Writeups
-
Easy
Blind OS command injection with out-of-band data exfiltration
fully blind os command injection taken from confirmation to theft, wrapping whoami in backticks so command substitution splices the username into the hostname of a dns lookup that burp collaborator logs
OS command injection 2 min -
Easy
Blind OS command injection with out-of-band interaction
fully blind os command injection with no readable output, no timing and no writable folder, confirmed by injecting nslookup so the server fires a dns lookup to a burp collaborator subdomain
OS command injection 2 min -
Easy
Blind OS command injection with output redirection
blind os command injection where the output is read back by redirecting whoami with > into the writable /var/www/images/ folder and then fetching that file through the image loader
OS command injection 2 min -
Easy
Blind OS command injection with time delays
blind os command injection in a feedback form where output is never shown, so the email parameter is injected with ||ping -c 10 127.0.0.1|| to make the server pause ten seconds and prove the command ran
OS command injection 4 min
Nothing matched that.
No writeups here yet. Try a broader tag, or clear the filter to see everything.
Clear filters