I am less fond of this technique. This shell is buggy, suckish, and in Ruby - a language I dont like using, despite my love of the Metasploit framework.
Anyways, this is another "One Request Ownage" vid, showing how we can leverage a command injection bug in a webapp to get a reverse shell!
Have fun :)
Visit us at http://insecurety.net/