Live Hacking Night - Day08 - Portswigger Academy Series (Command Injection + File Upload)

Опубликовано: 24 Апрель 2026
на канале: Heshan Perera
175
20

In this Stream Recording of Late Hacking Night Day 08 (Sinhala), we explore OS Command Injection and File Upload Vulnerabilities with practical labs from PortSwigger.

Topics Covered:

Basic Linux commands
What is command injection?
Identifying command injection vulnerabilities
Exploiting different types of command injection
Preventing command injection
Achieving command execution through malicious file uploads
Bypassing file upload and command injection defenses
Preventing file upload vulnerabilities

Labs Demonstrated:

OS command injection, simple case
Blind OS command injection with time delays
Blind OS command injection with output redirection
Remote code execution via web-shell upload
Web-shell upload via Content-Type restriction bypass
Web-shell upload via path traversal
Web-shell upload via extension blacklist bypass
Web-shell upload via obfuscated file extension
Remote code execution via polyglot web-shell upload

💬 Join Heshan Streams WhatsApp Channel for live notifications and events :
https://bit.ly/heshanpererawhatsapp

🌍 Websites :
Main : https://destinyoo.com
Blog : https://blog.destinyoo.com
Portfolio : https://about.destinyoo.com

🎙️ Daily Streams and Content :
   / @heshankperera  

‼️ Disclaimer: This content is for educational purposes only. I do not take responsibility for misuse. All material is freely available for those who love cybersecurity, use responsibly and ethically.

#cybersecurity #webhacking #CTF #portswiggerlabs #sinhala