CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester is performing a web application assessment and encounters a login form. The tester suspects the application might be vulnerable to command injection. Which of the following inputs, when entered into a username field, would be the MOST indicative of a successful command injection vulnerability on a Linux-based server?
- Aadmin' OR 1=1--
- B<script>alert('XSS')</script>
- Cadmin; cat /etc/passwd
- Dadmin' UNION SELECT NULL,NULL,NULL--
Show answer & explanationAnswer & explanation
Correct answer: C. admin; cat /etc/passwd
The input `admin; cat /etc/passwd` attempts to terminate the 'admin' string with a semicolon (;) and then execute the `cat /etc/passwd` command. If successful, this would display the contents of the password file, which is a clear indicator of a command injection vulnerability on a Linux system.
Why the other options are wrong
- A. This is a classic SQL injection payload to bypass authentication, not command injection.
- B. This is a Cross-Site Scripting (XSS) payload, designed to execute client-side scripts, not server-side commands.
- D. This is a Union-based SQL injection payload, used to retrieve data from a database, not execute system commands.
Command Injection
A web vulnerability that allows an attacker to execute arbitrary operating system commands on the server running a web application, typically by injecting commands into user-supplied input.
- Occurs when an application passes unsanitized user input to a system shell.
- Attackers can use various shell metacharacters (e.g., ;, &&, ||, |, `) to chain commands.
- Can lead to full system compromise if executed with sufficient privileges.
Memory trick: When input goes wild, system commands can be defiled.