Skip to main content

One doc tagged with "commmand injection"

View All Tags

Lab-5 nslookup with command injection

--> This lab is same as Lab-4 but here we have to execute the os command in the DNS lookup which we can do with the backtick so i set up my burp collaborator server and used this payload in every field :