OS Command Injection Through Shell Invocation in Node.js
Shell syntax in user input gets parsed as commands, not safely passed as data.
Senior Contributing Editor
Tariq spent eight years as a penetration tester at a boutique security consultancy before moving into full-time writing and research; his hands-on work with web application assessments informs his deeply technical breakdowns of injection and authentication weaknesses.
7 stories
Shell syntax in user input gets parsed as commands, not safely passed as data.
Attackers can execute arbitrary code by exploiting how Java and Python deserialize untrusted data.
Attackers exploit trust in collaboration tools by injecting malicious scripts into shared content.
Attackers operate undetected for weeks when logging and alerting gaps leave breaches invisible.
Misconfigurations in IAM roles and S3 buckets remain the source of most cloud breaches.
Microservices multiply authentication attack surfaces, and most teams aren't securing them.
Misconfigurations in OAuth 2.0 follow predictable patterns security teams can learn to spot.