Class: GuardrailsRuby::Checks::CodeExecution
- Inherits:
-
GuardrailsRuby::Check
- Object
- GuardrailsRuby::Check
- GuardrailsRuby::Checks::CodeExecution
- Defined in:
- lib/guardrails_ruby/checks/code_execution.rb
Constant Summary collapse
- PATTERNS =
[ # Shell commands /\brm\s+-rf\b/i, /\brm\s+-f\b/i, /\bcurl\b.+\|\s*(ba)?sh\b/i, /\bwget\b.+\|\s*(ba)?sh\b/i, /\bchmod\s+[0-7]{3,4}\b/, /\bchown\b/, /\bsudo\b/, /\bmkdir\s+-p\b/, /\bdd\s+if=/, /\b:(){ :\|:& };:/, # fork bomb # Code execution functions /\beval\s*\(/i, /\bexec\s*\(/i, /\bsystem\s*\(/i, /\b__import__\s*\(/i, /\bos\.system\s*\(/i, /\bsubprocess\.(run|call|Popen)\s*\(/i, /\bRuntime\.getRuntime\(\)\.exec\s*\(/i, # Shell interpolation /`[^`]+`/, # backticks /\$\([^)]+\)/, # $() command substitution # Dangerous redirects />\s*\/dev\/sd[a-z]/, />\s*\/etc\//, /;\s*shutdown\b/i, /;\s*reboot\b/i, /;\s*halt\b/i, /\bpowershell\b.+-enc/i, ].freeze
Instance Attribute Summary
Attributes inherited from GuardrailsRuby::Check
Instance Method Summary collapse
Methods inherited from GuardrailsRuby::Check
check_name, direction, #initialize, lookup
Constructor Details
This class inherits a constructor from GuardrailsRuby::Check
Instance Method Details
#call(text, context: {}) ⇒ Object
44 45 46 47 48 49 50 51 52 53 |
# File 'lib/guardrails_ruby/checks/code_execution.rb', line 44 def call(text, context: {}) matched = PATTERNS.select { |p| text.match?(p) } if matched.any? fail! "Potential code execution detected", matches: matched.map(&:source) else pass! end end |