Command Injection - Lab #4 Blind OS command injection with out-of-band interaction | Long Version

Опубликовано: 15 Март 2026
на канале: Rana Khalil
5,354
144

In this video, we cover Lab #4 in the Command Injection module of the Web Security Academy. This lab contains a blind OS command injection vulnerability in the feedback function.

The application executes a shell command containing the user-supplied details. The command is executed asynchronously and has no effect on the application's response. It is not possible to redirect output into a location that you can access. However, you can trigger out-of-band interactions with an external domain.

To solve the lab, we exploit the blind OS command injection vulnerability to issue a DNS lookup to Burp Collaborator.

▬ 🌟 Video Sponsor 🌟 ▬▬▬▬▬▬▬▬▬▬
Purchase the Hacking Fundamentals Bundle: https://hackersacademy.com/courses/ha... (affiliate link)

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://bit.ly/30LWAtE

▬ 📖 Contents of this video 📖 ▬▬▬▬▬▬▬▬▬▬
00:00 - Introduction
00:14 - Hackers Academy sponsorship (https://hackersacademy.com/courses/ha...)
02:06 - Navigation to the exercise
02:41 - Understand the exercise and make notes about what is required to solve it
03:48 - Exploit the lab
08:05 - Summary
08:27 - Thank You

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Exercise Link: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil