> For the complete documentation index, see [llms.txt](https://kruknight.gitbook.io/daemon-of-hacking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kruknight.gitbook.io/daemon-of-hacking/writeups/portswigger-labs/os-command-injection/blind-os-command-injection-with-output-redirection.md).

# Blind OS command injection with output redirection

## Lab Description

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FkOWq8VnuQyfU5sfBDC5F%2Fimage.png?alt=media&amp;token=041d893b-47eb-4170-a562-402e2b00ec92" alt=""><figcaption></figcaption></figure>

## Walkthrough

### **Step 1: Understanding the Feedback Functionality**

Navigating to the **Submit Feedback** page, you will notice four input fields:

1. Name
2. Email
3. Subject
4. Message

The goal is to determine if one of these fields is vulnerable to command injection and whether the output can be redirected to the writable directory `/var/www/images/`.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FCmJ90RlDvkRE1lSQ3Dte%2Fimage.png?alt=media&amp;token=8b6ebdf0-866b-46a8-b044-e836c857ee46" alt=""><figcaption></figcaption></figure>

### **Step 2: Intercepting the Feedback Request**

Using **Burp Suite**, intercept the feedback submission request. Below is an example of a normal intercepted request:

The request contains the user input as parameters, making it a good candidate for injection.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FwQpzibWERrLIfnDlpvMz%2Fimage.png?alt=media&amp;token=1653fe13-10a8-406d-8841-02573f090bc8" alt=""><figcaption></figcaption></figure>

### **Step 3: Crafting the Payload**

Modify the **Email** parameter to include the following payload:

```
||whoami>/var/www/images/whoami.txt||
```

This payload runs the command **`whoami` and saves it**&#x20;

#### **Payload Breakdown**:

* `||` is used to append and execute additional commands.
* `whoami` retrieves the current user running the application.
* `>/var/www/images/whoami.txt` redirects the output of the command to a file in the writable directory.

Submit the request with the modified payload.

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FmTT5oYb0zOafCeLHK5zN%2Fimage.png?alt=media&amp;token=e14f27af-a878-4532-bd28-33798394c83b" alt=""><figcaption></figcaption></figure>

### **Step 4: Accessing the Output**

To retrieve the saved command output:

1. Note that the application serves images from `/var/www/images/` via a parameter `filename=` in the URL.
2. Navigate to any image URL in your browser
3. modify the parameter to filename=whoami.txt

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FIBQ0fBVXs36p3Vzofozg%2Fimage.png?alt=media&amp;token=45f1e0f9-9879-494e-9414-1ad13e87683a" alt=""><figcaption></figcaption></figure>

Visiting the URL, the browser displays the output of the `whoami` command, confirming that the injection was successful. For example:

<figure><img src="https://2387347627-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F47EuhANOY5sIuDySBX97%2Fuploads%2FDPDDV2dKIQmQWKQxchAz%2Fimage.png?alt=media&amp;token=2e61459b-198b-474d-abb7-b3af9645f23b" alt=""><figcaption></figcaption></figure>
