You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SQLite自定义函数间接执行的安全风险及游戏Mod场景问询

SQLite Tcl自定义函数安全疑问

参考SQLite Tcl接口文档中关于自定义函数的安全描述,存在以下技术疑问:

  1. 未启用-directonly选项时,该漏洞的利用方式是什么?能否提供代码示例?
  2. 该漏洞会带来哪些风险:是否会导致主机被攻陷、数据库被篡改、敏感数据泄露?若函数无相关副作用,上述风险是否仍存在?
  3. 该漏洞是否依赖攻击者提供的恶意数据库文件?设置trusted_schema=off并复制数据到可信数据库的方案能否缓解?
EAV模型游戏Mod系统安全风险

正在搭建基于Entity-Attribute-Value(EAV)模型的游戏灵活Mod系统,通过触发器将属性约束检查委托给安全解释器中的proc,示例代码及输出如下:

#!/bin/sh
# This line continues for Tcl, but is a single line for 'sh' \
exec tclsh "$0" ${1+"$@"}


package require sqlite3

proc delegate {id type value} {
    set proc_name "is_valid_$type"

    # If no proc has been defined to delegate to, automatically succeed.
    if {[safe_interp eval "info proc $proc_name"] eq ""} {
        return
    }

    set failed [catch {
        safe_interp eval "$proc_name $id $type $value"
    } error_msg]

    if {$failed} {
        puts "delegate to: $proc_name\
            \nwith args:\
            \n  id: $id\
            \n  type: $type\
            \n  value: $value\
            \nfailed with error msg: $error_msg"
    }

    # Used by the trigger to determine whether to rollback.
    return [expr {!$failed}]
}

proc insert_attribute {type value} {
    db eval {
        insert into attribute (type, value) values(:type, :value);
    }
}

interp create -safe safe_interp
interp alias safe_interp insert_attribute {} insert_attribute
safe_interp eval {
    proc is_valid_t1 {id type value} {
        error "error: is invalid for some reason I guess?"
    }
    proc is_valid_t2 {id type value} {}
}

sqlite3 db -create true ""

db function delegate delegate

db eval {
    create table attribute(
        id integer primary key,
        type varchar not null,
        value varchar not null 
    );
}

db eval {
    create trigger delegate_on_attribute_insert
    after insert on attribute
    begin
        select case (select delegate(new.id, new.type, new.value))
        when false then
            raise(rollback, 'delegate failed, rolling back')
        end;
    end;
}

# Fails because attribute type t1 has a proc defined
# that checks for validity, and that proc is defined to always
# give an error.
if {[catch {safe_interp eval insert_attribute t1 v1} msg]} {
    puts "msg: $msg"
}

# Succeeds because attribute type t2's validity-checking proc
# always succeeds.
if {[catch {safe_interp eval insert_attribute t2 v1} msg]} {
    puts "msg: $msg"
}

# Succeeds because attribute type t3's has
# no validity-checking proc so nothing makes it fail.
if {[catch {safe_interp eval insert_attribute t3 v1} msg]} {
    puts "msg: $msg"
}

puts "attributes: [db eval {
    select * from attribute
}]"

输出:

delegate to: is_valid_t1 
with args: 
  id: 1 
  type: t1 
  value: v1 
failed with error msg: error: is invalid for some reason I guess?
msg: delegate failed, rolling back
attributes: 1 t2 v1 2 t3 v1

想了解在此场景下,设置trusted_schema=on或将delegate函数标记为innocuous会存在哪些安全风险?


内容的提问来源于stack exchange,提问作者guest

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 21:29:55