OS commanding
Home > Software Quality Glossary > Definition - OS commanding
EMAIL THIS
Glossary - powered by WhatIs.com
 BROWSE ALPHABETICALLY:    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #    
Search for: in Full Target Search with Google

OS commanding

OS commanding is a method of attacking a Web server by remotely gaining access to the operating system (OS) and then executing system commands through a browser. Once access has been gained in this way, a hacker can upload programs to the compromised server and run them. OS commanding is similar to command injection, a scheme in which an attacker alters dynamically generated content on a Web page by entering HTML code into an input mechanism, such as a form field that lacks effective validation constraints.

The vulnerability of a server or other network-connected computer to OS commanding attacks can be minimized by:

  • Blacklisting of forbidden character sequences.
  • Whitelisting of allowed character sequences.
  • Restricting permissions on OS commands.
  • Filtering out command directory names.

According to security experts, the main reason that OS commanding and similar exploits are on the rise is that security is not sufficiently emphasized in the development of operating systems and applications. To protect the integrity of network servers, experts recommend the implementation of simple precautions during development, such as controlling the types and numbers of characters that are accepted by servers from users.

Read more about it:
>>  The Web Application Security Consortium provides examples of OS commanding.
>>  Sverre H. Huseby outlines some common security problems in dynamic Web applications.

Last updated on: Jul 31, 2006

WHITE PAPERS  
Enable a Flexible, Efficient IT Infrastructure: Virtualization with Logical Domains and Sun Coolthreads™ Servers
Insight and Sun Microsystems, Inc

Consolidation through Virtualization with Sun™ x64 Servers
Insight and Sun Microsystems, Inc

The Next-Generation Development and Deployment Platform
AMD

Coding Tips Using Microsoft Visual Studio 2008 Targeting Quad-Core AMD Opteron™ Processors
AMD

Proactive PCI Compliance and Threat Mitigation Using OpenService InfoCenter
OpenService, Inc.

>> More White Papers
  WHAT'S NEW
 1. Managing performance in the enterprise
 2. Software testing fundamentals
 3. Learning Guide: Debugging & unit testing
 4. .NET Application Security Learning Guide


About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts