SQLite自定义函数间接执行的安全风险及游戏Mod场景问询
SQLite Tcl自定义函数安全疑问
参考SQLite Tcl接口文档中关于自定义函数的安全描述,存在以下技术疑问:
- 未启用
-directonly选项时,该漏洞的利用方式是什么?能否提供代码示例? - 该漏洞会带来哪些风险:是否会导致主机被攻陷、数据库被篡改、敏感数据泄露?若函数无相关副作用,上述风险是否仍存在?
- 该漏洞是否依赖攻击者提供的恶意数据库文件?设置
trusted_schema=off并复制数据到可信数据库的方案能否缓解?
EAV模型游戏Mod系统安全风险
正在搭建基于Entity-Attribute-Value(EAV)模型的游戏灵活Mod系统,通过触发器将属性约束检查委托给安全解释器中的proc,示例代码及输出如下:
#!/bin/sh # This line continues for Tcl, but is a single line for 'sh' \ exec tclsh "$0" ${1+"$@"} package require sqlite3 proc delegate {id type value} { set proc_name "is_valid_$type" # If no proc has been defined to delegate to, automatically succeed. if {[safe_interp eval "info proc $proc_name"] eq ""} { return } set failed [catch { safe_interp eval "$proc_name $id $type $value" } error_msg] if {$failed} { puts "delegate to: $proc_name\ \nwith args:\ \n id: $id\ \n type: $type\ \n value: $value\ \nfailed with error msg: $error_msg" } # Used by the trigger to determine whether to rollback. return [expr {!$failed}] } proc insert_attribute {type value} { db eval { insert into attribute (type, value) values(:type, :value); } } interp create -safe safe_interp interp alias safe_interp insert_attribute {} insert_attribute safe_interp eval { proc is_valid_t1 {id type value} { error "error: is invalid for some reason I guess?" } proc is_valid_t2 {id type value} {} } sqlite3 db -create true "" db function delegate delegate db eval { create table attribute( id integer primary key, type varchar not null, value varchar not null ); } db eval { create trigger delegate_on_attribute_insert after insert on attribute begin select case (select delegate(new.id, new.type, new.value)) when false then raise(rollback, 'delegate failed, rolling back') end; end; } # Fails because attribute type t1 has a proc defined # that checks for validity, and that proc is defined to always # give an error. if {[catch {safe_interp eval insert_attribute t1 v1} msg]} { puts "msg: $msg" } # Succeeds because attribute type t2's validity-checking proc # always succeeds. if {[catch {safe_interp eval insert_attribute t2 v1} msg]} { puts "msg: $msg" } # Succeeds because attribute type t3's has # no validity-checking proc so nothing makes it fail. if {[catch {safe_interp eval insert_attribute t3 v1} msg]} { puts "msg: $msg" } puts "attributes: [db eval { select * from attribute }]"
输出:
delegate to: is_valid_t1 with args: id: 1 type: t1 value: v1 failed with error msg: error: is invalid for some reason I guess? msg: delegate failed, rolling back attributes: 1 t2 v1 2 t3 v1
想了解在此场景下,设置trusted_schema=on或将delegate函数标记为innocuous会存在哪些安全风险?
内容的提问来源于stack exchange,提问作者guest
相关产品推荐
相关产品推荐

