Hunt for injection vulnerabilities including SQL injection, command injection, XSS, SSTI, path traversal, LDAP injection, and other input validation flaws...
Identify injection vulnerabilities by tracing user input from sources to dangerous sinks. Covers SQL injection, OS command injection, XSS, SSTI, path traversal, LDAP injection, and XML injection.
- request.params, request.body, request.query
- HTTP headers (Host, User-Agent, Referer, X-Forwarded-For)
- File uploads (filename, content)
- Database values (stored attacks)
- Environment variables (in some contexts)
- WebSocket messages
Follow data transformations:
- Variable assignments
- Function parameters
- Return values
- Object properties
SQL: db.query(), db.execute(), raw SQL strings
Command: system(), exec(), popen(), spawn(), backticks
XSS: innerHTML, document.write(), dangerouslySetInnerHTML
SSTI: render(), template(), eval() with user data
Path: open(), readFile(), fs.*, path.join() with user input
LDAP: ldap.search() with user-controlled filter
findings:
- title: "SQL Injection in search endpoint"
severity: critical
attack_scenario: "Attacker injects SQL via 'query' parameter to extract database"
preconditions: "None - public endpoint"
reachability: public
impact: "Full database compromise, data exfiltration"
confidence: high
cwe_id: "CWE-89"
affected_assets:
- "/api/search?query="
- "src/handlers/search.rs:45"
taint_path: "request.query['query'] -> format!() -> db.execute()"
// VULNERABLE - string concatenation
let query = format!("SELECT * FROM users WHERE name = '{}'", user_input);
db.execute(&query)?;
// SECURE - parameterized query
db.execute("SELECT * FROM users WHERE name = ?", &[user_input])?;
# VULNERABLE
os.system(f"convert {filename} output.png") # filename = "; rm -rf /"
# SECURE
subprocess.run(["convert", filename, "output.png"]) # Array form
// VULNERABLE - direct HTML insertion
element.innerHTML = userInput;
// SECURE - text content only
element.textContent = userInput;
// VULNERABLE
path := filepath.Join("/uploads", userInput) // userInput = "../../../etc/passwd"
// SECURE
path := filepath.Join("/uploads", filepath.Base(userInput)) // Strip directory components
# VULNERABLE
template = f"Hello {user_input}" # user_input = "{{7*7}}" or worse
render_template_string(template)
# SECURE
render_template("hello.html", name=user_input) # Template is static
| Type | Impact | Severity |
|---|---|---|
| SQL Injection | DB access | Critical |
| Command Injection | RCE | Critical |
| Stored XSS | Session hijack | High |
| Reflected XSS | Phishing | Medium |
| SSTI with RCE | RCE | Critical |
| Path Traversal (read) | Info disclosure | High |
| Path Traversal (write) | Code execution | Critical |
SQL: UNION, nested queries, time-based blind, error-based
CMD: &&, ||, ;, |, $(), backticks, newlines
XSS: Event handlers, data: URLs, SVG, encoding bypass
Path: ../, ..\\, URL encoding, double encoding, null bytes
Register injection findings and import scanner results:
kyco project list
kyco finding create \
--title "SQL Injection in search endpoint" \
--project PROJECT_ID \
--severity critical \
--cwe CWE-89 \
--attack-scenario "Attacker injects SQL via 'query' parameter to extract database" \
--impact "Full database compromise, data exfiltration" \
--assets "/api/search,src/handlers/search.rs:45"
# Import SARIF output
kyco finding import scanner-results.sarif --project PROJECT_ID
# Import Semgrep JSON
kyco finding import semgrep-results.json --project PROJECT_ID -f semgrep