Skip to main content

Posts

Showing posts from February, 2024

Blind OS command injection -Portswigger (LAB-2) | INFOCODX

  Hey there, how are you all? I hope everything is going smoothly and everyone is doing fine.  Today, we're diving into the exciting world of OS Command Injection labs from portswigger . Get ready for some hands-on action!  So what is blind OS command injection? I've already covered OS command injection in my previous blog post. Blind OS command injection works similarly, but instead of receiving output back to the web app, we don't get any output. So, how can we determine if there is a blind OS command injection? One technique is to use time delay. By using an OS command that takes some time to execute, we can test for it. LAB 2 : Blind OS command injection When we access this lab, a web application will be presented to us. As shown below, there is a feedback form available for submission. Firstly, let's go ahead and explore that particular feature, utilizing it to conduct a thorough analysis. It's worth noting that there is a dedicated functionality allowing users