Log injection

Log injection

Description

Writing user input to a log without neutralizing line breaks can let an attacker insert forged log entries or confuse log analysis.

Potential impact

  • Incident detection and investigation may become more difficult.
  • An HTML log viewer may be vulnerable to XSS if it interprets the input as HTML.

Remediation

  • Remove \r and \n, or encode input for the log format before writing it.
  • Log normalized values or identifiers instead of raw user input.

Examples

Before

go
user := r.FormValue("user")
log.Printf("user=%s", user)

After

go
user := strings.ReplaceAll(r.FormValue("user"), "\n", "")
user = strings.ReplaceAll(user, "\r", "")
log.Printf("user=%s", user)

Explanation:

  • Before: Recording input without neutralizing line breaks can let attackers forge log lines. A viewer that interprets unencoded input as HTML introduces an additional risk.
  • After: Removing \r and \n reduces line-based forgery. This does not perform HTML encoding; a web log viewer still needs encoding for its output context.

References