Command Injection
Theory
Practice
Tools
# With a request file
## Batch : do not ask for questions
## --os : specify OS if known
## -r : request file
commix -r request.req --batch --os=Unix
# Retreive all
# --all : Retrieve everything
# -u : Target URL
commix -u <TARGET_URL> --allFuzzing
Payloads
Filter Bypass
Data Exfiltration
Polyglot command injection
Resources
Last updated