Web Security / Injection
Lesson 8 of 27
Command injection
Passing user input to a shell lets attackers chain their own commands. Avoid shell=True and pass arguments as a list.
Key points
- Avoid os.system with user input
- subprocess.run([...]) without shell=True
- Validate against an allow-list
import subprocess
subprocess.run(["ping", "-c", "1", host], check=True)Quiz · +10 XP
Which is safer for running a program with user input in Python?
Log in to save progress and earn XP.