Cmd Injection

OS command injection occurs when user input is passed unsanitized to a system shell via dangerous APIs: Java `Runtime.exec()`, Python `os.system/subprocess`, PHP `system/shell_exec/exec/proc_open`, C `system/exec`. Detect via pipe `|`, semicolon `;`, `&&`, `||`, backtick, `$()` operators, and time-delay payloads (`sleep 5`). Tools: Commix, Burp Suite, OWASP WebGoat.

ShulkwiSEC Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/cmd-injection commit d35dc3f980

Frequently asked questions

npx skillmds@latest add shulkwisec/cmd-injection