logo

OS Command Injection; The Pain, The Gain

ID: 1de0e92a-4fb9-5a22-bb13-b060aca0de5f

STIX ID: report--1de0e92a-4fb9-5a22-bb13-b060aca0de5f

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-03-01

Date Updated: 2026-04-27

Author: BHIS

...
...

A practitioner blog post recounts finding an OS command injection in an Apache/Red Hat web application discovered via Burp Suite. The author describes troubleshooting a 32-character command-length constraint, realizing that output resembling HTTP headers could be injected into response headers to exfiltrate /etc/passwd, discovering Python on the target, fetching a Python Meterpreter payload with wget, and obtaining a reverse shell (with post-exploitation pty upgrade).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.