Skip to content

Commit d0cf032

Browse files
committed
Update 2026-08-10-ssc-security-analysis.md
1 parent 440b6ae commit d0cf032

1 file changed

Lines changed: 53 additions & 0 deletions

File tree

Lines changed: 53 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
---
2+
layout: post
3+
title: "Linux Shell Script Security: Structural Limitations and Vulnerabilities in ssc (Source Code Protection, Obfuscation, Reverse Engineering)"
4+
---
5+
6+
[ssc](https://github.com/liberize/ssc) is a project that improves on shc (shell script compiler).
7+
Like shc, it wraps a shell script in C source code and compiles it into a binary to keep the code from being exposed.
8+
9+
Unlike shc, ssc doesn't rely on the system shell — it uses a separate shell interpreter (e.g., BusyBox) instead.
10+
So [the technique used to attack shc (auditd)](https://himitsushell.github.io/en/shc-security-analysis/) can't be applied to ssc in the same way.
11+
12+
That said, ssc has a structural limitation of its own.
13+
A binary built with ssc briefly drops the embedded shell interpreter (e.g., BusyBox) to disk at /tmp/ssc.XXXXXX/busybox, then hands the shell script off to it to run.
14+
**So if you just watch for the moment the embedded shell interpreter gets exposed externally, you can capture the shell script.**
15+
16+
![ssc vulnerability diagram](/assets/images/ssc-security-analysis/1.png)
17+
18+
Let's test this directly and confirm the vulnerability.
19+
20+
## Test Environment
21+
We'll use the shell script below on ubuntu 24.04.
22+
23+
![Test shell script](/assets/images/ssc-security-analysis/2.png)
24+
25+
We'll proceed with the [shell interpreter (BusyBox) embedded](https://github.com/liberize/ssc/tree/master/examples/4_embed_interpreter) as shown below.
26+
27+
```shell
28+
./ssc test ssc_binary -s -r -e busybox -c
29+
```
30+
31+
## Test Method
32+
```shell
33+
# Install bpftrace
34+
sudo apt install bpftrace
35+
36+
# Start monitoring in terminal 1
37+
sudo bpftrace -e 'tracepoint:syscalls:sys_enter_write /comm == "ssc_binary"/ { printf("PID: %d | FD: %d | Data: %s\n", pid, args->fd, str(args->buf)); }'
38+
39+
# Run ssc_binary in terminal 2
40+
./ssc_binary
41+
```
42+
43+
**As shown in the red box in the image below, bpftrace (kernel tracing tool) makes it easy to capture the shell script.**
44+
45+
![Terminal 2 monitoring result](/assets/images/ssc-security-analysis/3.png)
46+
47+
![Terminal 1 monitoring result](/assets/images/ssc-security-analysis/4.png)
48+
49+
## Solution
50+
What's needed is a protection tool that keeps the shell interpreter entirely internal instead of exposing it externally.
51+
A representative example is [HimitsuShell](https://github.com/HimitsuShell/HimitsuShell).
52+
53+
The next post will introduce HimitsuShell.

0 commit comments

Comments
 (0)