CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is performing a web application assessment and encounters a login form. The tester suspects the application might be vulnerable to command injection. Which of the following inputs, when entered into a username field, would be the MOST indicative of a successful command injection vulnerability on a Linux-based server?

  1. Aadmin' OR 1=1--
  2. B<script>alert('XSS')</script>
  3. Cadmin; cat /etc/passwd
  4. Dadmin' UNION SELECT NULL,NULL,NULL--
Show answer & explanation

Correct answer: C. admin; cat /etc/passwd

The input `admin; cat /etc/passwd` attempts to terminate the 'admin' string with a semicolon (;) and then execute the `cat /etc/passwd` command. If successful, this would display the contents of the password file, which is a clear indicator of a command injection vulnerability on a Linux system.

Why the other options are wrong

  • A. This is a classic SQL injection payload to bypass authentication, not command injection.
  • B. This is a Cross-Site Scripting (XSS) payload, designed to execute client-side scripts, not server-side commands.
  • D. This is a Union-based SQL injection payload, used to retrieve data from a database, not execute system commands.

Command Injection

A web vulnerability that allows an attacker to execute arbitrary operating system commands on the server running a web application, typically by injecting commands into user-supplied input.

  • Occurs when an application passes unsanitized user input to a system shell.
  • Attackers can use various shell metacharacters (e.g., ;, &&, ||, |, `) to chain commands.
  • Can lead to full system compromise if executed with sufficient privileges.

Memory trick: When input goes wild, system commands can be defiled.

More Attacks and Exploits questions