OS Command Injection; The Pain, The Gain
ID: 1de0e92a-4fb9-5a22-bb13-b060aca0de5f
STIX ID: report--1de0e92a-4fb9-5a22-bb13-b060aca0de5f
Feed Name: Black Hills Infosec Blog
Threat Score
A practitioner blog post recounts finding an OS command injection in an Apache/Red Hat web application discovered via Burp Suite. The author describes troubleshooting a 32-character command-length constraint, realizing that output resembling HTTP headers could be injected into response headers to exfiltrate /etc/passwd, discovering Python on the target, fetching a Python Meterpreter payload with wget, and obtaining a reverse shell (with post-exploitation pty upgrade).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
