Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to analyze the OpenSSH command injection vulnerability CVE-2020-15778

Shulou Source: shulou.com Published: 2022-05-31 17:56:47 10月03日 Update

How to analyze the OpenSSH command injection vulnerability CVE-2020-15778. In view of this problem, this article introduces the corresponding analysis and solution in detail, hoping to help more partners who want to solve this problem to find a more simple and feasible method.

Introduction of loopholes

SCP (secure copy) is a command for secure remote file copying based on ssh login on linux systems, which can copy files and directories between linux.

A command injection vulnerability exists in the less than 8.3p1 version of the SCP command in OpenSSH. When a file is copied to a remote server, the file path is appended to the end of the local scp command, which can trigger a command injection vulnerability.

An attacker can use a backquote (`) file as a command injection to execute a scp command, which will be sent to a remote server and executed.

Affect the version

Version:

Tags: Commands vulnerabilities files analysis quotation marks questions messages packages passwords more servers versions paths targets help attacks services answers ease security Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Xiaomi Linux Shulou Tech Info NVidia vpn