies)
Discussion started by: cool.aquarian
4 Replies

3. UNIX for Dummies Questions & Answers

Using "mailx" command to read "to" and "cc" email addreses from input file

How to use "mailx" command to do e-mail reading the input file containing email address, where column 1 has name and column 2 containing “To” e-mail address and column 3 contains “cc” e-mail address to include with same email. Sample input file, email.txt Below is an sample code where... (2 Replies)
Discussion started by: asjaiswal
2 Replies

4. Shell Programming and Scripting

grep with "[" and "]" and "dot" within the search string

Hello. Following recommendations for one of my threads, this is working perfectly : #!/bin/bash CNT=$( grep -c -e "some text 1" -e "some text 2" -e "some text 3" "/tmp/log_file.txt" ) Now I need a grep success for some thing like : #!/bin/bash CNT=$( grep -c -e "some text_1... (4 Replies)
Discussion started by: jcdole
4 Replies

5. Shell Programming and Scripting

tcsh - understanding difference between "echo string" and "echo string > /dev/stdout"

I came across and unexpected behavior with redirections in tcsh. I know, csh is not best for redirections, but I'd like to understand what is happening here. I have following script (called out_to_streams.csh): #!/bin/tcsh -f echo Redirected to STDOUT > /dev/stdout echo Redirected to... (2 Replies)
Discussion started by: marcink
2 Replies

6. Shell Programming and Scripting

how to use "cut" or "awk" or "sed" to remove a string

logs: "/home/abc/public_html/index.php" "/home/abc/public_html/index.php" "/home/xyz/public_html/index.php" "/home/xyz/public_html/index.php" "/home/xyz/public_html/index.php" how to use "cut" or "awk" or "sed" to get the following result: abc abc xyz xyz xyz (8 Replies)
Discussion started by: timmywong
8 Replies

7. Shell Programming and Scripting

Using sed to find text between a "string " and character ","

Hello everyone Sorry I have to add another sed question. I am searching a log file and need only the first 2 occurances of text which comes after (note the space) "string " and before a ",". I have tried sed -n 's/.*string \(*\),.*/\1/p' filewith some, but limited success. This gives out all... (10 Replies)
Discussion started by: haggismn
10 Replies

8. Shell Programming and Scripting

awk command to replace ";" with "|" and ""|" at diferent places in line of file

Hi, I have line in input file as below: 3G_CENTRAL;INDONESIA_(M)_TELKOMSEL;SPECIAL_WORLD_GRP_7_FA_2_TELKOMSEL My expected output for line in the file must be : "1-Radon1-cMOC_deg"|"LDIndex"|"3G_CENTRAL|INDONESIA_(M)_TELKOMSEL"|LAST|"SPECIAL_WORLD_GRP_7_FA_2_TELKOMSEL" Can someone... (7 Replies)
Discussion started by: shis100
7 Replies

9. Shell Programming and Scripting

input string="3MMTQSZ348GGMZRQWMJM4SD6M";output string="3MMTQ-SZ348-GGMZR-QWMJM-4SD6

input string="3MMTQSZ348GGMZRQWMJM4SD6M" output string="3MMTQ-SZ348-GGMZR-QWMJM-4SD6M" using linux shell script (4 Replies)
Discussion started by: pankajd
4 Replies

10. Shell Programming and Scripting

check input = "empty" and "numeric"

Hi how to check input is "empty" and "numeric" in ksh? e.g: ./myscript.ksh k output show: invalid number input ./myscript.ksh output show: no input ./myscript.ksh 10 output show: input is numeric (6 Replies)
Discussion started by: geoffry
6 Replies
Login or Register to Ask a Question