
SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)
Detect unsafe Rsync commands before they become exploits
A lightweight, privacy-focused browser extension developed as part of Final Year Project NWS/129/23B to detect missing --protect-args flag in Rsync commands β preventing remote command execution via CVE-2018-5764.
β
Works entirely offline
β
No server connections or data collection
β
Real-time scanning & alerts
β
Educational & mitigation-focused
β
Built for students, sysadmins, and security enthusiasts
| No. | Name | Student ID | Role & Responsibilities |
|---|---|---|---|
| 1 | Muhammad Nur Faiz Bin Ahmad Fauzi | NWS23070251 | Project Manager & Testing Lead |
| 2 | Wan Muhammad Afifuddin Bin Wan Ahmad | NWS23070157 | Backend & Functionality Developer |
| 3 | Waleed Adam Bin Riza Farouk | NWS23070265 | Frontend & UI/UX Developer |
| 4 | Roshazne Elia Binti Mohd Roshidi | NWS23070105 | Security Analyst & Resource Coordinator |
Supervisor: Sir Amir Hakeem
Intake: July 2023 | Trade: CID (Computer Information & Data)
Project Code: NWS/129/23B
Submission: January 2025
Rsync is a powerful utility for file synchronization β but if misconfigured (especially without --protect-args), it can lead to remote command execution via specially crafted filenames or arguments (CVE-2018-5764).
SyncShield helps users:
--protect-args, unquoted inputs, etc.)β οΈ Scope: Focused only on CVE-2018-5764 β simple, targeted, and achievable within academic timeline.
Watch SyncShield in action:
SyncShield/
βββ docs/ # Extension and Website source code
β βββ css
β βββ images
β βββ js
β βββ extension # Extension folder
β βββ index.html # Website source code
βββ LICENSE # MIT License file
βββ README.md # You are here
Scans user-inputted Rsync commands to detect absence of --protect-args β the critical flag that prevents shell injection.
Flags unquoted variables, shell metacharacters, and unsanitized user inputs that could trigger CVE-2018-5764.
Provides immediate visual feedback with:
Offers actionable fixes:
# β Unsafe
rsync -av /src user@host:/dest
# β
Safe
rsync -av --protect-args /src user@host:/dest
Once installed, you can start using SyncShield:
rsync -av /src user@host:/dest
Follow these steps to install SyncShield in your browser:
Extract the Files
.zip file to a folder on your computer.Open Browser Extensions Page
chrome://extensions/about:debugging#/runtime/this-firefoxEnable Developer Mode
Load the Extension
manifest.json file inside the SyncShield folder.Installation Complete π
Rsync is a powerful tool used to copy and synchronize files between computers. Itβs popular because itβs fast, efficient, and saves bandwidth by only transferring changes instead of the whole file.
If Rsync is not used carefully, it can cause serious problems:
SyncShield helps by:
--delete or overwriting files)rsync command into the Rsync Command box.--protect-args and other secure practices./path/to/source)user@host:/path/to/dest)-a Archive-v Verbose-z Compress--progress Show progress--checksum Verify integritySyncShield includes a live visual diagram that updates as you type.
It shows:
This helps prevent reversed paths, accidental overwrites, or unsafe behavior by making the commandβs behavior visually clear.
The Dashboard tab gives you a quick overview of your last scan, including: