This video is a simple demonstration of how, using ONE HTTP POST Request, we were able to leverage a command execution vulnerability in Mutillidae to get a reverse shell using the /dev/tcp technique.
The "shell" I used is NOT IDS evasion friendly for now, and is just an example.
Check out our website! http://insecurety.net/