Skip to main content

2 docs tagged with "nslookup"

View All Tags

Lab-4 OAST with nslookup

--> In this lab the server is working asynchronously that's why output redirecion or blind command injection will not work but we can make sure the server is vulnerable with the nslookup in linux which is command for DNS lookup.

Lab-5 nslookup with command injection

--> This lab is same as Lab-4 but here we have to execute the os command in the DNS lookup which we can do with the backtick so i set up my burp collaborator server and used this payload in every field :