Blind OS Command Injection With Out-of-band Interaction | Web Security Academy (Audio)

Опубликовано: 14 Октябрь 2024
на канале: Bnke
80
1

This Video Shows the Lab Solution of a blind OS command injection vulnerability in the feedback function.

The application executes a shell command containing the user-supplied details. The command is executed asynchronously and has no effect on the application's response. It is not possible to redirect output into a location that you can access. However, you can trigger out-of-band interactions with an external domain.

To solve the lab, exploit the blind OS command injection vulnerability to issue a DNS lookup to Burp Collaborator.