Lazo Lab Sign up

Web Security / Injection

Lesson 8 of 27

Command injection

Passing user input to a shell lets attackers chain their own commands. Avoid shell=True and pass arguments as a list.

Key points

  • Avoid os.system with user input
  • subprocess.run([...]) without shell=True
  • Validate against an allow-list
import subprocess
subprocess.run(["ping", "-c", "1", host], check=True)
Watch a video on thisOpens YouTube search results for “Command injection” in a new tab

Quiz · +10 XP

Which is safer for running a program with user input in Python?

Log in to save progress and earn XP.