Class: GuardrailsRuby::Checks::CodeExecution

Inherits:
GuardrailsRuby::Check show all
Defined in:
lib/guardrails_ruby/checks/code_execution.rb

Constant Summary collapse

PATTERNS =
[
  # Shell commands
  /\brm\s+-rf\b/i,
  /\brm\s+-f\b/i,
  /\bcurl\b.+\|\s*(ba)?sh\b/i,
  /\bwget\b.+\|\s*(ba)?sh\b/i,
  /\bchmod\s+[0-7]{3,4}\b/,
  /\bchown\b/,
  /\bsudo\b/,
  /\bmkdir\s+-p\b/,
  /\bdd\s+if=/,
  /\b:(){ :\|:& };:/,  # fork bomb

  # Code execution functions
  /\beval\s*\(/i,
  /\bexec\s*\(/i,
  /\bsystem\s*\(/i,
  /\b__import__\s*\(/i,
  /\bos\.system\s*\(/i,
  /\bsubprocess\.(run|call|Popen)\s*\(/i,
  /\bRuntime\.getRuntime\(\)\.exec\s*\(/i,

  # Shell interpolation
  /`[^`]+`/,             # backticks
  /\$\([^)]+\)/,        # $() command substitution

  # Dangerous redirects
  />\s*\/dev\/sd[a-z]/,
  />\s*\/etc\//,
  /;\s*shutdown\b/i,
  /;\s*reboot\b/i,
  /;\s*halt\b/i,
  /\bpowershell\b.+-enc/i,
].freeze

Instance Attribute Summary

Attributes inherited from GuardrailsRuby::Check

#options

Instance Method Summary collapse

Methods inherited from GuardrailsRuby::Check

check_name, direction, #initialize, lookup

Constructor Details

This class inherits a constructor from GuardrailsRuby::Check

Instance Method Details

#call(text, context: {}) ⇒ Object



44
45
46
47
48
49
50
51
52
53
# File 'lib/guardrails_ruby/checks/code_execution.rb', line 44

def call(text, context: {})
  matched = PATTERNS.select { |p| text.match?(p) }

  if matched.any?
    fail! "Potential code execution detected",
      matches: matched.map(&:source)
  else
    pass!
  end
end