# Operating-system command injection checklist

Identify user input crossing into a system command, account for quoting and filters, then turn direct or blind execution into a stable shell.

## Recognition

- [ ] Features invoke ping, DNS, archive, image, document, backup, diagnostic, build, converter, or administrative utilities.
- [ ] Separators, substitution, quoting, or delay commands change output or timing.
- [ ] Errors expose shell syntax, executable paths, command arguments, or process failures.

## Manual workflow

- [ ] Determine operating system, shell, command location, argument position, quoting, normalization, and allowed characters.
- [ ] Try one appropriate separator or substitution construct with a harmless command.
- [ ] When output is hidden, confirm with deterministic delay and then a controlled callback.
- [ ] Enumerate identity, working directory, environment, available interpreters, egress, and writable locations.
- [ ] Choose a callback payload for an installed runtime rather than cycling random reverse shells.
- [ ] Transfer files only when needed and keep every hosted artifact in the evidence log.
- [ ] Upgrade the shell enough to navigate and read proof.txt; privilege escalation is not required.

## Escalation

- [ ] Direct command output can retrieve proof without a reverse shell when the objective and screenshot rules are satisfied.
- [ ] Blind execution can download or invoke a short callback payload from your controlled HTTP server.
- [ ] Writable web roots may allow a web shell when outbound callbacks fail.

## Pitfalls

- [ ] Combining separators, encodings, and shell syntax before learning which character is blocked.
- [ ] Using bash-specific syntax when /bin/sh or Windows cmd is executing.
- [ ] Debugging a listener when the actual problem is quoting or target egress.
- [ ] Forgetting to screenshot proof from its original location.

## Evidence

- [ ] Harmless direct/timing confirmation
- [ ] Execution context enumeration
- [ ] Listener and target command
- [ ] Stable shell or direct file read
- [ ] Original-location proof

## Tools

- [ ] Burp/ZAP resend and fuzzer
- [ ] curl or Python HTTP server
- [ ] nc/socat listener
- [ ] Reverse-shell generator

## Online references

- [PortSwigger command injection labs](<https://portswigger.net/web-security/os-command-injection>)
- [OWASP command injection testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/12-Testing_for_Command_Injection>)

> Do you want to live curiously?
