SSRF and command injection: constrain destinations and execution
Control destinations, process invocation and privileges in fetchers, converters and administrative tools.
Contents of this article
Two distinct control boundaries
Fetchers may access user-specified destinations, while converters may launch external processes. Control outbound targets and command structure separately, even when both occur in one feature.
Validate the eventual destination
Restrict schemes, destinations and ports, and revalidate after resolution and redirects. Narrow runtime egress to required services. A plausible hostname does not authorize loopback, internal or cloud-metadata access.
Prefer libraries to shell construction
Prefer library APIs. When a process is necessary, separate executable and arguments and validate argument meaning; escaping alone may leave dangerous options. Use low privileges, restricted directories and time limits without unnecessary credentials.
Test rejection and cleanup
In an isolated test environment, verify denied destinations, timeouts, cleanup and non-sensitive errors. Keep request correlation without logging secrets. Harden process permissions and outbound access alongside perimeter controls.
References
OWASP OS command injection defense
