Command injection is a security vulnerability that allows an attacker to execute arbitrary commands inside a vulnerable application.
Execute the command and voila :p
Works on Linux only.
Commands execution without spaces, $ or - Linux (Bash only)
Works on Windows only.
Linux
Commands execution without backslash and slash - linux bash
Challenge based on the previous tricks, what does the following command do:
Extracting data : char by char
Based on the tool from https://github.com/HoLyVieR/dnsbin
also hosted at dnsbin.zhack.ca
Online tools to check for DNS based data exfiltration: